KinCue · Privacy
Privacy, without the fine-print fog.
This operational policy describes KinCue v1.0's current data boundary. It does not claim protections or automation that are not implemented.
Version 1.0 · Effective July 19, 2026
Operator and privacy contact
KinCue is operated by Sungchul Kim under the jurisdiction of the Republic of Korea. Privacy questions can be sent to sungchul7039@gmail.com.
The published privacy-request handling deadline is 30 days. Keep documents, child or family details, credentials, exports, and deletion evidence out of email; use the authenticated privacy controls for export and account-deletion requests.
What KinCue handles
When you choose Google sign-in, Google provides only the email address, display name, avatar, and authentication identifier allowed by the openid, email, and profile scopes to Supabase Auth. KinCue uses this Google user data only to sign you in, identify your account, and show your profile; it does not request access to Gmail, contacts, Google Drive, or Google Calendar data. Account data also includes language and timezone. Family data includes memberships, member labels, invitations, assignments, and shared settings.
When signed-in live analysis is enabled and requested, a private image, PDF, text note, or short self-authored voice memo is sent for analysis. Fixed public-demo analysis sends no source to OpenAI; if a guest deliberately chooses optional Live AI, only the selected fictional synthetic sample is sent. KinCue's current intake does not persist raw bytes, filenames, original audio, or transcriptions. Structured results can include titles, dates, tasks, items, family-member references, source quotes, confidence, and review history.
Operational data includes request IDs, timestamps, bounded error codes, retention choices, privacy-request status, a content-free AI-consent version and grant or withdrawal record, and encrypted push-subscription credentials. Application logs must never contain document bodies, child or family names, contact details, source quotes, transcripts, or exported data.
On the public landing page only, Cloudflare Web Analytics can receive page-load performance, landing path, referrer, browser, device, and coarse country metrics. SPA tracking is disabled and the beacon is not loaded on signed-in or dynamic-ID routes. KinCue also records only fixed demo event name, surface, UI language, schema version, timestamp, and count; it excludes IP, account, family, document, URL, user-agent, source, and free-form fields.
Why it is used
KinCue uses account and family data to authenticate users, isolate a family workspace, analyze a user-requested source, let a person review the result, build confirmed tasks and calendar items, export an event, send enabled reminders, secure the service, and answer privacy requests.
KinCue does not use family documents for advertising and does not automatically message, assign, or export anything before human confirmation.
Landing analytics is used to understand aggregate visits and performance; fixed product events measure whether the public demo starts and reaches confirmation. Analytics is not used to profile a family or track a person across products.
Processors and transmission
Before the first signed-in source is sent, the account holder must allow the current version of OpenAI processing. KinCue remembers that account-level choice, blocks future OpenAI calls after withdrawal, and asks again after withdrawal or a material policy-version change. The separate reminder to obtain permission before recording another person still applies to each recording.
When the signed-in live-AI gate is enabled and available, OpenAI receives a user-requested source through a server-only API request to produce structured analysis or speech-to-text. Fixed public-demo analysis makes no OpenAI request; optional guest Live AI sends only the selected fictional synthetic sample through the same server-only boundary. The OpenAI key is never sent to the browser. The operator must verify and disclose the production OpenAI account's API data controls and retention status before launch; Zero Data Retention is not claimed here.
Supabase provides authentication and the Postgres database for account, family, structured-result, audit, and privacy-request data. Cloudflare provides application delivery and server execution. These providers may process data in locations selected by or applicable to the operator.
Cloudflare also provides the landing-page Web Analytics beacon and a server-side Analytics Engine dataset for the fixed demo events described above. Cloudflare documents seven days of unsampled beacon data followed by aggregation and sampling, with Web Analytics reports available for up to six months; the operator must re-verify provider terms before launch.
Retention choices
Every current mode deletes or avoids storing raw originals and audio after analysis. “Delete after analysis” is the conservative default: the raw source is absent while the structured family result remains until explicit deletion. “7 days” and “30 days” schedule deletion of a future structured document and all database rows derived from it. “Keep until deleted” keeps the structured result until a person deletes it.
A preference applies to documents created after the setting changes; it does not silently rewrite existing schedules. Per-document deletion immediately cascades through its derived database rows. Retention cleanup never operates on a record marked as holding a raw file.
Security and encryption boundaries
HTTPS/TLS protects traffic in transit. Supabase supplies provider-managed encryption at rest for stored database data. KinCue does not currently add application-level content encryption to structured family records, so this policy does not describe them as end-to-end encrypted.
Raw source files are not stored by the current intake. Push-subscription endpoint credentials use a separate application-encrypted representation and are not document content. Access is also limited by authenticated claims, family-scoped row-level security, checked database functions, and private no-store API responses.
Children and family context
KinCue is designed for adult account holders coordinating family logistics, not for children to create accounts. An adult should enter only information they are authorized to manage, minimize child details, and obtain consent and follow local law before recording another person's voice or conversation.
Family workspaces are shared. A member may see structured information available to that family. Account deletion cannot strand a shared family without an owner or delete a family owned by someone else.
International processing
KinCue's configured operating jurisdiction is the Republic of Korea. OpenAI, Supabase, and Cloudflare may process data outside the Republic of Korea. Before production, the operator must choose available regions, execute required data-processing terms, document transfer safeguards, and complete the applicable legal review; those steps are not claimed as complete here.
Your choices and requests
An account holder can correct reviewed results, delete an individual document and its derived items, change future retention, allow or withdraw future AI processing, and create durable export or account-deletion requests in Settings → Privacy. Withdrawing AI processing does not delete already reviewed structured results; those remain subject to the selected retention setting.
Account deletion requires operator verification, session revocation, safe ownership transfer or solo-family cleanup, database deletion, and Supabase Auth administration. Export and deletion requests are fulfilled through the documented operator procedure.
Privacy contact: sungchul7039@gmail.com. The privacy-request handling deadline is 30 days. Do not send documents, child details, credentials, or other sensitive information through email or a public issue tracker.