Privacy policy
1. Who we are
Kindred is a weekly couples check-in app operated by Quiet Studios Ltd, a company registered in England and Wales (company number 17221945), trading as Kindred Connect ("Kindred Connect", "we", "us", "our"). Quiet Studios Ltd is the data controller responsible for your personal data under applicable data protection law. This privacy policy explains how we collect, use, store, and protect your personal information when you use the Kindred mobile application ("the App") and when you visit our website at kindredconnect.app ("the Site").
Contact:
Email: privacy@kindredconnect.app
Registered office: Quiet Studios Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
2. Information we collect
2.1 Account information
- Email address — used for authentication and account recovery.
- Display name — the name your partner sees within the App. This does not need to be your legal name.
- Sign-in method — you can create an account with an email address and password, or with Sign in with Apple. If you use Sign in with Apple, Apple sends us the email address on your Apple ID — a private relay address if you choose to hide your real one — and, if you allow it, your first name, which we store and use to prefill your display name during setup. You can change that name at any time.
- Consent records — when you give explicit consent to the processing of your check-in answers at account creation, we store who consented, when, and the exact wording you agreed to (see Section 4).
2.2 Relationship information
- Partner pairing data — when you create or join a relationship in the App, we store the link between your account and your partner's account.
- Invite codes — temporary codes used to pair partners. These expire and are single-use.
2.3 Check-in data
- Responses to check-in questions — including numerical ratings and free-text answers across wellness, connection, reflection, and forward-looking categories.
- Review comments — written reflections shared between partners during a check-in session.
- Commitments — tasks and habits you create, including descriptions, categories, and status.
- Habit review ratings — ratings you give on your partner's habits during check-ins.
- Personal notes — private notes you write for yourself, which may be linked to commitments or used during check-ins.
Check-in questions ask about your relationship and how you're both doing — topics such as your wellbeing, mental health, and intimacy. UK data protection law treats information like this (for example, about your health or your sex life) as "special category" data, so we handle all of your check-in answers to that standard and process them only with your explicit consent (see Section 4). You still decide what to write — you are never required to enter any particular detail to use the App.
2.4 Session data
- Check-in session metadata — timestamps, session status, and participation records.
- Session history — a permanent record of completed check-ins, including frozen snapshots of questions and commitments at the time of completion.
2.5 Device and technical data
- Push notification tokens — device-specific tokens used to deliver notifications (e.g., session-ended alerts, mid-week commitment reminders).
- Device identifiers — standard technical identifiers transmitted during app usage.
- Crash reports and diagnostic data — collected via Sentry to diagnose errors and improve app stability. This may include device type, operating system version, stack traces, network connectivity state, and a short trail of the steps taken in the App before an error — for example, screens opened, sign-in attempts, and subscription checks, along with any error codes those returned. While you are signed in, this data is associated with your account identifier so we can investigate problems affecting your account. When you sign out, we stop attaching your identifier to new reports; reports already queued on your device may still carry it when they are sent. It does not include the content of your check-in responses.
2.6 Subscription data
- Subscription status — whether your subscription is active, expired, or absent. Managed through RevenueCat and Apple's in-app purchase system.
- Subscription holder — a subscription is held by one account at a time and can move between accounts, for example if you and your partner change which of you pays. We store which account currently holds it.
- We do not collect or store payment card details. All payment processing is handled by Apple through the App Store.
3. How we use your information
We use your information for the following purposes:
- Providing the service — running check-in sessions, storing your responses, syncing data between partners in real time, and maintaining your check-in history.
- Partner pairing — connecting you with your partner via invite codes.
- Notifications — sending push notifications when your partner finishes or ends a check-in, for mid-week commitment reminders, and for account lifecycle events (deletion requested and completed); and sending transactional emails for account lifecycle events and subscription events (payment issues and subscription expiry).
- Subscription management — verifying your subscription status and managing access to premium features.
- Error monitoring and stability — using crash reports to identify and fix bugs.
- Product improvement — understanding usage patterns in aggregate to improve the App. The content of your check-in answers is never used for this or anything else: it is used only to run your check-ins and share them with your partner. We do not sell your data or use check-in content for advertising.
4. Legal basis for processing (GDPR)
If you are in the European Economic Area (EEA) or United Kingdom, we process your data under the following legal bases:
- Performance of a contract — processing necessary to provide the App and its features (account creation, check-ins, partner pairing, subscriptions).
- Legitimate interests — crash reporting, security, and aggregated product improvement, where these interests are not overridden by your rights.
- Consent — push notifications. You can withdraw this consent at any time through your device settings (see Section 8).
Special category data (Article 9). Your check-in answers are about your relationship and how you're both doing, which the UK GDPR treats as "special category" data — for example, details about your health, mental wellbeing, or sex life (see Section 2.3). We process your check-in answers only on the basis of your explicit consent under Article 9(2)(a) of the UK GDPR, which we ask for through a dedicated consent step when you set up your account. We keep a record of when you consented and the exact wording you agreed to. You can withdraw this consent at any time by deleting your account in Settings, which erases your answers as described in Section 8; contact us at privacy@kindredconnect.app if you would like help. You are never required to enter any particular kind of information in your answers, and withdrawing consent does not affect the lawfulness of any processing carried out before you withdrew it.
5. Who we share your data with
5.1 Your partner
Check-in responses, review comments, and commitments are shared with your paired partner as a core function of the App. Your check-in answers are revealed to your partner only when you both choose to reveal them — neither of you sees the other's answers before you have both submitted. Personal notes are private and are never shared with your partner.
5.2 Service providers
We use the following third-party services to operate the App:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database hosting, authentication (including sign-in, email confirmation and password-reset emails), and real-time sync | All account and check-in data. Encrypted in transit and at rest. Stored in the EU (Ireland). |
| Cloudflare | Hosting for our website | Your IP address, processed transiently to serve the Site. Cloudflare derives your country from it so we can show prices in your local currency. Cloudflare is the only processor that handles your raw IP address, and it is not stored. |
| RevenueCat | Subscription management | User identifier, subscription status, purchase events |
| Expo | Push notification delivery | Push notification tokens and notification content |
| Resend | Account and subscription email delivery | Email address and the content of account and subscription emails. No check-in content. |
| Sentry | Crash reporting, performance monitoring, and error diagnostics | Device info, error logs, performance traces, and your account identifier while signed in. No check-in content. |
These providers process data on our behalf under data processing agreements. They do not use your data for their own purposes.
Apple acts as an independent controller for payment and transaction data, which it collects directly from you under its own privacy policy when you make a purchase through the App Store. We do not receive or store your payment card details. If you choose Sign in with Apple, Apple also acts as an independent controller for the sign-in itself, and provides us with the account details described in Section 2.1 under its own privacy policy.
5.3 We do not
- Sell your personal data to anyone.
- Share your data with advertisers.
- Use your check-in content for AI training.
- Share data with data brokers.
5.4 Legal requirements
We may disclose your information if required by law, regulation, legal process, or governmental request.
5.5 Business transfers
If Quiet Studios Ltd is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
6. Data retention
- Account and check-in data is retained for as long as your account is active.
- Inactive accounts — if your subscription has lapsed and you have not logged in for 12 months, we will notify you by email that your account is scheduled for deletion. If you do not respond or log in within 30 days of that notice, your account will be deleted and your data processed as described in the account deletion section below.
- In-progress session data (answers being drafted during a check-in) is temporary and is either finalized into your permanent check-in record or deleted when a session is completed or abandoned.
- Expired invite codes are retained for a short period for abuse prevention, then deleted.
- Crash reports are retained by Sentry according to their retention policies (typically 90 days).
- After account deletion, your account enters a 30-day deactivation period. You can cancel the deletion request at any time during this period by signing in. After this period, your personal data is permanently removed in accordance with Section 8 below.
7. Data security
We implement appropriate technical and organisational measures to protect your data:
- All data is encrypted in transit (TLS) and at rest.
- Row-level security policies ensure you can only access data belonging to your own relationship.
- Authentication is required for all data access.
- Sensitive service credentials are stored in secure vault infrastructure.
- Push notification tokens are scoped to individual devices and users.
No system is perfectly secure. If we become aware of a security breach affecting your personal data, we will notify you and any applicable regulator as required by law.
8. Your rights
Depending on your location, you may have some or all of the following rights:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate data.
- Deletion — request deletion of your account and associated data. When you delete your account, it enters a 30-day deactivation period during which you can sign in to cancel the request. After this period, your personal data is permanently removed. Permanent check-in records shared with your partner are anonymised — your user ID is disassociated from your check-in answers, review comments, commitments, and the habit review ratings you gave — so your partner retains their own check-in history without your identifying information.
- Data portability — request your data in a structured, machine-readable format (JSON). This includes your account information, check-in responses, commitments, personal notes, and habit review ratings.
- Withdraw consent — for processing based on consent, you can withdraw at any time: for your check-in answers, by deleting your account in Settings (see Section 4); for push notifications, in your device settings.
- Restriction — ask us to pause our processing of your data in certain circumstances.
- Object — object to processing based on legitimate interests.
- Lodge a complaint — with your local data protection authority. For UK residents, this is the Information Commissioner's Office (ICO) at ico.org.uk.
California residents (CCPA): You have the right to know what personal information we collect, request its deletion, and opt out of its sale. We do not sell personal information. To exercise your rights, contact us at the address below.
To exercise any of these rights, contact us at privacy@kindredconnect.app. We will respond within 30 days (or sooner if required by applicable law).
9. Children's privacy
Kindred is not intended for anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from someone under 18, we will delete it promptly.
10. International data transfers
Your data is processed and stored on servers that may be located outside your country of residence. Where data is transferred outside the EEA or UK, we ensure appropriate safeguards are in place (such as the EU standard contractual clauses or, where UK law applies, the UK Addendum or International Data Transfer Agreement) in accordance with applicable data protection law.
Your account and check-in data is stored in the EU (Ireland). The main transfers outside the UK and EEA are to processors that operate elsewhere: Cloudflare provides global website hosting, and Resend, which sends our emails, is based in the United States. Where your data reaches these processors, we rely on appropriate safeguards such as standard contractual clauses.
11. Cookies and tracking
Our website is cookieless: we do not use cookies, web analytics, or third-party tracking on the Site. Our hosting provider tells us the country your request comes from so the Site can show prices in your local currency; we do not store this or use it for anything else.
12. Push notifications
We send push notifications for:
- Session ended — when your partner finishes a check-in, or ends one that is in progress.
- Commitment reminders — mid-week reminders about habits and tasks (sent once per check-in cycle, around 4–5 days after your last check-in).
- Account events — when your partner requests deletion of their account, or their account deletion completes.
You can disable push notifications at any time through your device settings. Disabling notifications does not affect your ability to use the App.
13. Changes to this policy
We may update this policy from time to time. We will give you at least 30 days' notice of material changes via the App or by email before they take effect. The "Last Updated" date at the top of this page reflects the most recent revision.
14. Contact us
If you have questions about this privacy policy or your data, contact us at:
Kindred Connect (Quiet Studios Ltd, company number 17221945)
Email: privacy@kindredconnect.app
Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
This privacy policy was last reviewed on 25 July 2026.