Kin

Privacy Policy

Last updated: 24 August 2026

In short

Kin keeps your ledger on your phone. If you never sign in, nothing you record leaves the device. If you do sign in, a copy is stored on our server so your other devices — and the people you deliberately share a group with — can see it.

We do not track you. Kin contains no advertising, no analytics and no crash-reporting SDKs of any kind: the only third-party code in the app is Google’s sign-in library and two networking libraries. We sell nothing to anyone, and we show no ads.

Who is responsible

Samsonov Stepan Dmitrievich, an individual developer resident in the Russian Federation, is the controller of the personal data described below.

Contact: privacy@kin-app.org

What never leaves your phone

Until you sign in, Kin is entirely local. Your transactions, accounts, categories, budgets and receipt photos are stored in the app’s own database on the device and are not transmitted anywhere. Deleting the app deletes them.

What we receive when you sign in

Identity. Your email address; a stable identifier issued by Apple or Google when you use their sign-in; the display name you set, or the one Apple or Google hands over. We never see and never store a password. If you use Sign in with Apple and choose “Hide My Email”, we only ever see the @privaterelay.appleid.com relay address.

Your ledger. Transactions (amount, currency, date, note, category, tags), accounts and the banks or wallets they belong to, categories, tags, budgets, scheduled rules, and the exchange rates that were applied.

Shared expenses. Groups you take part in, the bills inside them, who paid and who owes whom, settlements, and the names of the participants and guests you add — including names of people who have no Kin account of their own, because you typed them in.

Receipts. Photographs you attach to a transaction.

Devices. The platform (iOS) and the device name your phone reports, so that you can tell your own devices apart.

Technical data. The IP address of the request that asks for a sign-in code, kept in order to limit how often codes can be requested and so make abuse of the service harder. Server access logs record the HTTP method, the path and how long the request took; they do not record IP addresses or request bodies.

Why we process it

To provide the service you asked for — storing, synchronising and sharing your ledger — which under the GDPR is performance of a contract (Art. 6(1)(b)). The IP address behind a sign-in request is processed on the basis of our legitimate interest in keeping the service usable and resistant to abuse (Art. 6(1)(f)).

Who else sees your data

That is the entire list. There are no advertising networks, no analytics services and no data brokers involved, and we do not sell or rent data to anybody.

What other people see

Inside a shared group, the other members see the bills in that group: the amounts, the notes, who paid, the balances, and the display name you chose. Your personal ledger — your own accounts, budgets and the transactions outside that group — is never visible to them.

Where your data is stored

On a server in the Netherlands (European Union). If you are in Russia, this means your data is stored outside the Russian Federation. Traffic between the app and the server is encrypted with TLS.

How long we keep it

Your ledger is kept for as long as your account exists. When you delete something in the app, Kin keeps a marker — an identifier and a timestamp, with no content — so that your other devices learn that the item is gone.

Sign-in code records expire after 10 minutes and are retained for a short period afterwards purely to enforce the hourly request limit. Server access logs are rotated by the host and are not archived.

When you delete your account, everything is erased within 30 days.

Your rights

You may ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, or hand it over in a portable form. Write to privacy@kin-app.org from the address your account uses and we will answer within 30 days.

If you are in the EU or EEA you may also complain to a supervisory authority — for data stored in the Netherlands that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

Deleting your account

In the app: More → Account → Delete the account. It erases the account and everything in it, and there is no undo. If you cannot get into the app, write to privacy@kin-app.org from the address the account uses and we will do it for you within 30 days.

Signing out is not deletion. It removes the local copy from that phone and leaves the account where it is.

Two things survive, and cannot be otherwise: entries in a shared group stay visible to the other members of that group, because they are their records of a shared expense as much as yours — your name on them becomes “Deleted user”. Backups roll over on their own schedule and are overwritten within 30 days.

Children

Kin is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.

Changes

If this policy changes in a way that matters, the date at the top changes and — where we can reach you — we tell you by email before the change takes effect.

Contact

privacy@kin-app.org

© 2026 Samsonov Stepan DmitrievichРусский