Theme

Privacy policy

Effective October 5, 2026. This page describes what KinCircle does with information, based on how the service works.

Information KinCircle collects

KinCircle collects these kinds of information:

  • Account information, such as your name, email address, and a hash of your password
  • Care data the circle enters, such as the care card, notes, appointments, medications, bills, and renewals
  • Uploaded documents, including files and words copied from a PDF so the circle can search them
  • Device and push tokens, when you turn on device reminders
  • Logs, such as the circle activity log and short-lived records used to limit repeated requests

The sections below say what each of those contains and who can see them.

Who runs KinCircle

KinCircle is operated by Opal IT. For a question about this policy or your information, contact us via our contact form.

What a family circle stores

A circle is your family's shared space. Members put in the care information they choose to keep, including:

  • The person in care and the care card
  • Appointments
  • Medications, including the name, dose, schedule, instructions, purpose, and dose logs
  • Vital readings such as blood pressure, heart rate, weight, blood sugar, temperature, and oxygen saturation, plus any target ranges the owner sets
  • Notes, comments, and reactions
  • Documents such as insurance cards, policies, and IDs, plus words copied from a PDF so the circle can search them
  • Circle chat
  • Household bills, recorded payments, and household renewals
  • The family tree, contacts, and places
  • Member names, email addresses, optional phone numbers, and roles

A connected Withings account sends weight, temperature, blood pressure, heart rate, and oxygen readings into the circle's vital readings, where anyone who can already see vitals can see them.

Your account stores your name, email address, and a hash of your password. An optional phone number is a contact number. If you turn on more ways to sign in, KinCircle also stores what that method needs: an encrypted authenticator secret, hashed recovery codes, passkeys, a Google link, or a Microsoft or Yahoo link. A Microsoft or Yahoo link stores the email, the account identifier, and whether that email was proven. Those link fields are not encrypted. Storing sign-in identifiers this way is standard practice for apps that offer sign-in with Microsoft, Yahoo, or Google. These fields contain no password, sign-in token, or care information, and they cannot be used to sign in to your account on their own. Family-tree photos can be stored for a person. New family-tree photos in JPEG, PNG, and WebP, and new document images, have location data and camera make and model removed before they are saved. A GIF family photo is stored as uploaded. JPEG, PNG, and WebP document images already had that metadata removed. Family-tree photos and HEIC document images saved before September 27, 2026 may still contain location or camera data. Upload the file again to remove it. KinCircle does not rewrite a photo or document that is already stored.

Google sign-in

You can sign in with Google after that Google account is linked to an existing KinCircle account with the same verified email. KinCircle does not create an account or a circle from Google.

The sign-in request asks Google only for the openid and email scopes. From Google's ID token we keep the verified email address and Google's account id (the subject). We use those to sign you in and to remember the link on your account. You can turn Google sign-in off from Account.

KinCircle does not access Gmail, Google Contacts, Google Drive, Google Calendar, or any other Google product. Google user data is not sold, not shared for advertising, and not used to train AI models. It is not shared except as required by law. KinCircle's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke KinCircle's access to your Google account at Google Account permissions. Turning that off stops Google from signing you in.

Microsoft sign-in

You can sign in with Microsoft after that Microsoft account is linked to an existing KinCircle account. KinCircle does not create an account or a circle from Microsoft. The first time, sign-in links Microsoft only when the email is proven and it matches that existing account. Later sign-in uses the stored account identifier. Linking from Account, after your current password, attaches Microsoft to the KinCircle account you are already signed in to. When the email is proven, it has to be that same address.

The sign-in request asks Microsoft only for the openid and email scopes. From Microsoft's ID token we keep the email and Microsoft's account identifier. That identifier is the tenant id and the object id. When those are missing, we keep the subject. We also keep whether the email was proven. We use those to sign you in and to remember the link on your account. You can turn Microsoft sign-in off from Account. Turning it off marks the link removed and leaves the row in place, so a later sign-in does not attach it again by email. Changing your password, a password reset, or turning off two-factor sign-in does the same. The link is marked removed and the row stays, so a later sign-in does not attach it again by email. You can link it again from Account after you confirm your current password.

The email counts as proven for a personal Microsoft account, or when the token says the organization has verified the email's domain. Microsoft's email-verified flag is not that proof. The preferred username is not used as an email. An email that is not proven does not select a KinCircle account.

KinCircle does not access Outlook mail, OneDrive, or any other Microsoft product. This data is not sold, not used for ads, not used for AI training, and not shared except as required by law.

You can revoke KinCircle's access for a personal Microsoft account at Microsoft account app permissions, or for a work or school account at My Apps. Turning that off stops Microsoft from signing you in.

Yahoo sign-in

You can sign in with Yahoo after that Yahoo account is linked to an existing KinCircle account. KinCircle does not create an account or a circle from Yahoo. The first time, sign-in links Yahoo only when Yahoo has verified the email and it matches that existing account. Later sign-in uses the stored account identifier. Linking from Account, after your current password, attaches Yahoo to the KinCircle account you are already signed in to. When the email is verified, it has to be that same address.

The sign-in request asks Yahoo only for the openid and email scopes. From Yahoo's ID token we keep the email and Yahoo's account identifier (the subject). We also keep whether Yahoo says that email is verified. We use those to sign you in and to remember the link on your account. KinCircle uses the email to find an account only when that verified flag is true. You can turn Yahoo sign-in off from Account. Turning it off marks the link removed and leaves the row in place, so a later sign-in does not attach it again by email. Changing your password, a password reset, or turning off two-factor sign-in does the same. The link is marked removed and the row stays, so a later sign-in does not attach it again by email. You can link it again from Account after you confirm your current password.

KinCircle does not access Yahoo Mail or any other Yahoo product. This data is not sold, not used for ads, not used for AI training, and not shared except as required by law.

You can revoke KinCircle's access to your Yahoo account at Yahoo Account Security. Turning that off stops Yahoo from signing you in.

Cookies and sessions

KinCircle uses cookies to sign you in, keep you signed in, and connect a Withings account. The session cookie (kincircle_session) lasts about 14 days. It is httpOnly. In production it is sent only over HTTPS. The database stores a hash of the cookie, not the cookie itself.

Short-lived httpOnly cookies finish sign-in when they are needed. One is for the Google sign-in check (about 10 minutes, sent to /api/auth/google, which covers starting sign-in and the callback). Microsoft uses the same kind of cookie, kincircle_oauth_state, sent to /api/auth/microsoft, for about 10 minutes. Yahoo uses the same kind of cookie, kincircle_oauth_state, sent to /api/auth/yahoo, for about 10 minutes. Connecting Withings uses the same httpOnly cookie, kincircle_oauth_state, sent to /api/vitals/withings, for about 10 minutes. Another is for an authenticator-app check (about 5 minutes). Your theme choice is saved in this browser's local storage. It is not a cookie.

KinCircle does not use advertising cookies or analytics cookies. The app does not include an analytics or tracking script. The session cookie is what keeps you signed in. KinCircle does not use it to follow you on other sites.

Where information is stored

KinCircle runs on a private server in the United States, operated by the owner. The public site is served through Cloudflare. The application and its PostgreSQL database run on that server. The database is not opened to the internet.

Some information is encrypted at rest with AES-256-GCM. The encrypted fields are:

  • The care card
  • Note text and comment text
  • Medication name, dose, schedule, dose times, days of the week, dose repeat schedule, instructions, and purpose
  • Dose-log notes
  • Vital value, context, notes, and targets
  • Withings OAuth tokens
  • Appointment title, location, notes, place, and the other person's name on a visit
  • Family-tree photo files
  • Optional member phone numbers

Vital type, source, and time taken stay unencrypted.

Withings is an optional data source that a circle member can connect, and its OAuth tokens are stored encrypted.

Document file bytes are encrypted with a separate key and kept outside the public website. They are not public links. If the documents key is missing, document upload is unavailable. A document's title, notes, file name, file type, size, and words copied from a PDF are not encrypted.

Other data, including names, email addresses, circle chat, family-tree notes, bills, household renewals, contacts, and places, is protected by access controls and transport security. It is not field-encrypted. An appointment title and place can also be stored on a notification, and an appointment title or a medication name can be stored in the activity log. Those copies are not field-encrypted. If a stored encrypted field cannot be opened, KinCircle shows that it can't be decrypted instead of a blank. Passwords are stored as bcrypt hashes. Session secrets are stored as SHA-256 hashes.

The operator keeps encrypted backups for 30 days.

Data in transit is protected with TLS.

How long information is kept

Encrypted backups are kept for 30 days.

A document in the Documents recycle bin is purged after 30 days. The Deletion section describes what that job removes. Other deleted items are not erased on a timer.

IP addresses

Sign-in, registration, invite accept, forgot-password, email sign-in links, the Help form, and the contact form store the client IP address in a rate-limit key. A sign-in key that also names an account stores a hash of the email, not the email itself. The running app keeps these keys in the database. An operator can point that store at memory for one process; those keys are then gone when the process stops. Each key covers a 15-minute window. The next time a limit is recorded, keys older than that window are deleted. A key can remain longer if nothing else is recorded.

Forgot-password attempts and email sign-in-link attempts store the IP address and the email address in plaintext. The next attempt deletes rows older than 15 minutes. A row can remain if nobody tries again.

Assistant calls and calendar-feed checks keep the client IP in memory on that server process, for about one minute (assistant) or 15 minutes (calendar feed). Those keys are not written to the database.

Browser and push details

If you turn on device reminders, KinCircle stores that browser's push address, the keys the browser uses for the notification, and the browser's User-Agent. Turning reminders off removes that browser. Signing out removes it when the sign-out request includes that push address. Changing the password, or an Owner or operator resetting it, removes every device for that account. The row is also removed when the push service reports that the device is gone.

The Help form and the contact form put the browser's User-Agent, shortened to 180 characters, in the email sent to support. KinCircle does not keep a separate copy of that email in the database. The contact form also keeps a short-lived rate-limit key for the network address. It does not keep the message.

An email sign-in link stores a SHA-256 hash of the User-Agent from the browser that used the link, not the raw header. The link expires in about 15 minutes. That row is not deleted on the same timer.

Activity log

The circle activity log keeps some care text in the row, not only an id. That includes a medication name when one is deleted or stopped, a medication name and whether a dose was taken or skipped when a dose is logged, an appointment title when a visit is deleted or a volunteer ask changes, a bill payee when a bill or payment is added, changed, or deleted, a renewal label, a contact or place name, a family-tree person's name, and an invite email address. When an assistant reads the circle, the log stores the tool name and a count or a reason code, not the care text the tool returned. These rows are not erased on a timer.

Email

When a Resend API key is configured, KinCircle sends email through Resend. That includes invites, one-time sign-in links, password and sign-in notices, appointment and note mail, the weekly summary if you turn it on, messages from the Help form, and messages from the contact form. If Resend is not configured, those messages are not delivered. Email can include care details the feature is meant to send, such as an appointment title, a medication name in the weekly summary, or a short note preview, and it goes to the people that feature is for.

Push notifications

If you turn on device reminders, KinCircle can send a short notification through your browser's push service. The text stays small. Examples are "Appointment tomorrow at 3:00 PM", "New message in your circle", "A bill is due today", and "A renewal is due soon". The notification does not include chat text, note text, medication names, bill amounts, or renewal details. Bill and renewal reminders are these short notifications. They are not emails.

Waiting list

The public site can store a waiting-list signup in Cloudflare D1: your name, email, the optional 'who you are caring for' choice, an optional message, a required consent checkbox, the time, the source, the referring page if sent, a salted hash of the network address (not the address), and a shortened browser name. Those entries are stored in plaintext. A Cloudflare Turnstile check runs first and does not receive the words you type. KinCircle does not send a confirmation email. To be removed, use the contact form.

Third parties

Cloudflare delivers the public site. The email provider sends the messages described in the Email section. That provider is Resend, when a Resend API key is configured. Push services deliver the short device reminders described in the Push notifications section. KinCircle does not sell information to these providers, and it does not let them use circle information for advertising.

Withings is an optional data source that a circle member can connect, and its OAuth tokens are stored encrypted.

A connected Withings account sends weight, temperature, blood pressure, heart rate, and oxygen readings into the circle's vital readings, where anyone who can already see vitals can see them.

Who can see circle information

Other KinCircle users cannot open your circle. People in the circle see information according to their role. Owners and Caregivers can add and edit. A Viewer can look, with less detail: Viewers do not see caregivers-only notes or documents, circle chat, bill amounts, account details, or bill notes, or renewal costs, policy numbers, notes, or confirmation numbers. The person in care, when they have their own login and it is linked to their record, sees their appointments, medications, contacts, and vital readings. They can mark their own dose taken and add vital readings. They can change or remove only the readings they entered, and they cannot set target ranges. They do not see notes, circle chat, bills, renewals, documents, volunteer asks, the family tree, activity, member management, circle settings, or exports of those sections, and they do not receive notifications or weekly summary text for those sections.

The operator console shows circle administration. It does not show the care card, notes, medications, or document files. For each circle it shows the name, whether it is archived, the member count, and whether it has an Owner, plus the person in care's display name and preferred name. For each member it shows the name, email, phone, and role. When the circle has one Owner and two-factor sign-in is on, it shows a control to turn that off. It does not show the authenticator secret, and it does not list two-factor status for other members. It shows open Owner invites: the email, when the invite expires, and the invite link when that link can still be shown. It shows how much document space is used and the limit. It shows assistant tokens for that circle: the label, the person and role the token acts as, when it was created, last used, and whether it expires or is revoked. The token secret is shown once, when it is created. It shows operator audit rows: the action, the time, the actor's name, and a short subject when the row has a name, such as a circle name, a member name, or an email stored as that name. The response for that page carries the short subject and the two-factor flag for that one Owner. After an operator password reset, the temporary password is shown once on that screen. An Owner can also create a read-only token so an assistant can read what that person's role can already see. That token cannot change circle data through KinCircle. KinCircle does not sell circle information and does not share it for advertising.

Deletion

You can delete items your role is allowed to change. Most deleted items stay in Recently deleted, where an Owner can restore them. They are not erased on a timer.

Documents are different. A deleted document stays in the recycle bin for 30 days. After 30 days a daily job permanently removes the file, its preview, the database rows, and any words copied from it. An Owner or Caregiver can restore a document during those 30 days, or delete it forever sooner.

There is no button that deletes an account or permanently erases a whole circle. The operator can archive a circle, which closes it for members and keeps the care information. To ask for an account or a circle to be deleted, contact us via our contact form. Those requests are honored. To revoke KinCircle's access for a personal Microsoft account, open Microsoft account app permissions, or for a work or school account, open My Apps. To revoke KinCircle's access to a Yahoo account, open Yahoo Account Security.

Children

KinCircle is for adult family caregivers. It is not directed to children under 13. Do not create an account if you are under 13. We do not knowingly collect account information from children under 13.

Changes

If this policy changes, the new version will be posted on this page and the effective date at the top will change. This version is effective October 5, 2026.

Privacy policy