Privacy Policy
Effective September 30, 2026 · Last updated 30 Sep 2026 · Questions? ankursultaniya431@gmail.com
Kinboard is a family logistics hub: it turns school emails, flyers, PDFs and group-chat messages into one shared family board and calendar. This policy explains, in plain language, what we collect and what happens to it.
What we collect
- Account information — your email address and the name you enter, whether you sign in with a magic link or Google.
- Household details — the household name, and the family members you add (a name, a color, and whether they’re a kid or an adult).
- Content you add — pasted text, photos and PDFs you upload, and school emails forwarded to your household’s Kinboard mailbox (including the sender and subject line).
- Extracted items — the events, deadlines, to-dos and payments Kinboard pulls out of that content, plus the edits and completions your household makes.
- Push tokens — if you opt in to notifications, the browser push subscription for that device.
How AI processing works
To pull dates, deadlines and names out of the content you add, that content is sent to NVIDIA NIM (NVIDIA API Catalog) for extraction. If NVIDIA is unavailable, the same content is sent to Google Gemini (Google’s AI service) instead. It is used only to produce the suggestions you see. Things you paste or forward stay in your review queue until you approve them. High-confidence school-mail auto-accept only runs when the household turns Auto-add clear school dates on in Settings. That switch is off by default. When it is on, a clearly dated item can go straight onto the board and, if writing confirmed dates to your calendar is also on, onto your calendar. Anything unclear still waits in Review.
Where your data lives
Your data is stored in Supabase (US region) in a database secured with row-level security: only members of your household can read your household’s board, and only you can read your account settings. Uploads live in private storage — never publicly accessible.
What we never do
- We never sell your data — to anyone, ever.
- There are no ads and no third-party advertising trackers in Kinboard.
- Your family’s data is used only to run the service for you — not to train models for other purposes, not for profiling, and not shared with other households.
Opt-in features only
Push notifications and calendar feeds are optional. Push reminders are sent only to devices where you explicitly enabled them, and you can turn them off in Settings or in your browser. Calendar feeds use an unguessable private link that only works because you choose to share it with your calendar app — you can regenerate it at any time.
Google user data — Limited Use
If you sign in with Google, Kinboard receives only your basic profile information (name and email) to identify your account.
Kinboard’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Connected school email
You can optionally connect one school, college, or organization mailbox per kid. That is separate from the account you use to sign in. Kinboard requests read-only access: Gmail scope gmail.readonly, or Microsoft Graph Mail.Read. We never send, modify, or delete mail.
Only messages that look like school mail are processed — sender domains such as .edu, .k12, .ac, and .sch, school words, the mailbox’s own organization domain, and flyer-style attachments. Newsletters, promotions, and personal mail are skipped. Message text that we do keep is sent to NVIDIA NIM (NVIDIA API Catalog) for extraction, with Google Gemini as the fallback, the same way other sources are.
Access and refresh tokens are encrypted at rest with AES-256-GCM. Disconnect anytime from Settings and the tokens are deleted immediately. For Google we also revoke the grant at Google. Deleting a kid or the household deletes the connection with it.
If auto-add is on (it starts on), Kinboard asks for calendar.events on Google or Calendars.ReadWrite on Microsoft, and uses that only to create, update, and delete Kinboard events on your calendar. Declining the calendar step never blocks the mailbox connection.
Kinboard’s use of Gmail data adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only to provide the family board you asked for. It is not sold, not used for ads, and not used to train generalized models.
Deleting your data
You can delete items, uploaded files, or your entire household (board, people and history) from Settings at any time — deleting your household removes its data for every member. Deleting your account removes your profile and membership. You can also ask us to delete everything by emailing ankursultaniya431@gmail.com. We may keep minimal records where the law requires it.
Children’s information
Kinboard is designed for parents and guardians to manage family logistics. Household members can include children (names and the events that concern them), but accounts are created and controlled by adults. If you believe a child’s personal information was provided without a parent or guardian’s consent, contact us and we’ll delete it.
Changes to this policy
If we change this policy materially, we’ll update the effective date above and, where it matters, tell you in the app before the change takes effect.
Contact
Reach us at ankursultaniya431@gmail.com for any privacy question, request, or deletion.