Privacy Policy

Effective Date: March 30, 2026

1. Introduction

Welcome to Kindred. We are committed to protecting your privacy and being transparent about how we collect, use, and protect your personal data.

Kindred is an AI-powered cooking app that helps you discover recipes based on your dietary preferences and pantry contents. Our standout feature is voice cloning: you can upload a voice sample of a loved one, and we'll use it to narrate recipes in their voice, making cooking feel like a warm conversation with someone you care about.

Data Controller: Ersin Kirteke
Location: Vilnius, Lithuania (European Union)
Contact: privacy@kindred.app

2. Data We Collect

2.1 Voice Data (Biometric Identifier)

What: Audio recordings of human speech (30-90 seconds) for AI voice cloning

Why: To create a personalized AI-cloned voice that narrates recipes in Kindred

How it works:

  • You upload a voice recording via the app (requires explicit consent)
  • Audio is sent to ElevenLabs (third-party AI voice provider) for processing
  • Audio sample is stored in Cloudflare R2 storage (encrypted)
  • Voice is used ONLY for recipe narration within Kindred
  • Voice is NEVER shared with other users

Legal basis: Explicit consent (GDPR Article 6(1)(a) + Article 9(2)(a) for biometric data)

Retention: Stored until you delete it from Settings or close your account

Your rights: Delete your voice profile anytime from Settings → Privacy & Data

2.2 Location Data

What: City-level location (coarse location, not precise GPS)

Why: To show you trending recipes in your area

How it works:

  • Location is detected once during onboarding (requires system permission)
  • Geocoded to city name using Mapbox API
  • Location is processed on-device first, then sent to Mapbox for city lookup
  • We do NOT store your GPS coordinates

Legal basis: Consent (GDPR Article 6(1)(a))

Retention: Location preference stored locally on your device (UserDefaults)

Your rights: Change location anytime from app settings

2.3 Account Data

What: Email address, Apple ID identifier (if you sign in with Apple)

Why: Authentication and account management

How it works:

  • Authentication managed by Clerk (third-party auth provider)
  • If you sign in with Apple, we receive a privacy-preserving Apple ID token
  • Email is used for account recovery and security notifications (if provided)

Legal basis: Contract performance (GDPR Article 6(1)(b))

Retention: Until you delete your account

2.4 Analytics & Diagnostics

What: App usage events, crash logs, device model, OS version

Why: To improve app stability and understand how features are used

How it works:

  • Collected via Firebase Analytics and Firebase Crashlytics
  • Data is anonymous and aggregated
  • NOT linked to your account or identity

Legal basis: Legitimate interest (GDPR Article 6(1)(f))

Retention: 14 months (Firebase default)

2.5 Advertising Data (Free Tier Only)

What: Ad impressions, ad interactions

Why: To fund the free tier via non-personalized ads

How it works:

  • Ads served by Google AdMob
  • Kindred does NOT use personalized ads (no tracking across apps)
  • We do NOT request IDFA (Apple's advertising identifier)
  • Pro subscribers see NO ads

Legal basis: Legitimate interest (GDPR Article 6(1)(f))

3. Your Rights (GDPR)

As a user in the European Union, you have the following rights under GDPR:

3.1 Access & Portability

You can request a copy of your personal data in a machine-readable format (JSON). Email privacy@kindred.app with subject "Data Export Request".

3.2 Deletion (Right to Erasure)

You can delete your data at any time:

Upon account deletion, we will:

3.3 Withdraw Consent

You can withdraw consent for voice cloning or location access at any time:

3.4 Object to Processing

You can object to analytics or advertising by:

3.5 Lodge a Complaint

If you believe we've violated your privacy rights, you can file a complaint with your national Data Protection Authority (DPA). In Lithuania: State Data Protection Inspectorate.

4. Third-Party Services

Kindred uses the following third-party services to provide core functionality:

These services are bound by their own privacy policies and may process data in the United States. ElevenLabs and Cloudflare are GDPR-compliant and use Standard Contractual Clauses (SCCs) for EU data transfers.

5. Data Security

We implement industry-standard security measures to protect your data:

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

6. Children's Privacy

Kindred is not intended for children under the age of:

We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@kindred.app and we will delete it immediately.

7. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in:

Material changes will be notified via:

Your continued use of Kindred after changes constitutes acceptance of the updated policy.

8. Contact Us

For privacy-related questions, data requests, or to exercise your rights under GDPR:

Data Controller: Ersin Kirteke
Email: privacy@kindred.app
Location: Vilnius, Lithuania (European Union)
Response time: Within 30 days (as required by GDPR Article 12)