Privacy
Privacy Policy
Last updated 4 July 2026
Kinli is a referral-only community for trusted regional groups. We take a deliberately modest approach to data: we collect what the service needs to work, nothing more. We do not track you, we run no advertising, and we use no analytics that follow you around. This policy explains, in plain language, what we hold, why we hold it, and the rights you have over it.
Who we are
Kinli is operated by [COMPANY LEGAL NAME], a company registered in England and Wales (company number [COMPANY NUMBER]) with its registered office at [REGISTERED ADDRESS]. For the purposes of UK GDPR and the EU GDPR, we are the data controller for the personal data described in this policy.
We are registered with the Information Commissioner’s Office (ICO) under registration number [ICO REGISTRATION NUMBER].
If you have any question about this policy or about how we handle your data, including any request to exercise your rights, please contact us at support@kinli.co.uk.
What this policy covers
This policy covers the Kinli mobile apps, the Kinli website at kinli.co.uk, and the services behind them. It applies to members and to anyone who visits our website or signs up through an invitation.
What data we collect, and why
We only collect data that we need to run Kinli and to give you the experience you have asked for. Below is everything we hold and the reason we hold it.
Account data
Your name and email address, and the way you sign in. You can sign in with Apple, Google, or an email address and password. If you sign in with Apple using its private-relay email, we only ever receive the relay address, not your real one. For email accounts we store your password as a one-way hash — we never see or keep your actual password.
Profile data
Anything you choose to add to your profile, such as a short bio and an avatar image (or a preset avatar). This is optional and visible to other members of your circles.
Content you create
Posts, replies, reactions, marketplace listings, and the images you attach to them. This is the heart of the service — it is shared with the members of the circle you post into.
Conversations (direct messages)
Private messages you send to other members. Message bodies are encrypted at rest on our servers using AES-256-GCM. To be honest about what that does and does not mean: it protects your messages if a database copy were ever to fall into the wrong hands, but it is not end-to-end encryption — we, as the operator, hold the key and can in principle access message content (for example, to respond to a lawful request or a safety report). Treat direct messages as private between you and the recipient, but not secret from us.
Location
Some circles are tied to a place. If you choose to find or create a place-based circle, we may ask your device for your location to help you find circles near you. This is requested “while using the app” only, never in the background, and only at the moment it is relevant — never at start-up. You can decline, and you can change the permission at any time in your device settings. When you describe a circle’s area, that is a general area you type in; other members never see your exact home address.
Payment data
If you take out a paid subscription (Insider or Founder), payment is handled on our website by Stripe. Stripe collects and processes your card details directly — we never see or store your full card number. We keep a record that you have an active subscription and the identifiers Stripe gives us to manage it.
Device and diagnostic data
If the app crashes, we receive a crash report through Sentry so we can fix the problem. This can include technical details about your device and the state of the app at the time. We do not use any advertising or tracking identifiers, and we never trigger Apple’s App Tracking Transparency prompt because we do not track you across other apps or websites.
Support correspondence
If you email us, we keep that correspondence so we can help you and keep a record of the request.
Contacts shared by members (recommendations)
A member can attach a contact card to a post to recommend someone — for example a babysitter, plumber or tutor. The card holds the name and whatever details the member chose to share (such as a phone number or email), and is visible only to the members of that circle. The member chooses, field by field, what is shared. If you are the person being recommended, see “If someone shared your details” below for how this works and how to remove your details.
These recommendations also build a private professional directory (“Your Book”), visible only to members and only within circles they belong to — for example, so a member can find a plumber that people in their circles have recommended. If you are a professional who has been recommended, the invitation email may let you claim your profile: this is optional, and lets you set up how you appear (your trade, area, a short bio, and how to reach you), manage it, or take it down yourself. If you claim a business profile and choose to add your Companies House registration number, we check that number against the public Companies House register to show a verification mark. We send only the number; we store the confirmed company name and status returned to us. Sole traders are not asked for a company number.
Our legal bases for using your data
Under UK and EU GDPR we must have a lawful basis for each use of your personal data. Here is how each purpose maps to a basis.
| Purpose | Lawful basis |
|---|---|
| Creating and running your account; showing you your circles and content | Performance of a contract (our Terms of Service with you) |
| Sending you service emails (verification, password resets, important notices) | Performance of a contract |
| Taking subscription payments and managing billing | Performance of a contract |
| Keeping the service secure, preventing abuse, and diagnosing crashes | Legitimate interests (running a safe, reliable service) |
| Using your device location to find nearby circles | Consent (you grant the device permission, and may withdraw it any time) |
| Optional push notifications for circle activity | Consent (you choose which notifications to receive) |
| Holding a contact card a member shared as a recommendation, and (if the member chose to invite them) sending that contact one invitation email | Legitimate interests (helping members recommend trusted people within a private circle), balanced by a one-tap removal link in any email we send |
| Building a private directory of recommended professionals for members to browse within their circles | Legitimate interests (helping members find trusted local professionals), balanced by the removal link and the ability to claim and manage a profile |
| Setting up and managing a professional profile you have claimed, and (for businesses) verifying a Companies House number | Performance of a contract (running the profile you asked to claim) and legal obligation / legitimate interests for accurate business verification |
| Complying with legal obligations (e.g. tax records, lawful requests) | Legal obligation |
Where we rely on legitimate interests, we have considered your rights and freedoms and believe our use is proportionate and would be reasonably expected. You can object to processing based on legitimate interests — see “Your rights” below.
Ask Kinli
Ask Kinli is a feature that can answer questions by drawing on posts across the circles you belong to, always pointing to the real posts it drew from. When you use it, your question and the relevant posts are processed by an AI model provider to generate a response. We only send what is needed to answer your question, and we do not use your private direct messages for this. Ask Kinli can be imperfect and its answers should not be relied upon as professional advice.
How long we keep your data
We keep your data for as long as you have an account, and then for the periods below.
- Your account and profile: kept while your account is active. When you delete your account, we permanently remove your authentication details (sign-in methods, password hash) and profile information.
- Your posts, replies and reactions: by design, deleting your account does not erase the knowledge you contributed to a circle. After a grace period of 14 days, your authored content is anonymised — your name is replaced with “Former member” and can no longer be linked back to you. You can also delete individual posts yourself at any time.
- Direct messages: retained for the life of the conversation; the seller and buyer record of a completed marketplace exchange is retained as part of that record.
- Crash reports: retained only as long as needed to diagnose and fix issues.
- Billing records: retained as required by law (typically six years for UK tax purposes).
International transfers
We host your data within the UK/EU wherever we can, and we have chosen our core providers accordingly. Some providers may process limited data outside the UK and EEA. Where that happens, we rely on an appropriate safeguard recognised by UK and EU law — such as an adequacy decision, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses — so that your data continues to receive an equivalent level of protection.
How we protect your data
We use encryption in transit (HTTPS) for everything, and encryption at rest for direct message content. Access to our systems is restricted and authenticated. No system can be guaranteed perfectly secure, but we take the safeguarding of your data seriously and design for it from the start.
Your rights
Under UK and EU data protection law you have the following rights over your personal data.
- Access — ask for a copy of the personal data we hold about you.
- Rectification — ask us to correct data that is wrong or incomplete. You can edit most of your profile yourself in the app.
- Erasure — ask us to delete your data. You can delete your account in the app; this permanently removes your authentication and profile data and anonymises your content as described above.
- Portability — ask for a copy of the data you have given us in a structured, machine-readable format (we can provide your data as JSON).
- Restriction — ask us to limit how we use your data in certain circumstances.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — where we rely on consent (such as location or notifications), you can withdraw it at any time without affecting earlier processing.
To exercise any of these rights, email us at support@kinli.co.uk. We will respond within one month. Exercising your rights is free, and we will not treat you differently for doing so.
If you are unhappy with how we have handled your data, you have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113. If you are in the EU, you may complain to your local supervisory authority. We would, of course, appreciate the chance to put things right first.
Children
Kinli is not intended for children. You must be at least 18 years old to create an account. We do not knowingly collect data from anyone under 18. If you believe a child has provided us with personal data, please contact us and we will remove it.
Changes to this policy
We may update this policy from time to time. When we make a material change, we will update the “Last updated” date and, where appropriate, let you know in the app or by email. Please check back occasionally.
Contact us
For any privacy question or request, write to us at support@kinli.co.uk, or by post to [COMPANY LEGAL NAME], [REGISTERED ADDRESS].