Privacy Policy
Your moments are yours. Here is exactly what we collect, why, who sees it, and what you can do about it.
effective April 16, 2026
The bullet points below are a friendly summary, not the legal agreement. The numbered sections below them are what governs.
- We only collect what we need to run Kith: your phone number, your display name, the content you share inside your spaces, and basic technical logs.
- Your phone number lives in a separate, self-only table — other members of your spaces can never see it, by design. Your display name and avatar are all anyone else sees.
- Your content stays inside your space. We do not sell your data, we do not use it to train AI, we do not run ads, and we do not embed third-party social or advertising trackers.
- We use a small set of trusted vendors (Vercel, Supabase, Google Firebase, Stripe, Anthropic, Resend, Upstash, Sentry) to actually deliver the service. Their job is bounded by contract.
- We honor your browser’s Do Not Track and Global Privacy Control signals. If they are on, we drop our cookieless usage analytics for your session entirely.
- You can see, export, correct, or delete your data at any time — by yourself in the app, or by emailing privacy@startakith.com.
- Kith is not for children under 13. If you are in the EU/UK, the EEA, California, or another place with specific privacy rights, those rights apply to you and we honor them.
- 01.Who we are
- 02.Information we collect
- 03.How we use your information
- 04.Legal bases for processing (EU/UK only)
- 05.How we share your information
- 06.Service providers and sub-processors
- 07.Cookies and similar technologies
- 08.How long we keep your information
- 09.How we protect your information
- 10.International data transfers
- 11.Your rights and choices
- 12.Children’s privacy
- 13.Changes to this policy
- 14.How to contact us
Who we are
A small company in the U.S. We built and run Kith.
Kith is operated by Real Tech LLC (“Real Tech LLC,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, share, and protect your personal information when you use Kith via startakith.com, our mobile web app, or any related services (collectively, the “Service”).
For purposes of the EU and UK General Data Protection Regulation (the “GDPR”), Real Tech LLC is the “controller” of the personal data we process about you. You can reach our privacy team at privacy@startakith.com or by mail at [Real Tech LLC, business mailing address — TODO].
By using the Service, you acknowledge that you have read this Privacy Policy. If you do not agree with it, please do not use Kith.
Things you tell us, things you put in your spaces, and basic technical info needed to deliver the app.
We collect information in three ways: (a) information you provide to us directly, (b) information generated when you use the Service, and (c) information we receive from a small number of trusted service providers acting on our behalf.
- Account information. When you create an account we collect your mobile phone number (used solely for SMS one-time passcode authentication and account recovery), an optional display name, and an optional profile photo. Your phone number is stored in a separate, self-only table that other members of your spaces cannot read; to them, you are your display name and avatar only.
- Content you share. When you participate in a space we store the messages, photos, videos, reactions, wishes, help offers, captions, and any other content you choose to post, together with metadata such as timestamps and which space you posted in.
- Membership and invite data. The list of spaces you belong to, your role within each space (owner, admin, or member), the invitations you send and receive, and basic membership history.
- Subscription and billing data. If you purchase a paid plan, our payment processor (Stripe) collects payment-card and billing-address information directly. We receive a subscription status, plan tier, and a tokenized customer reference — we never see your full card number.
- Device and usage data. We automatically record information about how the Service is used, including IP address, device type, operating system, browser type and version, referring URL, pages or features used, approximate session duration, and diagnostic logs (including error reports collected via Sentry).
- Push and email tokens. If you enable notifications, we store the device push token, browser push subscription, or email address required to deliver the notifications you have asked for.
- Cookies and similar technologies. We use a small number of strictly necessary first-party cookies for authentication and security. We do not use advertising cookies or third-party tracking pixels. See section 7.
We do not knowingly collect government-issued identifiers, precise geolocation, biometric data, or special categories of personal data (such as health, ethnicity, sexual orientation, or religious belief) as part of the Service. Any such information that you choose to post into a space is processed only as “content you share” and is visible only to the members of that space.
To run the app, keep it working, keep it safe, and let you reach us.
We use your information for the following purposes:
- Provide the Service. Authenticate you, deliver messages and photos, route reactions, render your spaces, and store your content so it is available the next time you sign in.
- Maintain and improve the Service. Diagnose performance issues, debug errors, prevent abuse, plan capacity, and decide what to build next based on aggregated, non-identifying usage patterns.
- Communicate with you. Send transactional messages you have asked for (sign-in codes, security alerts, invite notifications, billing receipts) and respond to your support requests.
- Provide AI-assisted features. When you opt to use a feature like “Catch up” chat summaries or AI photo captions, we send the relevant content for that single request to our AI provider (Anthropic) for processing. See section 6.
- Process payments. If you subscribe, we use Stripe to process your payment, charge subscriptions on a recurring basis, and handle refunds, chargebacks, and tax compliance.
- Comply with law and protect rights. Meet our legal obligations, enforce our Terms of Service, investigate suspected abuse, and protect the safety, rights, and property of you, us, and others.
We do not use your personal information for behavioral advertising, we do not sell or “share” your personal information for cross-context behavioral advertising as those terms are defined under U.S. state privacy law, and we do not use your content to train artificial intelligence or machine-learning models — our own or anyone else’s.
If you are in Europe, here is the lawful basis we rely on for each kind of processing.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR or UK GDPR:
- Performance of a contract — to provide the Service you have signed up for, including authenticating you, delivering your messages and photos, and processing subscriptions you have purchased.
- Legitimate interests — to keep the Service secure, prevent fraud and abuse, debug errors, understand aggregate usage, and improve our product. We balance these interests against your rights and freedoms.
- Consent — to enable optional features such as push notifications, AI-assisted features, or marketing emails. You may withdraw consent at any time.
- Legal obligation — to comply with applicable laws, tax requirements, court orders, and lawful requests from public authorities.
These vendors do specific jobs for us. Each one is bound by contract and processes only what is needed.
To deliver the Service we rely on the following service providers (sometimes called “sub-processors”). Each is contractually bound to handle your data only as instructed by Real Tech LLC, in accordance with applicable law and appropriate technical and organizational safeguards.
| Provider | Purpose | Region |
|---|---|---|
| Vercel, Inc. | Application hosting, edge delivery, and cookieless aggregate page-view + performance metrics (Vercel Analytics and Speed Insights). Disabled when your browser sends Do Not Track or Global Privacy Control. | United States |
| Supabase, Inc. | Database, authentication, file storage, realtime | United States |
| Google LLC (Firebase Authentication) | SMS delivery for one-time passcodes | United States |
| Stripe, Inc. | Subscription billing and payment processing | United States |
| Anthropic, PBC | AI processing for opt-in summary and caption features | United States |
| Resend, Inc. | Transactional email delivery | United States |
| Upstash, Inc. | Rate limiting and abuse prevention | United States |
| Functional Software, Inc. (Sentry) | Error monitoring and diagnostics | United States |
We review this list periodically and update it before adding a new sub-processor that processes your personal data. If you would like to receive advance notice of changes, write to privacy@startakith.com.
Anthropic processes content you submit to AI features only to return a response for that single request and, per our agreement with them, does not retain it for model training. AI features are off by default on the free tier and are only invoked when you explicitly trigger them.
As long as your account is active. After deletion, content is removed within 30 days; backups roll off within 90 days.
We retain your personal information for as long as your account is active and for as long as needed to provide the Service. The specific periods are:
- Account data — kept while your account exists. When you delete your account, we delete or de-identify it within 30 days from our production systems and within 90 days from encrypted backups.
- Content you posted into a space — kept for as long as the space exists. When you delete an individual message, photo, wish, or help offer, it is removed from the space immediately and purged from production within 30 days. Note that copies may persist on devices of other members who have already received them.
- Spaces — when an owner deletes a space, all of its content (messages, photos, wishes, help offers, member list) is deleted within 30 days from production and within 90 days from backups.
- Billing records — kept for the period required by tax and accounting law in the relevant jurisdiction (typically up to 7 years).
- Security and abuse logs — retained for up to 12 months in identifiable form for fraud prevention and incident investigation, then aggregated or deleted.
When the law requires us to retain information for longer (for example, to respond to a legal hold), we will keep only what is necessary to satisfy that obligation.
Encryption in transit and at rest, least-privilege access, monitoring, and a real plan if something goes wrong.
We apply technical and organizational safeguards designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These include:
- Encryption of data in transit using TLS 1.2 or higher.
- Encryption of data at rest in our database and object storage.
- Multi-tenant isolation enforced by row-level security policies tying every record to a specific space and an authenticated user.
- Phone numbers stored in a separate, self-only table that not even your fellow space members can read — only you and our service role can ever see your number.
- Realtime channels (presence, broadcast, postgres-changes) gated by membership: simply knowing a space ID is not enough to subscribe.
- Photo/video storage paths bound to your space; cross-tenant URL re-attachment is rejected at the API layer.
- Cryptographically random invite codes (CSPRNG) and short-lived (≤ 10 minute) signed media URLs.
- Stripe webhooks idempotency-checked and replay-protected; webhook payloads (which contain billing PII) are never logged.
- Sentry telemetry scrubbed for phone numbers, OTP codes, JWT/auth tokens, signed-URL tokens, and request cookies; session replays mask all text and inputs.
- Least-privilege access: only a small number of named employees have production access, on principle of need; all access is audited.
- Rate limiting, abuse detection, and continuous error monitoring.
- Regular security review of our infrastructure, dependencies, and third-party providers.
No method of transmission over the internet or electronic storage is 100% secure. Despite our efforts, we cannot guarantee absolute security. If we become aware of a personal-data breach affecting your information, we will notify you and the relevant supervisory authority within the timelines required by applicable law.
If you believe your account has been compromised or you have discovered a security vulnerability, please contact us immediately at legal@startakith.com.
Our servers are in the United States. If you live elsewhere, your data is transferred to and stored in the U.S.
Real Tech LLC is based in the United States. The personal information we collect is stored and processed primarily on servers located in the United States, including by the sub-processors listed in section 6.
If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country.
For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on the European Commission’s Standard Contractual Clauses (and, where applicable, the UK International Data Transfer Addendum) with each recipient, supplemented by appropriate technical and organizational measures.
You can see, export, correct, or delete your data. Most of it you can do yourself in the app.
Subject to applicable law, you have the following rights with respect to your personal information:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct inaccurate or incomplete data. You can update your display name and profile photo yourself in your account settings.
- Deletion — request that we delete your account and associated personal data. You can delete your account from settings.
- Portability — request that we provide your data in a structured, machine-readable format.
- Restriction or objection — ask us to restrict or object to certain processing, including processing based on our legitimate interests.
- Withdraw consent — withdraw any consent you have given (for example, for push notifications or AI features) at any time. Withdrawal does not affect the lawfulness of past processing.
- Lodge a complaint — complain to your local data protection authority. We would appreciate the chance to address your concerns first.
For California residents (CCPA / CPRA): You have the right to know what personal information we have collected about you, the categories of sources, the business or commercial purpose for collecting it, and the categories of third parties to whom we disclose it. You have the right to request deletion or correction of your personal information, and the right not to be discriminated against for exercising any of these rights. We do not sell or “share” personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that require an opt-out under California law.
To exercise any of these rights, sign in and use the relevant in-app control, or write to privacy@startakith.com. We may need to verify your identity (typically by confirming control of the phone number on the account). We will respond within the time required by applicable law (generally 30 days under the GDPR and 45 days under the CCPA). An authorized agent may submit a request on your behalf with written proof of authorization.
Kith is not for kids under 13. If we learn we have, we delete it.
Kith is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you are under 13, please do not use Kith.
If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us at privacy@startakith.com and we will take steps to delete that information. For users between 13 and the age of digital consent in their jurisdiction (16 in many parts of the EU), we rely on parental authorization where required.
When we change anything material, we tell you in the app first.
We may update this Privacy Policy from time to time to reflect changes to our practices, technology, legal requirements, or other factors. We will revise the “effective” date at the top of the policy whenever we make a change.
If a change is material, we will notify you in advance through the app, by email, or by SMS to the phone number on your account, and we will give you a meaningful chance to review the change before it takes effect.
Your continued use of the Service after the effective date of an updated policy constitutes acceptance of that policy. If you do not agree to a change, please stop using the Service and delete your account.
Real humans, real email addresses.
For privacy questions, data-subject requests, or to reach our privacy team, email us at privacy@startakith.com. For account or billing help, write to support@startakith.com. For legal notices including DMCA takedowns, write to legal@startakith.com.
Postal mail: Real Tech LLC, [Real Tech LLC, business mailing address — TODO].
If you are in the EU/UK and would like to escalate a complaint, you have the right to lodge it with your local supervisory authority. We would, however, appreciate the opportunity to resolve any concern with you first.
Plain-English questions get plain-English answers. We read every message we get.
