Last updated: April 6, 2026
When you create a KinKeep account, we collect your name, email address, hashed password, and role (primary caregiver or invited caregiver).
For each senior profile you create, we collect: name, date of birth, relationship to caregiver, state of residence, veteran status, VA file number (if applicable), phone number, and timezone.
KinKeep collects health-related information that you provide, including:
When you connect financial accounts through Plaid, we collect: bank account metadata (institution name, account type, last four digits), up to 90 days of transaction history, subscription detection results, and fraud analysis results. We do not store your bank login credentials.
KinKeep allows you to upload and store documents such as wills, trusts, insurance policies, medical records, financial documents, and government-issued identification. All uploaded documents are encrypted and stored via Vercel Blob.
We process email content submitted for fraud and scam scanning, and SMS metadata for notification delivery and verification.
We automatically collect user agent strings, IP addresses, and activity logs when you use KinKeep.
Payment processing is handled by Stripe. We store only your Stripe customer ID and subscription ID. We do not store credit card numbers or other payment method details on our servers.
We use the information we collect to:
For users in the European Economic Area (EEA), we process your personal data on the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and management | Contract |
| Health data processing | Explicit consent |
| Financial data processing | Explicit consent |
| AI analysis | Legitimate interest + consent |
| SMS notifications | Explicit consent |
| Email (transactional) | Contract |
| Email (marketing) | Consent |
| Necessary cookies | Legitimate interest |
| Analytics cookies | Consent |
We share data with the following sub-processors to provide the KinKeep service:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Plaid | Bank account linking and financial data retrieval | Financial data | US |
| Stripe | Payment processing | Email, subscription data | US |
| Anthropic (Claude) | AI analysis | Email/mail content, medication data | US |
| Twilio | SMS notifications | Phone numbers, message content | US |
| Resend | Email delivery | Email addresses, email content | US |
| Vercel | Hosting and document storage (Blob) | All data in transit, uploaded documents | US |
| Neon | Database | All stored data | US |
| Upstash | Rate limiting | IP addresses, request metadata | US |
We never sell your personal data. We share data only in the following circumstances:
You may request account deletion from your account settings or by contacting support. Upon deletion request, your account enters a 30-day grace period during which you may reverse the deletion.
After the grace period, we perform a hard delete that includes:
Legal representatives may request account deletion on behalf of a deceased user by providing a death certificate and documentation establishing legal authority to legal@trykinkeep.com.
You may request a data export from your account settings. KinKeep will generate a JSON archive containing all data associated with your account, including senior profiles, health data, financial data, documents, and activity logs. A secure download link will be provided within 48 hours of your request.
We implement the following security measures to protect your data:
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at privacy@trykinkeep.com.
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
Categories of personal information we collect:
Categories sold: NONE. We do not sell any personal information.
Categories disclosed to sub-processors: Identifiers and service data are disclosed to sub-processors solely for the purpose of providing the KinKeep service.
KinKeep complies with applicable state health privacy laws, including:
All KinKeep data is processed and stored within the United States. All of our sub-processors are US-based. For users in the European Union or European Economic Area, data transfers to the United States are conducted under Standard Contractual Clauses (SCCs) as approved by the European Commission.
KinKeep is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe that we have inadvertently collected information from a child under 13, please contact us at privacy@trykinkeep.com.
KinKeep uses automated processing to provide certain features, including:
These automated processes are not legally binding and do not produce legal effects. They are designed to assist caregivers and are informational only. You have the right to request human review of any automated decision by contacting us at privacy@trykinkeep.com.
In the event of a data breach that affects your personal information, KinKeep will notify affected users within 72 hours of becoming aware of the breach. Notification will be provided via email and in-app alert and will include:
We will also notify relevant authorities as required by applicable law.
Material changes:For material changes to this Privacy Policy, we will provide at least 30 days' advance notice via email and may require re-consent before the changes take effect.
Non-material changes:Non-material changes (such as clarifications or corrections) will become effective upon posting to this page with an updated "Last updated" date.
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at privacy@trykinkeep.com.