Legal

Privacy policy

Last updated 25 July 2026

Who this policy covers

Kinflo is a platform that lets creators and businesses build their own branded community app without writing code. That means two different groups of people are involved, and the way we handle their data differs.

Creators are our customers. They sign up at kinflo.io, design an app in our dashboard and pay us a subscription. We decide how their data is handled, so for creators we are the data controller.

Members are the people who join a creator's community, on the web or in the creator's app. That community belongs to the creator, not to us: the creator decides what to collect, what to publish and who may join. For members, the creator is the data controller and Kinflo is their processor, handling data on their instructions. If you are a member and want your data changed or deleted, the fastest route is to contact the creator whose community you joined. You can also contact us and we will help.

What we collect

We only collect what the product needs to work.

  • Account details. Your email address and a securely hashed password. If you sign in with Google or Apple we receive your email address and basic profile details from them, never your password.
  • Profile. Username, display name, and optionally an avatar image and short bio.
  • Content you create. Posts, comments, replies, poll votes, direct messages, and any images, video or audio you upload.
  • Membership and purchases. Which plan you are on, when it renews, courses or products you have bought, event RSVPs and coaching bookings. Card details are handled by Stripe or by Apple and never reach our servers.
  • Delivery addresses. Only if you buy a physical product that needs shipping.
  • Onboarding answers. If a creator has set up onboarding questions, the answers you give so they can tailor the community to you.
  • Notifications. If you allow push notifications, a device push token so we can deliver them. You can revoke this in your device settings at any time.
  • Support messages. If you contact support or use the help-centre chat, the message you send and your email address so we can reply.
  • Technical data. Standard server logs kept by our hosting providers, such as IP address and browser type, used to keep the service running and secure.

We do not use advertising trackers, third-party analytics SDKs or cross-site tracking cookies anywhere in the dashboard, the web app or the mobile apps. We do not sell personal data, and we never will.

Why we use it

  • To provide the service. Creating your account, showing you the community you joined, delivering courses and content, and processing your purchases. This is necessary to perform our contract with you.
  • To keep it working and safe. Diagnosing faults, preventing abuse and spam, and enforcing community rules. This is our legitimate interest in running a secure service.
  • To communicate. Sending account emails such as confirmation and password resets, and notifications you have asked for.
  • To improve the product. Understanding which features are used, in aggregate. Creators can see engagement statistics about their own community.
  • Marketing emails. Only where a creator has set up an email sequence and you have consented to receive it. Every marketing email has a one-click unsubscribe link.

Who we share it with

We use a small number of specialist providers to run Kinflo. They act on our instructions and may only use the data to provide their service to us.

SupabaseDatabase, authentication and file storage. Almost all data described above is stored here.
VercelHosting for the dashboard, marketing site and creators' web apps.
StripePayments. Creator subscriptions to Kinflo, and member purchases which are charged on the creator's own connected Stripe account.
RevenueCatManages in-app purchases and subscriptions made through the Apple App Store or Google Play.
ExpoDelivers push notifications to devices.
ResendSends transactional and marketing email on our behalf.
AnthropicPowers the AI assistant in our help centre. If you use that chat, your messages are sent to Anthropic to generate a reply. Do not put sensitive information into it.
CalendlyOnly if a creator connects their Calendly account, to sync coaching bookings.
getAddress.ioLooks up UK addresses from a postcode at checkout, to save you typing.
Apple and GoogleIf you choose to sign in with them, or buy through their app stores.

We may also disclose data if the law requires it, or to protect our rights or someone's safety. If Kinflo is ever sold or reorganised, data may transfer to the new owner, who would remain bound by this policy.

A note on what creators can see: the creator who runs a community can see its members, the content posted in it, and purchase and engagement information for their own community. They cannot see anything from another creator's community.

Where your data is held

Some of our providers are based outside the United Kingdom and the European Economic Area, mainly in the United States. Where data is transferred internationally we rely on the safeguards those providers offer, such as the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.

How long we keep it

We keep your data for as long as your account is active. If you close your account, or a creator removes you from their community, we delete the personal data associated with you, except where we must keep records for a legal reason such as tax and accounting rules, which normally require transaction records to be retained for six years.

When a creator deletes a member, that removal covers their profile, posts, comments, messages, course progress and other community data.

Your rights

If you are in the UK or the EEA you have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, to receive a copy in a portable format, and to withdraw consent where we relied on it.

To exercise any of these, email hello@kinflo.app. We will respond within one month. If you are a member of a creator's community, we may need to pass your request to that creator, since the data is theirs to control. If you are unhappy with how we have handled a request you can complain to the Information Commissioner's Office at ico.org.uk.

Cookies and similar technology

We use only the cookies the product needs. A secure cookie keeps you signed in, and a small cookie remembers which app you are managing if you have more than one. We store your light or dark theme preference in your browser. There are no advertising or tracking cookies, so there is no cookie banner to dismiss.

Children

Kinflo is not intended for children. You must be at least 16 to create an account, or older if the law where you live requires it. If we learn that we hold data about a child we will delete it. Creators are responsible for the age requirements of their own community.

Security

Data is encrypted in transit and at rest by our hosting providers. Access between different creators' communities is separated at the database level, and internal access to production data is limited to those who need it. No system is perfectly secure, but if a breach ever affected your data we would tell you and the regulator as the law requires.

Changes to this policy

If we change this policy we will update the date at the top of this page, and tell you by email if the change is significant.

Contact us

For anything about this policy or your data, email hello@kinflo.app and we will come back to you.