Effective August 13, 2026 · privacy-v5
KinTypes privacy policy
Worldbuilders Inc operates KinTypes. This policy explains what we collect through the KinTypes app, website, hosted Kinlists, social features, and related services; why we use it; when it is disclosed; and the choices you have.
1. The important privacy boundary
KinTypes is cloud-backed, including the private parts of your workspace. Raw Journal entries, Journal tags and attachments, private notes, Kinshift records and timing, archives, editor prompts, organization, and private kintype material are stored in an authenticated account-private backup. They do not enter public profiles, hosted kintype pages, posts, discovery, or social responses without a separate sharing model and an explicit action by you.
The account-private backup is server-readable and is not end-to-end encrypted. Authorized KinTypes operators could technically access it when reasonably necessary to operate, secure, troubleshoot, support, or comply with law. Public and social publishing uses a separate allowlisted projection so private workspace fields are not returned by public or social APIs.
2. Information we collect
Account, authentication, and consent
Before sign-in, KinTypes checks whether you meet its minimum age. On supported Apple operating systems, Apple’s Declared Age Range service may share an age range and general declaration category, not a birthday or exact age. If that service is unavailable or declined, a date of birth is checked only in memory on the device and is not saved or sent. The server stores only that the current 13-or-older requirement was confirmed, the method, a general declaration category, the policy version, and the confirmation time. See the age policy.
When you sign in with Apple or Google, we receive a provider account identifier and, when the provider makes them available, your email address and name. On the server, we store internal account and session identifiers, encrypted or hashed provider and refresh credentials as applicable, and access and refresh-token state. The app stores the accepted policy version, acceptance time, age-confirmation metadata, and internal account identifier in device secure storage where available. Apple and Google process sign-in information under their own privacy policies.
Profile and hosted identity
We store the username, display name, avatar, pronouns, bio, links, profile theme, and other presentation choices you provide. We store the kintype pages and sections you create, including names, identity labels, source references, descriptions, boundaries, visuals, images, and image credits.
Each kintype page is public, unlisted, or private. Public kintypes can appear on your hosted profile and in discovery. Unlisted kintypes are reachable by anyone with their direct links even though they are omitted from ordinary profile and discovery surfaces. Private kintypes are owner-only. All completed sections inherit the page state.
Your Profile identity may be the account, a pinned eligible public kintype, or a presentation resolved from an eligible public active Kinshift. Public and social responses receive only that resolved presentation plus the accountable owning account. They do not receive the raw Kinshift record, its timing or overlap, private identities, or Journal text. A new post stores a snapshot of its resolved presentation so later identity changes do not rewrite the post’s attribution.
Account-private workspace
The device keeps an offline SQLite working cache. The account-private server copy can include active and archived kintypes; collection organization; draft and private page fields; private notes; raw Journal entries, tags, and attachments; Kinshift ranges; Canon and Scene records; editor prompts and working state; import archives; and private appearance or image data. These records may reveal sensitive beliefs, identity, health-adjacent experiences, relationships, or interests even when you do not label them that way.
Community activity
We store posts and images; comments and replies; likes and votes; follows; Hide and Block relationships; optional kintype tags; source and canon requests; notification state; content edits and deletions; and other actions needed to operate shared features. The people involved can see interactions such as posts, comments, follows, and likes as the product indicates. Hide and Block relationships are used to enforce your safety boundary and are not published as a public list.
Reports and moderation
We store reports, reason codes, reporter notes, moderation status, action and appeal history, automated safety signals, and an allowlisted snapshot of the content visible when it was reported. Report evidence may remain available to authorized moderators even if the live content is later edited or deleted. Reports are not public, but we may give an affected person enough information to explain and review an enforcement decision without identifying a reporter where possible.
Purchases
Apple or Google processes payment. RevenueCat helps us determine Pro entitlement. We may receive an app user identifier, store, product and entitlement identifiers, purchase and renewal state, expiration, trial, and transaction metadata. We do not receive your full payment-card number.
Images, files, exports, and support
We receive images or files you choose to upload or import and the image credits or captions you provide. A selected file may contain metadata embedded by your device. Readable exports are created at your request and can contain sensitive private workspace data. If you contact us, we receive your contact details, message, and any attachments or diagnostic information you send.
Device, request, and security data
Our app and infrastructure may process app version, operating-system or device information, request time and route, IP address, authentication and internal user or asset identifiers, error and reliability logs, and abuse-prevention signals. IP addresses may be used for rate limiting, security, and approximate network-level location, but KinTypes does not intentionally request precise GPS location, contacts, microphone recordings, or advertising identifiers for the current service.
3. How we use information
We use information to:
- authenticate accounts, issue sessions, and record policy consent;
- save, restore, synchronize, export, and delete the account-private workspace;
- publish only the profile, kintype, image, and social fields eligible under your settings and actions;
- operate feeds, search, source records, follows, interactions, and notifications;
- process Pro entitlements and provide purchase restoration;
- enforce Hide and Block, review reports, prevent abuse, and protect users and the service;
- debug failures, secure infrastructure, respond to support requests, and improve service reliability;
- comply with law, preserve legal claims, and respond to valid legal process; and
- communicate material service, safety, privacy, or terms changes.
We do not use private workspace content to train generative artificial-intelligence models, target advertising, or build advertising profiles. We do not use sensitive personal information to infer characteristics for purposes unrelated to providing and protecting KinTypes.
4. When information is disclosed
According to your visibility and actions
Public profile fields, public kintype pages, public media, and shared community activity can be viewed and copied by other people and may eventually be indexed by search engines where the product makes them web-accessible. Anyone with an unlisted link can view the linked page. Private pages and account-private workspace records are available only to the owning account and authorized operators or providers as described here.
Service providers
We disclose information to providers that process it for us under contractual or platform terms:
- Apple and Google for sign-in, app distribution, and in-app purchases;
- RevenueCat for subscription and entitlement management;
- DigitalOcean for the standalone KinTypes server and database infrastructure; and
- Cloudflare for network protection, secure connectivity, website delivery, object storage, and public media delivery.
Providers receive only the information reasonably needed for their function. Their own services may independently collect information under their privacy policies.
Legal, safety, and business events
We may disclose information when we reasonably believe it is necessary to comply with valid legal process; protect a person from imminent harm; investigate fraud, exploitation, or security incidents; enforce our terms; or report suspected child exploitation or other conduct as required by law. We may also transfer information in a merger, financing, reorganization, bankruptcy, or sale of all or part of the service, subject to this policy and applicable notice requirements.
No sale or behavioral-advertising sharing
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising or targeted advertising, and the current KinTypes app does not include third-party advertising trackers. KinTypes does not send account or workspace data to Yumeship, Lifa, or their shared auth or data services.
5. Automated safety signals
KinTypes may use first-party rules and thresholds to rate-limit activity, flag unusual behavior, or place a temporary, reversible hold on content or social writes. These signals help moderators prioritize review. They do not by themselves make a final permanent-ban decision. You may request human review of an enforcement decision by contacting us.
6. Storage, security, and international transfers
KinTypes uses authenticated access, encrypted network transport, restricted production access, private object-storage controls, separated public-media publishing, token protection, and logging intended to protect the service. Device tokens use platform secure storage where available. No online service, storage system, or transmission method is completely secure.
Your device cache and any export you create are under your control. Exports are not guaranteed to be encrypted. Other apps, device backups, shared devices, screenshots, and people who receive an export can create additional copies beyond KinTypes’ control.
Worldbuilders Inc and its providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, we rely on approved contractual safeguards or other lawful transfer mechanisms.
7. Retention
We keep information for as long as needed to provide KinTypes, meet the purposes in this policy, resolve disputes, enforce agreements, and satisfy legal, safety, accounting, or security requirements. More specifically:
- While your account is active, the server ordinarily retains the ten most recent completed versions of the account-private workspace so a known-good copy can be restored. Replaced versions and unreferenced private assets are eligible for cleanup.
- Hosted profile, kintype, media, and social records remain until you change visibility, delete them, delete the account, or we remove them. A privacy downgrade makes the public copy ineligible and triggers removal from public storage and delivery, although caches and outside copies may persist temporarily.
- The local device cache remains until the app data is removed, you use the relevant deletion control, or you sign out after a completed backup. Device or operating-system backups may retain separate copies.
- After account deletion, we delete active private backups, hosted and social content, uploaded media, provider links, credentials, and entitlement links. We may retain a minimal tombstone with an internal identifier and deletion time to record the deletion and invalidate access.
- Reports, allowlisted report-time evidence, moderation and appeal history, fraud or security records, and related internal account identifiers may be retained after content or account deletion for as long as reasonably needed to protect users, prevent repeat abuse, support review, establish legal claims, or comply with law.
- Transaction and support records may be retained for tax, accounting, dispute, and legal requirements. Infrastructure backups, if present, are protected from ordinary use and are removed on their rotation schedule unless preservation is legally required.
8. Your choices and rights
Depending on where you live, you may have rights to know or access personal information; obtain a portable copy; correct inaccurate information; delete information; restrict or object to processing; withdraw consent; opt out of a sale, sharing, or targeted advertising; appeal a rights-request decision; and complain to a data-protection authority. KinTypes does not sell personal information or use it for targeted advertising, so there is no sale or targeted-advertising opt-out to exercise for the current service.
You can use KinTypes controls to:
- edit profile and kintype information and choose public, unlisted, or private for each kintype page;
- delete posts and other supported content, Hide or Block accounts, and submit reports;
- export a readable copy of account-private data without Pro;
- manage or restore purchases through the app-store flow;
- remove the downloaded cache from a device; and
- delete the KinTypes account and associated active service data in the app or through our account-deletion page.
For another privacy request, email admin@worldbuilders.app. Describe the request and the account involved. We may need to verify that you control the account, and we may deny or limit a request where the law permits—for example, to protect another person, preserve safety evidence, or comply with a legal obligation. Authorized agents should also provide proof of authority. We will not discriminate against you for exercising a privacy right.
9. Account deletion
You can start deletion inside KinTypes Settings or use the instructions at kintypes.com/delete-account/. Deletion is designed to remove the account’s active private backup, hosted and social records, uploaded media, provider connections, and sessions. The limited retained records described above are not used to recreate your account or make deleted content public.
Deleting the KinTypes account does not cancel an Apple or Google subscription. Cancel the subscription in the applicable app store.
10. Children and teens
KinTypes is not directed to children under 13, and we do not knowingly allow them to create accounts. The age check occurs before provider sign-in so an under-13 result does not send Apple or Google account information to KinTypes. We do not offer an under-13 or parental-consent account flow. If local law requires a higher age or parental permission, that requirement applies. See the age policy for details. If we learn that an underage child provided personal information, we will take steps to remove it and close the account. Contact admin@worldbuilders.app if you believe this has happened.
Shared surfaces are safe-for-work. Teens should avoid publishing contact details, precise location, school, legal name, or other information that could identify or locate them. Parents and guardians can contact us with a substantiated safety or privacy concern, but we may need to protect the teen’s privacy and verify legal authority.
11. Legal bases for EEA and UK users
Where the GDPR or UK GDPR applies, Worldbuilders Inc is the controller. We process data as needed to perform our contract with you (providing KinTypes); for legitimate interests such as security, service reliability, support, and proportionate community safety; with consent where required; and to comply with legal obligations. You can object to legitimate-interest processing, but we may have compelling grounds to continue. Consent can be withdrawn without affecting earlier lawful processing.
12. Changes and contact
We may update this policy as the service or law changes. We will post the updated effective date and provide additional notice when required. If a change materially affects how previously collected private information is used, we will seek consent where required rather than relying only on continued use.
KinTypes is operated by Worldbuilders Inc. Send privacy questions, rights requests, or complaints to admin@worldbuilders.app. You may also complain to the privacy or data-protection regulator where you live.