How Your Data Works

Last updated: 11 April 2026 · Version 1.2 · No legalese. Just how it works.

The journey of a message

1

You type a message. It travels over an encrypted connection (TLS) to our server.

2

Our server processes it. Your message, along with your Person model and recent conversation context, is sent to the AI model via OpenRouter (which routes to Anthropic's Claude).

3

Claude generates a response. The response streams back through OpenRouter to our server, then to your browser.

4

Both messages are stored. Your message and Kin's response are saved in our database so Kin can remember your conversations.

Where your data lives

All Kin data is stored on a dedicated server hosted by Hetzner in Germany (EU). Your data never leaves EU infrastructure for storage.

  • Database: PostgreSQL with encryption at rest. Contains your conversations, Person model, and account information.
  • Backups: Automated daily backups, also stored in the EU.
  • In transit: All connections use TLS encryption. No data is transmitted unencrypted.

What we store

  • Conversations — every message you send and every response Kin gives. This is how Kin remembers.
  • Person model — Kin's understanding of how you think, what you value, and how you communicate. Built from your conversations, not scraped from anywhere else.
  • Account info — email address and subscription status. We don't store passwords (we use magic links).
  • Payment info — handled entirely by Stripe. We never see or store your card number.

What we don't store: raw AI prompts after processing, browsing history, device data beyond what's needed for the session, anything from other apps.

Who can access your data

  • You — full access to everything. You can export all your data at any time from Settings.
  • Kin's operator — Opal Harmony P.C. (Olympou 9, 54630 Thessaloniki, Greece), a Greek private company; in practice, one person (the founder, Orestis Palampougioukis). Database access is for maintenance and debugging only. We don't read your conversations for fun, and we don't have a team of moderators reviewing content.
  • AI providers — OpenRouter and Anthropic process your messages to generate responses. Neither uses your data to train their models. Both operate under data processing agreements.
  • Nobody else. We don't sell data. We don't share it with advertisers. We don't use your conversations to train AI models.

Third-party services that touch your data

Every external service Kin uses, and exactly what they receive:

  • OpenRouter + Anthropic (US) — your messages and conversation context, for AI response generation. No training use.
  • Stripe (US) — your email and payment method, for subscription billing. Card details are never on our servers.
  • Resend (US) — your email address, for transactional emails (magic links, confirmations).
  • ElevenLabs (US) — text of Kin's responses only, for voice synthesis. No conversation context or personal data.
  • Sentry (EU) — technical error data only. No personal conversation content.
  • Hetzner (EU, Germany) — server infrastructure. All data at rest.
  • Cloudflare (global anycast) — DNS only for thekin.chat. Receives your IP and the requested hostname. Does NOT proxy or terminate TLS for Kin traffic, so it never sees your messages.

EU-to-US data transfers operate under Standard Contractual Clauses (SCCs). Where applicable, the receiving processor is also certified under the EU-US Data Privacy Framework (DPF). We do not rely on the old Privacy Shield, which was invalidated by Schrems II in 2020. Full legal details in our Privacy Policy.

When you delete your account

Deletion is immediate and irreversible. When you delete your account from Settings:

  • All conversations are permanently deleted.
  • Your Person model is permanently deleted.
  • Your account record is permanently deleted.
  • Active subscriptions are cancelled in Stripe.
  • There is no recovery period. Once deleted, the data is gone.

You can export all your data before deleting — Settings has a one-click export that gives you everything in a portable format.

If Kin shuts down

If we ever need to close the service, we commit to:

  • 30-day notice — you'll have at least 30 days to export your data before anything is deleted.
  • Full export — conversations, Person model, everything you've shared with Kin, in a standard format you can keep.
  • Complete deletion — after the export window closes, all user data is permanently deleted from all systems and backups.

Your memories belong to you. We hold them; we don't own them.

Questions?

If anything here is unclear, email privacy@getsinew.dev. We'll give you a straight answer.