Version: 2026-10-03 · Last updated: 3 October 2026
The short version
KinNest is a private record of what you own and where to find it, held so that the people you name can reach it if something happens to you. We are paid by subscription. We do not sell your data, we do not advertise, and we do not read your record.
Three things matter more than anything else in this document:
- Records and account access. KinNest does not ask for access to your financial accounts or login credentials. We recommend keeping passwords, PINs and other access credentials separately, and recording where to find them in KinNest.
- Nobody sees your record unless something happens to you, or you choose to share it. Not your nominees, not us.
- You can delete everything, at any time, from inside the app. Two exceptions, stated plainly below — one protects you, and one is a single date that is not about you.
Who we are
KinNest is owned and operated by Built4U Apps Private Limited ("we", "us"), a company registered in India. We are the data fiduciary for the personal data described here under India's Digital Personal Data Protection Act, 2023 (DPDPA).
- General contact: contact@kinnest.in
- Grievances (DPDPA §13 / IT Rules): grievance@kinnest.in
- Security reports: security@kinnest.in
- Data-protection questions, including from the EU and UK: privacy@kinnest.in
What we hold, and why
Your account. Your email address, your name, your date of birth, and the country you live in. The email address is your account and the only way back into it — we cannot change it for you, which is a deliberate protection against someone else changing it. Date of birth exists for one reason: KinNest is not for under-18s. You may also save an optional phone number as a private contact detail in your account and edit or remove it in Your details. This saved number is unverified, is not shared with your nominees, and is never a way to sign in. Saving it does not turn on WhatsApp or SMS messages or give consent to receive them. If WhatsApp becomes available, verification and your explicit consent will be required separately before we use a number for that channel.
Your record. Whatever you choose to write down: entries describing what you own and where the papers are, the notes you add, the letters you write, the documents and photos you attach, and the names and dates of birth of any children you record. We do not read it, index it, analyse it, or train anything on it.
The people you name. Your nominees' names, email addresses, relationship to you, and optionally a phone number — supplied by you, about them. We contact them on your behalf, and we tell them what their role means.
How the app is used, in aggregate only. We keep a small set of counts — how many people completed signup, named a nominee, sent an invitation, had a nominee accept, and recorded a first entry; how many accounts our three-year inactivity rule warned, closed, or kept because they were paying, were named by somebody, or were holding a record left to them; and how many people who were named by somebody went on to keep a record of their own. We also keep three totals each month: how many accounts hold a record, how many are named by somebody without holding one, and how many are neither. All of it as whole numbers, month by month. These counters carry no user identifier, no timestamps about any individual, and nothing from your record. A counter can tell us "how many"; it can never tell us "who". We use no analytics product, no advertising identifiers and nothing that follows you between apps or websites. When paid subscriptions begin, a payment provider will handle billing and be told an account identifier and what you bought — never anything from your record — and this page will name that provider before the first payment is taken.
When the app crashes. The app reports crashes and errors to Google Firebase Crashlytics so that we can find and fix them. A report carries the technical facts of the failure — where in our code it happened, the error our own systems returned, your device model, its operating system version and an identifier for the installation. It does not carry anything from your record: no entry, no name you have written down, no document, no photograph, and no message you have written to anyone. Google processes this on our behalf as a data processor. If we could fix a crash without knowing the device it happened on we would, but we cannot, and an app whose failures we cannot see is one we cannot make safe.
Technical necessities. Your device's notification token (so we can reach you), your time zone (so reminders arrive at a civil hour where you actually are), and standard security logs kept by our infrastructure provider.
Account access and information we do not collect
- Account credentials. KinNest does not ask for access to your financial accounts or login credentials. We recommend keeping passwords, PINs and other access credentials separately, and recording where to find them in KinNest. Notes, letters and uploads can contain information you choose to add; input checks cannot guarantee that every credential is detected. Your KinNest sign-in and app-lock credentials are separate from the credentials for accounts you record.
- Payment card details. Subscriptions are billed by Google Play; we never see your card.
- Your location, your contacts list, your other apps, or your browsing.
- Your payment card, your location, your contacts, your other apps and your browsing — none of which we hold, and most of which we could not reach if we wanted to: KinNest asks Android for three permissions in total (camera, internet, notifications).
One thing we will not overstate
We do not read your record. Nobody at KinNest reads your entries; it is not part of anyone's job and no support process involves it.
That is a rule we hold ourselves to, not yet a mathematical impossibility. Your record is encrypted in transit and at rest, and access to production data is limited to keeping the service running — but we hold the keys, so "we do not" is the honest verb and "we cannot" would not be. Before KinNest opens to the public we will make the most sensitive parts unreadable to us in a way that does not depend on our good behaviour, and we will state it plainly here on the day that is true, and not before.
When your record is shared, and with whom
This is the heart of the product, so it is stated precisely.
1. While you are checking in, nothing is shared. Your nominees can see that you named them. They see nothing of your record. 2. If you go quiet, we remind you first — for several days, on every channel you have allowed. Only then do we ask the people you named to check on you, and we tell them nothing about your record when we do. 3. A nominee can report that you are unavailable. We verify nothing about that report. We tell you at once, and your record opens to your nominees only after a further seven days of your silence. One tap from you stops it, at any point. 4. You can share your record deliberately, at any time, with a nominee who has accepted — and close it again. We tell you when they open it. 5. We do not disclose your record to anyone else — not to family who ask, not to anyone claiming authority — except where Indian law compels us, in which case we will tell you unless we are legally forbidden from doing so.
Where your data lives
On Google Cloud infrastructure (Firebase) in asia-south1, Mumbai, India — one region, always. We do not move your record to another region, and we do not keep a copy anywhere else.
If you are in the EU or the UK, this means your data is stored in India, a country without a European adequacy decision. The transfer therefore relies on the Standard Contractual Clauses incorporated into Google Cloud's data-processing terms, together with the technical measures described under Security below. We are the controller; Google is our processor and does not use your data for its own purposes.
Wherever you live, the same thing is true of the record itself: it is readable only by your own account, enforced by server-side rules rather than by the app choosing to behave.
How long we keep it
While you are using it, and for three years of complete silence after that. If you stop checking in, stop signing in and stop answering us for three years, we close the account and erase the record — and we write to you two months before that happens, so the last thing that occurs is never the first you hear of it. Signing in once stops the clock.
When you delete your account, your record, your files and your account are erased.
The first exception, and why it exists: a small, tamper-evident log of release events — that a report was filed, that you checked in, that a record was shared — survives account deletion. It contains no content from your record: only what happened and when. It exists because the release machinery is the part of this product that could most seriously go wrong, and if it ever did, that log is the only evidence of what actually occurred — for you or your family, not for us. It is not used for any other purpose.
That log is kept for ten years, and then it is deleted too. It is the longest thing we keep, and it is the only thing that outlives the record it refers to — so the period is stated here rather than left open. An exception with no end date is a promise to keep it for ever.
The second exception is one number, and it is not about you. When an account is deleted we keep a record that this email address once started a free trial — the date, and nothing else. The address itself is not kept: it is stored as a one-way fingerprint that cannot be turned back into an address, and the entry carries no name, no account and nothing whatever from the record. It exists so that the 30-day free trial is one free trial per person rather than a fresh one every time an account is deleted and remade. If you sign up again with the same address you keep your account and your record in full — only the trial does not start over.
If you simply stop using KinNest without deleting your account, we will write to you before taking any action, and never delete anything without warning you first.
The same promise covers our own shutdown. If KinNest itself ever has to wind down, we give at least 90 days' notice on every channel, you can export your record to keep offline through that whole window, and nothing is deleted without that warning — for any reason. The full commitment, including the backstop that makes it credible, is in our continuity policy.
Your rights (DPDPA 2023)
You can, at any time and mostly from inside the app itself:
- See everything we hold — it is the record you wrote; the app shows all of it.
- Correct it — every field is editable.
- Erase it — Settings → Clear my data permanently erases your data and keeps your account; Settings → Delete my account erases both.
- Withdraw consent — deleting your account withdraws it entirely.
- Nominate someone under DPDPA §14 to exercise these rights if you cannot.
- Complain — write to our grievance officer above. If we do not resolve it to your satisfaction, you may approach the Data Protection Board of India.
We will answer a request within 30 days, and usually far sooner.
Reaching us from the EU or the UK
KinNest is available worldwide, so some of the people using it — and some of the people they name — live in the EU or the UK. Where the GDPR or the UK GDPR applies to you, this is how it works in practice.
Why we are allowed to hold your data. For your account and your record, because you asked us to: we cannot provide KinNest without them (Article 6(1)(b) — performance of a contract). For the release machinery — the check-ins, the reminders, and reaching the people you named — the same contract, because that mechanism is the product. For the small tamper-evident log of release events described above, our legitimate interest in being able to show what actually happened if the machinery is ever disputed (Article 6(1)(f)).
Your nominee's data, and why they hear from us at all. You give us another person's name and email address. They did not give it to us, so under Article 14 we tell them: the invitation we send them says who named them, what the role means, what we hold about them, and how to remove themselves — and any nominee can decline or resign at any point, which erases their side of it. We hold nothing else about them: no record of their own, no profile, no tracking. This is the part of KinNest that touches someone who never signed up, and we have tried to keep it to the minimum a person needs in order to say no.
Your rights. Access, rectification, erasure, restriction, portability, and objection — Articles 15 to 22. Most are immediate and self-service: the record is what you wrote and the app shows all of it, every field is editable, and Delete my account erases the account and the record together. For anything the app cannot do for you, write to privacy@kinnest.in and we will answer within one month. You do not need to give a reason, and exercising a right never costs anything.
Complaining. If we get it wrong, you can complain to your own supervisory authority — the data protection authority of the EU country you live in, or the Information Commissioner's Office in the UK — without going through us first. We would rather you told us as well, but that is your choice and not a condition.
Automated decisions. There are none in the sense Article 22 means. The release mechanism runs on a clock and on people answering questions, it is described in full on our website, and the owner's own tap outranks every other signal in it, always.
Two things we have not done yet, said plainly. We have not appointed an Article 27 representative in the EU or the UK, and we have not published written confirmation of the transfer clauses referred to above. Both are required before we market KinNest in Europe, and we will do them before we do that. Until then, write to privacy@kinnest.in and a person will answer.
Children
KinNest is for adults; you must be 18 or older, and we ask your date of birth to enforce that. You may record that a child exists — their name and date of birth — so that the people you name know about them. That is an existence record you write about your own family; children do not have KinNest accounts, are never contacted by us, and nothing is addressed to them.
Security
The security design is the product, so it is not a paragraph of reassurance:
- Everything travels encrypted, and is encrypted at rest by our infrastructure.
- Your record is readable only by your own account — enforced by server-side rules, not by the app being polite. Your nominees cannot read it, and neither can another user.
- Nobody at KinNest reads your record. Access to production data is limited to what is needed to keep the service running, and no support process involves reading your entries.
- Input guidance. Some identifier fields refuse detected credentials, and fields labelled for the last four digits offer masking. Notes and letters warn about detected credentials and allow you to continue. These checks do not inspect every possible secret or guarantee the contents of an upload.
- Delivered files are fetched one at a time, brokered by the server, and never left publicly addressable.
- We publish a security contact and welcome reports: security@kinnest.in.
No system is perfect. If a breach ever affects your data we will notify you and the Data Protection Board as the law requires, and tell you plainly what happened.
Changes
If we change this policy we will say what changed, in the app, and record the date. Where a change is material, we will ask you to accept it rather than assume it.
This policy describes KinNest as it actually works. If you find something here that does not match what the app does, that is a defect and we want to hear about it: contact@kinnest.in.