Plain-English Summary: We collect what we need to run the service. We don't sell your data. Health data and voice prints are treated with the highest sensitivity. You can export or delete everything. We use a handful of trusted third-party services — all listed below.

Table of Contents

  1. Who We Are
  2. Data We Collect
  3. Sensitive & Special Category Data
  4. How We Use Your Data
  5. Legal Basis for Processing (GDPR)
  6. Data Sharing & Disclosure
  7. Sub-Processors
  8. Data Retention
  9. Security
  10. California Residents (CCPA)
  11. EU/EEA Residents (GDPR)
  12. Illinois Residents (BIPA)
  13. Children's Privacy
  14. Cookies & Analytics
  15. Data Deletion
  16. Contact & DPO

1. Who We Are

KinBridge ("we," "us," "our") is operated by KinBridge Inc. We are the data controller for personal data processed through kinbridge.polsia.app. Our primary contact for privacy matters is privacy@kinbridge.app.

2. Data We Collect

Account & Profile Data

Conversation Data

Health & Wearable Data

When you connect a wearable device via Terra, we receive:

Technical & Usage Data

3. Sensitive & Special Category Data

Health Data

Health metrics constitute sensitive personal information under CCPA and special category data under GDPR Article 9. We process health data solely to provide the health monitoring features you enable. Health data is never used for advertising, profiling for non-service purposes, or sold.

Biometric Data (Voice Prints)

If you use the Last Words voice cloning feature, we collect a voice print — a biometric identifier. This is the most sensitive category of data we process. Key protections:

Spiritual & Religious Preferences

We may process spiritual or religious preferences you voluntarily provide to personalize companion interactions. This is a special category under GDPR Article 9. We process it solely to deliver your selected experience and never share it with third parties for commercial purposes.

End-of-Life & Bereavement Data

Last Words projects and farewell content are treated with the highest confidentiality. Access is restricted to the account holder and authorized family members you designate. This data is never used in aggregate analytics or shared with third parties except as required to deliver the service (e.g., voice synthesis providers under NDA).

4. How We Use Your Data

PurposeData UsedBasis
Provide AI companion conversationsProfile, conversation dataContract performance
Display health metrics dashboardWearable/health dataContract + consent
Generate Heartfelt MomentsConversation dataContract performance
Create voice clone for Last WordsVoice print (biometric)Explicit consent
Process paymentsBilling data (via Stripe)Contract performance
Send account & service emailsEmail addressContract / Legitimate interest
Improve platform (aggregate, anonymized)Usage dataLegitimate interest
Comply with legal obligationsAs required by lawLegal obligation
Detect fraud and abuseAccount, technical dataLegitimate interest

We do not use your data for advertising. We do not sell your data. We do not use health or biometric data to train AI models without explicit, separate consent.

For EU/EEA users, our legal bases are:

6. Data Sharing & Disclosure

We share data only in these circumstances:

We never sell personal data. We never share health or biometric data with insurers, employers (except enterprise customers with BAAs), or advertisers.

7. Sub-Processors

We use the following third-party sub-processors. All are bound by data processing agreements (DPAs) with appropriate protections.

ProcessorPurposeLocationData Processed
Neon / RenderDatabase & hosting infrastructureUSAAll user data
StripePayment processingUSABilling information
AnthropicAI language model (companion conversations)USAConversation messages
TerraWearable device data aggregationUSAHealth & wearable data
ElevenLabs / Voice AI ProviderVoice synthesis for Last WordsUSAVoice recordings (biometric)
TwilioSMS messaging (daily check-ins)USAPhone number, message content
PostmarkTransactional emailUSAEmail address, message content
Cloudflare R2Media file storageUSAAudio files, images, documents

This list is maintained and updated as processors change. Enterprise customers may request immediate notification of processor changes by emailing enterprise@kinbridge.app.

8. Data Retention

Data TypeRetention PeriodBasis
Account & profile dataDuration of account + 30 days after closureContract
Conversation dataDuration of account + 30 daysContract
Health & wearable dataDuration of account + 30 daysConsent
Voice print (biometric)Duration of consent (max 3 years) or account closureExplicit consent
Farewell / Last Words contentDuration of account; exportable on requestContract
Billing records7 yearsLegal obligation (tax)
Consent audit logs10 yearsLegal / regulatory
Server logs90 daysLegitimate interest (security)

9. Security

We implement technical and organizational security measures appropriate for the sensitivity of the data. Key measures include:

For full security details, see our Security page.

10. California Residents (CCPA / CPRA)

California residents have specific rights under the California Consumer Privacy Act (CCPA) as amended by the CPRA.

Your Rights

Categories of Personal Information (past 12 months)

We collect: Identifiers, Commercial information (billing), Internet or electronic network activity, Health information, Biometric information (voice print, if applicable), Inferences drawn from other data.

Submit a CCPA Request

Email privacy@kinbridge.app with subject "CCPA Request." We will respond within 45 days.

11. EU/EEA Residents (GDPR)

EU/EEA residents have rights under the General Data Protection Regulation (GDPR).

Your Rights

International Transfers

Data is processed primarily in the USA. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for international transfers. Enterprise DPAs include SCCs on request.

Lodge a Complaint

You may lodge a complaint with your national supervisory authority. Contact us first at privacy@kinbridge.app — we aim to resolve all concerns within 30 days.

12. Illinois Residents (BIPA)

Illinois residents using voice cloning features are protected by the Biometric Information Privacy Act (740 ILCS 14).

Our BIPA compliance commitments:

To request destruction of your biometric data, contact privacy@kinbridge.app.

13. Children's Privacy

KinBridge is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact privacy@kinbridge.app immediately for deletion.

14. Cookies & Analytics

We use cookies and similar technologies for:

We do not use advertising cookies or behavioral tracking cookies.

15. Data Deletion

You can delete your account and all associated data through:

Upon deletion request:

16. Contact & DPO

Privacy inquiries: privacy@kinbridge.app
Data deletion requests: privacy@kinbridge.app
Enterprise / DPA: enterprise@kinbridge.app
GDPR Data Protection Officer: dpo@kinbridge.app

We aim to acknowledge all privacy requests within 3 business days and resolve them within 30 days (45 days for CCPA requests).