KinLark
Privacy at KinLark
How KinLark keeps parent and child information limited, useful, and protected during the beta.
Last updated:
Who operates the service and who it is for
KinLark is operated by an individual based in China. Questions and privacy requests can be sent to support@kinlark.com.
KinLark is for adults aged 18 or older acting as parents or caregivers. Children must not use the service directly.
We use age ranges instead of exact birthdates, optional nicknames instead of legal names, and ask for only the activity details needed to make the product useful. If you believe a child has used the service directly or submitted personal information, contact us so we can investigate and remove it where appropriate.
Information we collect
For an account, we store the parent's email address, account and session records, and any marketing preference. Optional child profiles can include a nickname and age range.
To create and improve activities, we process the challenge or goal, age range, available materials, time, language, and any optional child context you provide. We may also store generated or saved activities, plans, progress check-ins, feedback, coarse product events, daily usage counters, and billing or audit status.
We do not sell child data, share it for advertising, or use it for targeted ads.
Why we use information
We use account and activity information to provide the service you request: sign you in, generate and save activities, create plans, show progress, provide downloads, manage subscriptions, and answer support requests.
We use limited operational information to secure the service, prevent abuse and fraud, enforce daily limits, diagnose failures, understand whether product flows work, and meet accounting, legal, and provider obligations.
We use a marketing preference only with your choice. You can change that choice or contact us at any time.
Signing in with Google
If you choose Google sign-in, we use your Google account identifier, email address and verification status to create or access your KinLark account. We may also store the name and profile image supplied by Google, together with sign-in dates. Google sign-in does not give us access to your Gmail, Drive, Contacts or Calendar, and we do not store your Google password or access tokens.
Google provides the sign-in button and, where supported, a browser sign-in prompt. You can dismiss the prompt or use an email sign-in link instead. Signing in does not subscribe you to marketing email. You can export your linked identity information and remove it by deleting your KinLark account.
Activity generation with Google Gemini
The activity details you submit are sent to the Google Gemini Paid API to generate an activity. Google states that for Paid Services it does not use those prompts or responses to improve its products, although it may retain limited logs for safety and abuse monitoring and may process or cache data where Google or its agents operate.
Do not enter a child's legal name, contact details, medical records, or other sensitive child information. Use a general description that is sufficient to create the activity.
Generated suggestions can be incomplete or inaccurate. They are not medical, therapy, developmental screening, diagnostic, or other professional advice; an adult must review and supervise every activity.
Hosting, email, and where providers process information
Cloudflare Workers runs the service, and Cloudflare D1 stores account, activity, plan, feedback, usage, and billing-status records. Cloudflare also supports security and rate limiting.
Resend processes the parent's email address, sign-in-link message content, and delivery metadata so we can send account authentication email. Resend states that its primary processing takes place in the United States.
The operator is based in China, and Google, Cloudflare, Resend, Creem, and their agents or subprocessors may process information in countries other than yours. Those providers apply their own contractual, privacy, security, and legal safeguards.
Product events, website analytics, and abuse limits
During the beta we keep a coarse, privacy-minimal record of product events — such as a page view, generation request, save, or print — so a one-person team can see whether the product is useful and where it breaks.
These product events store only general signals such as an age range, goal category, language, a public page identifier such as a course slug, or whether an activity matched a known pattern. They do not store raw IP addresses, exact locations, cookies, account passwords, the text of your activity descriptions, or a child's name.
We also use Cloudflare Web Analytics to understand aggregate page traffic and site performance. It does not use cookies, fingerprint people, or track them across websites, and KinLark does not use it for advertising.
To limit abuse and runaway costs, we cap how many activities can be generated per day. The daily counter is keyed by your account or by a salted, one-way hash — never by a stored raw IP address.
How long information is kept
We keep account and product information while your account is active or as needed to provide and secure the beta. Provider records may be kept under each provider's own terms and privacy obligations.
After account deletion, coarse product events remain without the account or saved-activity link. Feedback may remain without its account link; if a feedback message itself contains personal information you want removed, contact us.
If the account has billing history, we keep a deleted-account marker and the minimum subscription, payment, provider-reference, and audit records needed for accounting, legal, fraud-prevention, and provider obligations. Creem and other providers keep their own records under their privacy and legal duties.
Cloudflare keeps database recovery history for up to 30 days, and we create a private weekly database export in Cloudflare R2. Weekly exports expire after approximately 35 days.
Deleting an account removes the information described below from the live service, but it does not immediately remove copies already present in that recovery history or in an existing weekly export. If we restore an older recovery point or export, we reconcile account deletions made after that snapshot before normal service resumes.
Download and delete your account data
A signed-in parent can download one JSON file from the Account page. It includes the account and billing-status summary, child profiles, saved activities, learning plans and sessions, and feedback. It does not include sign-in secrets or payment-provider identifiers.
Account deletion requires you to type the account email. Active, trialing, and past-due subscriptions must be canceled or resolved first. Download your data before deleting if you want to keep a copy.
Deletion removes sign-in records, child profiles, saved activities, learning plans and sessions, and account-scoped usage counters. If there is no billing history, the account row is deleted. If billing history exists, the account email is replaced with a deleted-account marker and the limited billing and audit records described above remain.
Copies that were already captured in private recovery history or weekly exports can remain for up to approximately 35 days; account deletion does not erase those existing recovery copies immediately.
Deleting your account cannot be undone. It does not itself cancel a subscription or request a refund. If deletion is available while canceled paid access remains, deleting the account gives up that remaining access. Provider records are not automatically deleted with the KinLark account.
Payments and billing
Paid checkout may be paused during launch checks, maintenance, or an operational review. The Pricing and Account pages show current availability.
Paid subscriptions are offered when checkout is available and where Creem supports purchases.
For paid subscriptions, Creem hosts checkout and acts as merchant of record. Creem may receive a parent's name, verified email address, IP address, payment details, and billing information needed to process payments, taxes, invoices, subscriptions, refunds, fraud checks, and buyer support.
Creem's current Data Processing Agreement states that buyer name, email address, and IP address are processed to generate AI-based statistics and lists OpenAI as an AI API subprocessor in Ireland and the United States. KinLark has chosen to make paid checkout available under those disclosed provider terms. You can continue using the Free plan without entering Creem checkout.
KinLark will not send Creem a child's nickname, age range, profile, challenge, generated activity, saved activity, or progress information. Creem's own terms and privacy notice apply to the information it receives through checkout and its customer portal.
Your choices and contact
You can email support@kinlark.com to request access, correction, deletion, a portable copy, a change to your marketing preference, or help with a provider record. We may need to verify that the request concerns your account.
Depending on where you live, you may also have rights to restrict or object to processing, withdraw consent, or complain to a privacy regulator. These rights can have legal limits and exceptions.
We use reasonable safeguards designed for the beta, but no online service can guarantee complete security.
We may update this notice as the product develops. Material changes will be reflected in the updated date above.