How it’s built

How KinNest actually works.

A tool that decides when to reach your family should be the last thing you take on faith. So here is how KinNest actually works — the switch drawn to scale, why the decision is made on our servers and never on a phone, and where today's protection ends and next year's begins.

How your record is guarded
StoredINDIA ONLY
Release decidedON THE SERVER
EncryptedIN TRANSIT & AT REST
Report a flawSECURITY@KINNEST.IN
Open to scrutiny — tell us what we have got wrong
The dead man's switch

Drawn to scale.

KinNest reaches your family only after a long, deliberate sequence — never a single missed tap. You choose the window — one month, two, or three. The ladder below is the three-month default, and these are the exact numbers the code counts, not a friendly approximation. Choose a shorter window and every number moves with it.

Days 0–83
Silence, on purpose.

An eligible, accepted Check in starts or resets the watch. Opening the app does not reset the watch.

Days 84–90
We ask you, and only you.

Seven days of once-a-day reminders — is everything alright? Nobody else is contacted. A single answer ends it here.

Day 91
Your named people are asked to check on you.

Only now, after ninety days of genuine silence, do the people you named hear from us — and they are asked to check on you, told nothing of your record.

Days 91–120
The primary nominee's window.

If your primary nominee reports you are gone, a further seven days must pass in continued silence before your record opens — and your own "I'm fine" outranks their report at any moment inside it.

Day 121
The backup nominee wakes.

If the primary never acts, a backup you named — dormant until this moment — is woken so the handover is never stranded on one person being unreachable too.

Your word wins, while the subscription is live.

For as long as you are subscribed and keep answering, nothing advances and nothing opens. A report is a request to wait — never a switch that fires. One tap from you stops everything, at any point on this line. If the subscription ends, that tap no longer moves the date; the next note says what happens then.

A lapsed subscription stops the date moving, not the clock.

If your subscription lapses the countdown carries on: on the fixed date we still reach out to the people you named and ask them to check on you. What ends is your ability to move that date by checking in — only subscribing again does that. Every message we send you offers the other door too: pause the countdown, from your own device. What that costs, in plain words →

Records and account access

Keep what matters, with care.

KinNest does not ask for access to your financial accounts or login credentials. We recommend keeping passwords, PINs and other access credentials separately, and recording where to find them in KinNest.

Your record
  • HOLDSDetails of your accounts and assets, and where to find them.
  • HOLDSYour notes, personal wishes and letters.
  • HOLDSDocuments and photos you choose to upload.
Account access
  • NOKinNest does not connect to your financial accounts or move your money.
  • TIPKeep passwords, PINs, private keys and recovery phrases separately.
  • TIPEntry checks offer guidance, but cannot detect every sensitive detail.

Your records can contain sensitive information. Limiting credentials does not replace protecting the records themselves.

Where the decision lives

The server decides. A phone cannot.

The most important rule in the whole system: a device can never talk itself, or anyone else, into an early handover. The state that governs release is guarded on the server, and the rules are enforced there — not left to the app to behave.

Server-authoritative state

A phone may only say "I'm alive."

The one thing your app is allowed to write to the release record is that you are ACTIVE, with the time of your last activity. Nothing else.

And that timestamp may only ever move forward, and never into the future — so a tampered client cannot backdate itself into the danger zone, or drag anyone toward a handover. Everything past that point is computed by the server alone.

A seal on every entry

Any change is detectable.

Each entry carries a cryptographic seal (SHA-256). When your record is prepared for your family, the server recomputes each seal and marks any entry whose seal no longer matches — so a silently altered entry is handed over openly flagged, never passed off as yours and never quietly dropped.

A seal proves integrity — that a thing is unchanged. It is honest to call it that, and wrong to call it secrecy; we say only the first.

An append-only trail

The machinery keeps its own receipts.

Every step the release machinery takes — a check-in, a report, a record opening — is written into a trail that cannot be quietly edited, and that survives even account deletion.

It holds nothing from your record: only what happened and when. If the one part of this product that could most seriously go wrong ever did, that trail is the evidence — for your family, not for us.

The locks around it

Attested, PIN-held, default-deny.

In the Android app your record sits behind an app lock bound to your account. We store your PIN in a form we cannot read back, which is why we can never tell you what it was — only help you set a new one. The web has no PIN; there your sign-in and two-step are the lock. Every request for your record is checked on our servers against rules that refuse anything they have not been told to allow.

You do not have to take the reach on faith either: from inside the app you can run a delivery readiness check and see exactly who your record would reach, and what would stop it, before you ever need it to work.

The honest boundary

What is true today, said plainly.

Your record is encrypted in transit, and at rest with AES-256 — the standard our infrastructure (Google Cloud) applies to everything it stores. Every entry carries a tamper-evident seal. Access is governed by strict server-side rules, and your data is stored in one place only — India. We never sell it, never advertise against it, and reading your entries is part of no one's job here.

Here is the line we will not blur: today, so that we can hand your record to your family if something happens to you, our systems can access it. Records and uploaded documents can contain sensitive information. Not-being-able-to is a different, stronger property — end-to-end encryption, where only the family you name holds the key — and it is the final layer we are building. We will say it here, plainly, on the day it is true, and not one day before.

If you want the full picture of what can go wrong and how each failure is answered, we publish it: read our threat model →

Get early access Read the security overview Free 30-day trial · No ads, and we never sell your data