Trust

Security

How Kinrally protects family data — encryption in transit, on-device vault encryption, session-verified sync — and how to report a vulnerability privately.

Last updated: August 12, 2026

How Kinrally protects household data, what we deliberately do not claim, and how to report a vulnerability.

1. How we protect your data

  • All traffic between the apps and our services is encrypted in transit.
  • Family sync requires a signed-in account and is verified on every single request, so only members of your family group can read your household's data.
  • Documents Vault files are encrypted on your device with AES-256-GCM before upload, using a key derived from your family code (PBKDF2-HMAC-SHA256, 200,000 iterations). Our servers store ciphertext only.
  • Calendar events marked Private never leave your device.
  • Our deletion audit trail stores one-way SHA-256 hashes of email addresses, never plaintext addresses.

2. What we don't claim

The Documents Vault is not zero-knowledge, and family chat is not end-to-end encrypted.

The vault key is derived from your family code, which is also used to route your household's sync data, so it is known to our service rather than to your devices alone. Chat is private, invite-only and encrypted in transit, but messages pass through our sync service in a form our infrastructure could technically read. We do not read them and never use them for advertising, analytics or AI training — but please don't use family chat for passwords or financial account numbers.

No online service can promise perfect security. Keep your own copies of documents that would be painful to lose.

3. Your part

  • Your family code grants access to your household's synced data and derives your vault encryption key. Treat it like a password.
  • Use a strong, unique password for your Kinrally account.
  • Delete your account, or remove members, when someone should no longer have access.

4. Reporting a vulnerability

If you believe you've found a security issue, please report it privately to support@kinrally.com with the subject line "Security report". Include steps to reproduce, the affected surface (iOS app, Android app, website or API), and any proof-of-concept detail.

  • We aim to acknowledge reports within 3 business days.
  • Please give us a reasonable window to remediate before any public disclosure.
  • Do not access, modify or delete data belonging to other households while testing, and do not run denial-of-service or spam tests.
  • We will not pursue legal action against good-faith research that follows these guidelines.

We do not currently run a paid bug bounty, but we credit reporters who ask to be.

See also our Privacy Policy and Cookies & Tracking page.