Privacy Policy
Kinono AI helps adult caregivers record and share everyday baby care information. It is currently in TestFlight testing. This policy explains how we handle data for accounts, family sharing, care records and testing support.
Who operates this service
Kinono AI is operated by Monbee Ltd. Co. In this policy, “we” means Monbee Ltd. Co. For privacy or service questions, email cyhsu.bayer@gmail.com.
What data we process and why
- Accounts and sign-in: Account identifiers, display names, account status and creation, update and deletion times help us identify accounts and manage access. When you use Sign in with Apple, we process Apple identity information and credentials to verify sign-in, maintain sessions and revoke authorization. The server currently has no separate account fields for an Apple email address or Apple name; the app supplies a display name or uses a default.
- Families and babies: Family names, baby names or nicknames, dates of birth, sex and other profile information you enter, together with caregiver memberships, relationships, invitations and permissions, establish your family care space and determine who can view or edit its data.
- Care records: Feeding, sleep, diaper, solid food, growth, vaccination and other care records you enter or sync, including times, measurements and notes, support recordkeeping, display and family sharing. These records may contain your baby's health information.
- Sync and service operation: Record versions, change history, deletion markers, contribution attribution, account deletion status, service errors and necessary connection information help us sync devices, resolve conflicts, enforce permissions and troubleshoot problems. Network services process transmission information such as IP addresses, and error logs may contain technical details.
- Support and testing feedback: Emails, problem descriptions, screenshots and attachments you choose to send help us respond and resolve issues. Please avoid sending unnecessary baby health information, other people's data, passwords or sign-in credentials.
Google and Facebook sign-in
You may choose Google or Facebook instead of Apple to sign in. We verify the provider's signed identity token and a one-time nonce, then use the provider account identifier and the display name supplied in that token to create or find your Kinono account. Facebook uses Limited Login and the public_profile permission. We do not request Facebook friends, posts, photos, birthday or email permissions. Accounts from different sign-in providers are not automatically merged by matching names or email addresses.
We retain the provider account identifier, provider/app identifiers and Kinono account/session records needed to recognize you and maintain sign-in. Google and Facebook identity tokens are verified transiently; they are not retained as reusable provider access or refresh tokens. We store short-lived token and nonce digests to prevent replay. The app stores Kinono's own refresh credential in the device Keychain. Display names can appear to authorized caregivers in your shared family.
Facebook sign-in opens Meta's authorization service. Meta processes information needed for that interaction under its own policy. Our Meta SDK configuration disables automatic app-event logging and advertising identifier collection. We do not send baby care records to Meta as part of Facebook sign-in or use Facebook login data for advertising.
Who can access data
Authorized caregivers in the same family receive access according to their permissions. Before inviting someone, make sure you have permission to share the relevant information. Revoking access does not automatically erase private copies that a caregiver has already saved.
Operator-controlled servers and databases provide the features described above. Apple processes information for Sign in with Apple and TestFlight. Google and Meta process information for their respective sign-in services when you choose them. Support emails and sender information pass through email providers, including Google Gmail, which we use for support. These providers have their own policies:
Meta's practices are described in the Meta Privacy Policy.
Currently enabled Kinono AI server integrations do not include advertising, external analytics, AI transcription, media processing, push notifications or automated email services. This statement does not include Apple's TestFlight statistics or mean that network traffic, sign-in and support never involve third parties.
TestFlight testing data
When you use a beta through TestFlight, Apple automatically collects crash and usage data and provides it to developers. You may also submit written feedback or screenshots, which may include device information and personal data. We use the testing data and feedback we receive to investigate problems, improve Kinono AI and respond to testing questions. See the TestFlight information linked above for Apple's practices.
Storage and protection
The service database and encrypted operational backups are currently stored on the same operator-controlled host. Connections use HTTPS, and the server checks family access permissions. Apple identities are looked up using keyed hashes. We also retain encrypted identity information and refresh tokens needed to manage and revoke sign-in credentials. These measures do not make the data anonymous.
This policy does not promise that data is processed only in your country or a particular region. Apple, Google, Meta, email and network services may process data in different regions. Contact us for further information about storage locations. No system can guarantee absolute security.
Backups and their limits
We maintain encrypted PostgreSQL backups and archived database changes for operator-managed service recovery. They cover data stored in the shared service database, including accounts, family memberships, permissions and synced care records. They are stored on the same host as the database, so they do not provide protection against loss of that entire host. We have not verified an off-site copy.
The app also provides manual local backup export and import. This is separate from server recovery and from any backup managed by Apple. Server backups are not a user-operated restore feature and do not back up your entire iPhone, local changes that have not synced, or photo files outside the database. Do not assume that a local export includes every shared record or photo; its coverage depends on the app's implementation. We have not verified your Apple backup settings or their coverage.
How long we keep data
We retain account and family data while providing the related features. Shared care history, record versions, deletion markers, contribution attribution, archived families and account deletion records currently have no single automatic expiry period. They may remain to preserve family records, sync consistency and traceability of deletion handling.
Backups rotate periodically. Under the current configuration, full backups become eligible for routine cleanup after eight days and archived database changes after nine days; deletion then depends on the next successful backup and cleanup run. Failures may extend retention. Deleting an account therefore does not mean every backup copy is erased within seven days. Some service logs rotate by file size rather than age. Other logs, support emails and testing feedback also have no single automatic deletion period.
Deleting an account and ending sharing
To request deletion, open Kinono, choose the Caregiver tab, select Delete account, complete sign-in verification, review the family and data consequences shown in the app, and confirm deletion. If you cannot sign in, email cyhsu.bayer@gmail.com with the subject "Kinono account or Facebook data deletion". Tell us which sign-in provider you used and enough account information to locate your request. Do not send passwords, access tokens or verification codes. We may ask you to verify account ownership before processing the request.
These instructions also apply to information received through Facebook Login. When the account deletion job completes, the server removes the Facebook or Google identity association and the associated Kinono access, refresh and session records. Removing Kinono's authorization in Facebook alone does not submit an in-app Kinono account deletion request; use the steps above or contact support for deletion from Kinono.
You can request account deletion in the app, or contact support if you cannot use that feature. Deletion processing disables the account, ends family access and replaces the account display name with a deleted-account label. You may first need to transfer family ownership or follow the app's instructions.
Historical contributions to shared family care records and their attribution links may remain so other family members can maintain their records. Deleting a family currently archives it rather than immediately erasing all historical data. Once both Apple revocation and the account deletion job have completed, the server removes the old Apple identity, associated encrypted credentials and sign-in session data. External service failures may delay completion.
Leaving a family or having access revoked ends access but does not automatically delete earlier contributions. Removing the app does not delete your server account. If we restore an older backup, later deletions and revocations need to be checked and reconciled manually before service resumes. There is currently no mechanism that automatically completes this reconciliation.
Your choices and how to contact us
You can view and edit data, manage sharing or delete your account using the app's available features and your family permissions. To ask about a copy, correction or deletion of data, or stopping a particular use, email cyhsu.bayer@gmail.com. We may need to verify your account and the scope of your request to avoid disclosing or deleting someone else's data. Do not email any password, access token or verification code. Other family members' rights and applicable requirements may affect how we can respond.
Baby and children's data
Kinono AI accounts are for adult caregivers. Caregivers provide baby information and should enter and share only data they are authorized to handle. Contact us if you believe a child's information has been provided or shared improperly.
Policy updates
We will update this page and its date when the service or our data practices change. Please read the relevant data information before using new features.