Privacy and data practices

Private by default. Published by decision. Deleted by a verified process.

Genealogy data is relational: one person’s upload can describe many relatives who never agreed to be part of a service. Kin Resolve treats privacy as an access, retention, and publication decision—not a footer promise.

Prelaunch disclosure updated July 15, 2026. This page describes product practice and planning; it is not an approved legal privacy notice.
Product principle

The private archive and public story are different surfaces.

Imported records, research notes, cases, API responses, and unfinished hypotheses need a private place to develop. Public family history should contain only what an owner has reviewed and intentionally shared. Real-data public publishing is disabled for the first hosted cohort.

Implemented in source

Controls the code enforces today.

Implemented does not mean deployed or approved for private family data. Live provider configuration and launch evidence remain separate gates.

01

Archive-scoped access

Private research routes require an authenticated archive membership. Cohort one is designed as one isolated deployment, database, object store, secret set, and archive—not shared multi-family tenancy.

02

Server-enforced limits

Hosted DNA, external AI, binary evidence uploads, media packages, public archive access, and real-data publishing are disabled at server boundaries for cohort one.

03

Reviewable import and export

Plain GEDCOM changes are previewed before apply, a recovery snapshot is created, and an owner can export the full archive back to GEDCOM.

04

Bounded observability

Operational events use fixed names and allowlisted metadata. Record content, names, queries, credentials, response bodies, session replay, and browser recording are excluded.

05

Controlled invitations

Hosted accounts use single-use, expiring invitations bound to an exact archive, email, role, and approved legal-document manifest. Open signup remains disabled.

06

Data-operation records

An owner can request a structured research export or record a deletion request. A deletion request is not a completed deletion; final real-pilot deletion remains an operator-reviewed whole-cell teardown.

07

Scoped API preview

The source includes owner-created, expiring, revocable read-only API tokens. The hosted API remains unavailable until its release, edge-limit, canary, and revocation gates pass.

08

Synthetic public material

The public repository, challenge, examples, and launch media use fictional Hartwell–Mercer records. Real genealogy and DNA files do not belong in source control or the beta application.

Cohort-one provider boundary

External-provider AI is disabled for the hosted cohort.

Deterministic structural and privacy checks do not need an AI provider. Although self-hosted operators can configure an OpenAI-compatible provider, the proposed hosted cohort rejects external-provider analysis at the server boundary.

If that boundary changes in a later cohort, the privacy notice must identify the provider, data sent, purpose, retention, training posture, region, and participant choice before private context leaves the deployment.

What is not promised

A private beta is not a compliance badge or availability guarantee.

Kin Resolve does not claim GDPR, CCPA, HIPAA, or genetic-privacy compliance; multi-tenant readiness; production-grade hosted DNA handling; guaranteed backups; zero data loss; instant deletion; or an uptime SLA.

DNA, external AI, binary media, open signup, billing, shared multi-family hosting, and real-data public publishing are excluded from cohort one.

Planned data lifecycle

Specific enough to review; not presented as an approved promise.

The durations below are proposed operating targets. The versioned privacy notice and participation terms control only after owner and counsel approval, publication, byte verification, and explicit participant acceptance.

  1. Beta applicationThe fallback form opens the applicant’s email client. The marketing site does not receive or store the form. The applicant’s mail provider, Kin Resolve mail routing, and the receiving mailbox handle the sent message.
  2. Invitation and accountInvitations, verification, and recovery capabilities are hashed, single-use, and short-lived. Account and acceptance evidence remain for the pilot lifecycle under the exact approved terms; no duration is promised before those terms are approved.
  3. Archive and importsA real pilot is designed for one dedicated data cell. Direct GEDCOM staging older than 24 hours has bounded cleanup, while archive records and retained import artifacts follow the participant’s approved pilot and deletion terms.
  4. Operational and audit dataOperational logs have a proposed 14-day target and non-content security/audit evidence a proposed 90-day target. These are planning values—not live promises—until provider configuration, owner approval, and counsel review are recorded.
  5. Backups after deletionPrimary deletion and retained-backup expiry are separate. The planning target is primary teardown within seven days after verification and optional export, with retained backups expiring no later than 30 days afterward. Neither target is promised until rehearsal and approval prove it.
  6. Security evidenceAPI token metadata, security events, legal acceptance, and deletion evidence are protected non-content records. The approved notice must state what survives a row reset, what is destroyed with the dedicated cell, and whether any minimal legal receipt remains outside it.
Planned service map

Where beta data would go.

The final approved privacy notice must name the providers actually configured at launch. A planned provider is not proof that a live processor relationship, region, retention rule, or contract has been approved.

01

Marketing application

Applicant email provider, Cloudflare mail routing, and the Kin Resolve beta mailbox
Contact and fixed workflow fields only; no files or family details

02

Hosted product

Vercel runtime and private object storage
Application requests and private GEDCOM artifacts under the approved product configuration

03

Primary data and provider backup

Supabase Postgres
Account, archive, research, operational, and encrypted provider-backup data

04

Transactional email

Resend
Invitation, verification, recovery, and service messages with no family-record content

05

Off-provider recovery

A protected encrypted backup destination selected before real data
Encrypted database and both object namespaces; exact provider and expiry must be disclosed

06

Operational alerts

A provider selected under the allowlisted event contract
Fixed event metadata only; no request or response bodies, record content, or replay

Export and deletion

A request, loss of access, and completed deletion are three different events.

  1. RequestAn authenticated owner records a deletion request. Support verifies the owner and offers fresh GEDCOM and structured research exports without asking for passwords, tokens, or records by email.
  2. ContainInvitations and new work pause; sessions, scheduled writers, database identity, both object namespaces, backup evidence, and the exact target cell are independently verified.
  3. Destroy the dedicated cellThe authoritative real-pilot finish is operator-reviewed destruction of the dedicated database and object resources—not merely hiding the app or deleting a few rows.
  4. Track retained backup expiryProvider and encrypted off-provider backups expire under the approved schedule. Kin Resolve must not claim they disappear immediately or mark deletion complete without evidence.
Support and security routes must be safe before invitations begin.

Participant help, export, and deletion requests will use support@kinresolve.com. Private vulnerability reports will use security@kinresolve.com. The proposed support acknowledgement target is one business day, not an SLA.

Never email family records, GEDCOM files, private screenshots, passwords, cookies, API tokens, source images, or genetic information. Arrange a separately approved private transfer only when evidence bytes are necessary.

This is a product-practices page—not the private-beta legal privacy notice.

The approved participation terms, privacy notice, and cohort boundary have not been published. No invitation should be accepted and no real family data should be uploaded until their exact versioned bytes are approved, published, verified, and presented for explicit acceptance.

A beta application consents only to beta communications; it does not accept hosted participation terms.

Read the application and cohort boundaries
Privacy-minded beta

Help test the boundary between private research and public history.

Apply with the fixed contact and workflow fields only. Keep GEDCOM files, DNA data, source images, credentials, and private family details out of the application and email.