Privacy Policy

>

Last updated: 12 August 2026

The short version

KinNest is a private record of what you own and where to find it, held so that the people you name can reach it if something happens to you. We are paid by subscription. We do not sell your data, we do not advertise, and we do not read your record.

Three things matter more than anything else in this document:

Who we are

KinNest is operated by A2D Consultancy Services ("we", "us"), a business registered in India, of which Built4U Apps is a division. We are the data fiduciary for the personal data described here under India's Digital Personal Data Protection Act, 2023 (DPDPA).

What we hold, and why

Your account. Your email address, your name, your date of birth, and the country you live in. The email address is your account and the only way back into it — we cannot change it for you, which is a deliberate protection against someone else changing it. Date of birth exists for one reason: KinNest is not for under-18s. If you turn on WhatsApp reminders (when that channel exists) we hold the phone number you give for that purpose alone; it is never a way to sign in.

Your record. Whatever you choose to write down: entries describing what you own and where the papers are, the notes you add, the letters you write, the documents and photos you attach, and the names and dates of birth of any children you record. We do not read it, index it, analyse it, or train anything on it.

The people you name. Your nominees' names, email addresses, relationship to you, and optionally a phone number — supplied by you, about them. We contact them on your behalf, and we tell them what their role means.

How the app is used, in aggregate only. We keep counts — how many people completed signup, how many finished the tour, how many recorded a first entry — as whole numbers, month by month. These counters carry no user identifier, no timestamps about any individual, and nothing from your record. A counter can tell us "how many"; it can never tell us "who". We use no third-party analytics, no advertising identifiers and no tracking software of any kind.

Technical necessities. Your device's notification token (so we can reach you), your time zone (so reminders arrive at a civil hour where you actually are), and standard security logs kept by our infrastructure provider.

What we do NOT hold

When your record is shared, and with whom

This is the heart of the product, so it is stated precisely.

1. While you are checking in, nothing is shared. Your nominees can see that you named them. They see nothing of your record. 2. If you go quiet, we remind you first — for several days, on every channel you have allowed. Only then do we ask the people you named to check on you, and we tell them nothing about your record when we do. 3. A nominee can report that you are unavailable. We verify nothing about that report. We tell you at once, and your record opens to your nominees only after a further seven days of your silence. One tap from you stops it, at any point. 4. You can share your record deliberately, at any time, with a nominee who has accepted — and close it again. We tell you when they open it. 5. We do not disclose your record to anyone else — not to family who ask, not to anyone claiming authority — except where Indian law compels us, in which case we will tell you unless we are legally forbidden from doing so.

Where your data lives

On Google Cloud infrastructure (Firebase) in asia-south1, Mumbai, India. If you or your nominees are outside India, that data still rests in India; the transfer to reach you is governed by standard contractual protections. We do not move your record to another region.

How long we keep it

As long as your account exists. When you delete your account, your record, your files and your account are erased.

The one exception, and why it exists: a small, tamper-evident log of release events — that a report was filed, that you checked in, that a record was shared — survives account deletion. It contains no content from your record: only what happened and when. It exists because the release machinery is the part of this product that could most seriously go wrong, and if it ever did, that log is the only evidence of what actually occurred — for you or your family, not for us. It is not used for any other purpose.

If you simply stop using KinNest without deleting your account, we will write to you before taking any action, and never delete anything without warning you first.

Your rights (DPDPA 2023)

You can, at any time and mostly from inside the app itself:

We will answer a request within 30 days, and usually far sooner.

Children

KinNest is for adults; you must be 18 or older, and we ask your date of birth to enforce that. You may record that a child exists — their name and date of birth — so that the people you name know about them. That is an existence record you write about your own family; children do not have KinNest accounts, are never contacted by us, and nothing is addressed to them.

Security

The security design is the product, so it is not a paragraph of reassurance:

No system is perfect. If a breach ever affects your data we will notify you and the Data Protection Board as the law requires, and tell you plainly what happened.

Changes

If we change this policy we will say what changed, in the app, and record the date. Where a change is material, we will ask you to accept it rather than assume it.

This policy describes KinNest as it actually works. If you find something here that does not match what the app does, that is a defect and we want to hear about it: contact@kinnest.in.