Security

Your records deserve protection. Here is how KinNest handles them.

KinNest helps you organise important records, documents and personal wishes. This information deserves protection. Here is how account access, sharing and storage work today.

Records and account access
Account login credentialsNEVER ASKED FOR
Financial account connectionsNOT REQUESTED
Your moneyNEVER TOUCHED
Keep access credentials separately
Your information

Records, credentials and access.

KinNest does not ask for access to your financial accounts or login credentials. We recommend keeping passwords, PINs and other access credentials separately, and recording where to find them in KinNest.

Your record

Keep useful information together

Record details of accounts and assets, add documents, and leave notes and personal wishes for the people you trust.

Your credentials

Keep the means of access separately

We recommend recording where credentials are kept. For crypto, credentials include private keys and recovery phrases.

Your choices

Manage who can receive your record

Naming someone does not give them access. Access follows your sharing choices or the handover process.

In plain words

What KinNest has — and what we never do.

What KinNest has, and how it's guarded
  • YESYour records, notes, letters, documents and photos — the information you choose to keep for yourself and the people you trust.
  • YESLocked behind your PIN on your phone. The Android app adds a 6-digit lock on top of your sign-in. On the web there is no PIN — the sign-in and two-step are the protection, so sign out when you use a shared computer. Naming someone alone does not grant access to your record.
  • YESThe handover is decided on our servers — never by a phone or an app trick. There is no shortcut around the waiting checks.
  • YESEvery entry carries a seal that shows if anything was changed, and every important action is written into a record that can't be quietly edited.
What we never do
  • NOWe do not request account credentials. We recommend keeping them separately. Some fields restrict detected credentials; notes and letters offer a warning. These checks cannot identify every sensitive detail.
  • NONo bank logins, no account linking. KinNest does not access your financial accounts or move money.
  • NONo ads, no selling data. The subscription is how we earn, so your information never has to be.
  • NONo one browsing your record. Reading your entries is not part of anyone's job — and we're building toward a system where it isn't possible at all.
The handover

The handover has checks and a response period.

Opening your record is the most important moment, so it is guarded like this:

01
KinNest always assumes you're alive.

As long as you answer a gentle check-in, nothing moves. One tap resets everything.

02
One report is never enough.

If someone reports that something has happened to you, nothing opens at once. You are told, and there is always a waiting period.

03
You always get the last word.

Before anything opens you are reached for days — by email, and on your phone if you have notifications on. A single "I'm fine" stops it at once — and your word outranks theirs every time, for as long as you keep checking in.

04
Even then — only to the people you named.

Your record opens only to the addresses you gave us, each one verified in that person’s own KinNest account. Never on request, and never to anyone who simply asks. The one thing we cannot check is whether the address you typed belongs to the person you meant — so when you save it the app tests that the domain really accepts mail, and refuses one that does not exist.

One more thing, said plainly

KinNest is in early access, and before opening it widely we have set one clear requirement: your most sensitive details encrypted so that we cannot read them. That is not true yet: today your record is encrypted in transit and at rest, and we hold the keys — so we do not read it is the honest verb, and we cannot would not be. We will not launch broadly until it is. You'll see it stated here, plainly, on the day it is true — and not before.

Your data stays yours in the ordinary ways too: delete everything whenever you want. One thing survives any deletion, by anyone: the trail of what the release machinery actually did — that a check-in happened, that a report was filed, and when. It holds nothing from your record. It is a record of what happened and when, and nothing more.

Found a problem?

Report a vulnerability.

If you have found a flaw, we want to hear it. We read every report from a person, and we answer.

01
Write to security@kinnest.in.

Tell us what you did and what you saw. Our contact is also published for scanners at /.well-known/security.txt.

02
Test in good faith, and we will not come after you.

If you act in good faith — avoiding privacy violations and data destruction, and giving us reasonable time to fix the issue before making it public — we will not pursue or support legal action against you.

03
We tell you when it is fixed.

You get a reply, a fix, and word from us when it is done.

Get early access Free 30-day trial · No ads, and we never sell your data