Privacy Policy
Last updated: January 2025
Our Privacy Philosophy
Kinu was built with one core belief: your conversations are your business. We've designed our systems so that we cannot read your messages, even if we wanted to. This isn't just a policy—it's a technical guarantee built into our architecture.
What We Collect
Account Information
- Handle: Your chosen username (e.g., @alice)
- Display Name: The name shown to your contacts
- Recovery Email (optional): Encrypted and used only for account recovery
What We DO NOT Collect
- Message contents (encrypted end-to-end, we cannot read them)
- Your contacts list
- Your location (Rally Mode locations are encrypted client-side)
- Device identifiers for advertising
- Usage analytics for advertising purposes
Encryption
All messages are encrypted end-to-end using the Matrix protocol's Olm/Megolm encryption. This means:
- Only you and your recipients can read your messages
- Our servers only see encrypted data
- Even if our servers were compromised, your messages remain private
- We cannot comply with requests to read your messages because we technically cannot
Mesh Networking Data
When using mesh networking features:
- Messages are encrypted before being transmitted over Bluetooth
- Relay devices cannot read the contents of messages they forward
- Peer discovery uses rotating identifiers to prevent tracking
- No mesh network activity is logged on our servers
Data Storage
On Your Device
Your messages, contacts, and encryption keys are stored locally on your device in an encrypted database. This data never leaves your device unencrypted.
On Our Servers
Our servers store:
- Encrypted message data (we cannot decrypt it)
- Account metadata (handle, encrypted email)
- Public encryption keys for message delivery
Data Retention
- Account data is retained until you delete your account
- Encrypted messages are stored for delivery and then can be deleted by you
- Server logs are automatically purged after 30 days
- Mesh network data is never persistently stored on our servers
Your Rights
You have the right to:
- Access: Request a copy of your account data
- Deletion: Delete your account and all associated data
- Portability: Export your data in a standard format
- Correction: Update your account information
Third Parties
We do not sell, rent, or share your personal information with third parties for marketing purposes. We do not use third-party analytics or advertising services that would have access to your data.
Law Enforcement
Due to our end-to-end encryption, we cannot provide message contents to law enforcement even if legally compelled to do so. We will notify users of legal requests unless prohibited by law.
Changes to This Policy
We will notify users of any material changes to this privacy policy via the app and email (if provided). Continued use of Kinu after changes constitutes acceptance of the updated policy.
Contact Us
For privacy-related questions or requests, contact us at: privacy@kinuchat.com