1. Who is responsible
This notice describes how personal information is handled through the Kinvoria service. Privacy questions and requests may be sent to the contact published below. Google and Paddle act under their own privacy notices for their parts of the service.
Controller and service operatorKinvoriaContact: [email protected]This notice applies to organizers, contributors, recipients, intended listeners, and visitors of any age. If a person is below the applicable age of consent or otherwise cannot provide valid authorization, their parent or legal guardian must actively assist them and provide the permission or other lawful authorization required for their participation and information. Organizers must be authorized to provide another person's information. Before creating the project, the organizer must provide each project subject—or their parent or legal guardian where appropriate—with the Recipient and project-subject privacy notice and confirm that this was actually done before creating the project.
2. Information we collect
Organizers provide an occasion, recipient or group name, event date, prompt, collection deadline, locale, timezone, email, and explicit confirmations that the organizer has authority to provide the information, that any required parent or legal guardian is involved, and that the recipient privacy notice was provided before creation. We do not ask for or store a recipient's or project subject's full date of birth. Birthday projects include only the whole-number age displayed on the gift, from 1 to 150, and whether it is a current or upcoming age. Organizers sign in with Google. Contributors may also choose Google sign-in, which supplies an account identifier, email, display name, optional profile image, account locale, and, when the person uses a Google Workspace account, its hosted-domain claim.
Contributors use a private invitation, then either continue as a guest or optionally sign in with Google. They provide a display name, optional relationship, one final submission consent record, and one audio recording of up to 90 seconds. Google account identifiers limit the same signed-in account to one active contribution per project. When a private contribution invitation is opened while signed out, the browser generates a first-party, high-entropy random contribution token and sends it to Kinvoria to check guest duplicate status. If the contributor continues as a guest, the same token accompanies the submission. The server combines it with the project ID and stores only a project-scoped SHA-256 digest, which avoids using one stable server-side value to link the browser across projects. That digest limits the same guest browser token to one active contribution in the project. If the contributor instead signs in with Google, the account identity is used for duplicate prevention and the token is ignored for that signed-in submission. This is not a MAC address, hardware identifier, or browser fingerprint, and we do not attempt to derive one. Clearing Kinvoria site data, using private browsing, changing browsers, or changing devices can create a new token, so this control discourages ordinary duplicates but cannot reliably identify a person. A recording may naturally reveal personal information about the speaker or another person. Do not submit unnecessary medical, financial, government-identifier, precise-location, or other highly sensitive information. When a child's name, voice, story, image, or other personal information is submitted, the parent or legal guardian must provide the authorization required for that submission and actively assist where necessary.
A person holding a valid private contribution link can view the limited project information made available through that link. At final submission, we record the contributor's privacy and policy acknowledgment, content-rights confirmation, any required guardian authorization, policy versions and content hashes, either the local account link or project-scoped guest-token digest used to prevent ordinary duplicate submissions, and server time. The raw guest token is not stored on the server. Private listening may require a separate time-limited privacy and policy confirmation.
We also receive technical and service information such as file type and duration, upload and render status, browser type and standard request metadata, approximate event time, IP-derived security data, request logs, and private-link use. We do not ask for an address book or guest email list and do not use these details to fingerprint a contributor's device.
Paddle handles checkout, tax, and receipts. We receive the order state, amount, currency, and transaction identifiers needed to reconcile delivery and support; we do not receive raw card details.
When an organizer enters the creation flow through a link containing a currently active affiliate code, we associate the referring partner identifier, attribution timestamp, and a snapshot of the commission amount and currency with the resulting Project. If the organizer starts checkout, that limited attribution snapshot is also associated with the Order. If a durable financial record must survive account or project deletion, the same snapshot is copied to the payment-reconciliation ledger. The affiliate code identifies the referring publisher, not the organizer, contributor, recipient, or intended listener, but the Project and Order associations mean the source record is linked to the organizer and their purchase in Kinvoria's systems.
3. Purposes and legal bases
We process account, project, contribution, and order information to provide the service and perform our contract with organizers; to act on a contributor's request to submit or remove a recording; and to take steps requested before a purchase.
We rely on legitimate interests where appropriate to secure private links, prevent duplicate contributions, prevent fraud and abuse, diagnose failures, improve reliability, and answer support requests. Those interests are balanced against the limited, private nature of the service. We rely on legal obligations for tax, accounting, consumer, fraud, dispute, and regulatory records. Where applicable law requires consent for a particular use, we ask for it separately and it may be withdrawn for future processing.
We use a limited affiliate-attribution record to attribute verified sales, calculate and reconcile partner commissions, prevent referral fraud and duplicate claims, and account for refunds and chargebacks. We do not use an affiliate code for cross-site tracking, profiling, or targeted advertising.
Voice recordings are used only to receive, validate, normalize, assemble, host, play, download, rebuild, and delete the private gift. We do not sell recordings or personal information, use them for targeted advertising, train AI models with them, identify a speaker biometrically, or infer health or other sensitive traits.
4. Access, sharing, and international processing
An organizer can see contributor display names, relationships, submission metadata and, when a contributor chose Google sign-in, the optional Google profile image; the organizer can manage inclusion and order, and access or download the finished radio. A contributor's Google email and account identifier are not shown to the organizer. A guest's raw token and server-side digest are also not shown to the organizer. A recipient or intended listener given the private listening link can hear the finished radio after completing any required privacy and policy confirmation. A parent or legal guardian must assist when the listener cannot validly complete that confirmation themselves. A person holding a valid private contribution link can view its limited project details while collection is open and gives one explicit set of confirmations when finally submitting. Private links act as credentials and should be shared only with the intended people.
We use the following recipients or categories of recipients only for the work identified. The location column states the processing location we can accurately disclose; provider-managed services may use the locations described in their own privacy documentation.
| Role | Recipient or category | Processing location |
|---|---|---|
| Core service hosting and private media storage | Cloud infrastructure and private storage provider | Singapore |
| Organizer identity and optional contributor identity | Locations described in Google’s privacy documentation | |
| Checkout, tax, and payment support | Paddle | Locations described in Paddle’s privacy documentation |
| Essential transactional email | Transactional email delivery provider | Locations described in the provider’s privacy documentation |
If a Project was attributed to an affiliate partner, that partner may receive only aggregate sale counts and commission amounts needed to reconcile the affiliate program. Affiliate partners do not receive organizer, contributor, recipient, or listener names or email addresses, and they do not receive voice recordings.
We may also disclose limited information to professional advisers, regulators, courts, or law enforcement when lawfully required, or in connection with a business reorganization subject to appropriate protections.
These providers may process information outside the country where it was collected. Where transfer rules apply, we use an available legal mechanism such as an adequacy decision or approved contractual safeguards. Contact us to request more information about safeguards relevant to your data.
5. Retention
| Information | Typical retention | Why |
|---|---|---|
| Original uploads | Queued for deletion 30 days after the first final render | Short recovery and rebuild window |
| Permission, policy, and access evidence | Current project-level authority, guardian-authorization where applicable, privacy-notice-provided, and policy confirmations remain with active project metadata and are deleted or redacted with the project or account. Historical eligibility confirmations recorded under earlier policy versions follow the same lifecycle; they do not create a current age restriction. We do not retain a full date of birth for a project subject. Private-listening access grants expire after 30 minutes; their evidence rows are deleted with the project. Versioned contribution confirmations follow the project deletion lifecycle. | Record authority, notices, and private-access choices |
| Processed chapters and final MP3 | Hosted for 90 days, then queued for deletion | Private playback and download |
| Unpaid unfinished projects | Project details are redacted and associated audio is queued for deletion 30 days after the collection deadline | Short recovery without indefinite storage |
| Active and completed project metadata | Recipient, occasion, prompt, contributor, consent, status, and project-history records remain while the organizer account is active, including after hosted audio expires. A project deletion immediately replaces the main personal project and contributor fields and revokes private links. A second retention pass removes or redacts remaining project content 30 days after the completed deletion, once physical media cleanup is confirmed. Versioned consent evidence may remain linked to the organizer account until account deletion. | Library history, support, deletion evidence, and order delivery |
| Organizer or contributor account and profile | While the account is active, then deleted on account deletion except for required records | Sign-in, library, contribution uniqueness, and account support |
| Guest duplicate-prevention digest | Kept with the related contribution and project metadata, then removed or redacted through the same contribution, project, and retention lifecycle | Discourage repeat guest submissions from the same browser |
| Essential email delivery records | Recipient address, subject, body, provider message identifier, and last error are purged 30 days after a message reaches a terminal sent or failed state. This clears the delivery outbox copy; it does not delete the separate immutable order confirmation and purchase-consent evidence described below. A minimal notification type, status, attempt count, and timestamps remain with the related account until account deletion. The email provider may keep its own delivery records under its documented retention rules. | Deliver essential links and hosted-expiry reminders |
| Security and diagnostic logs | Application operational events are deleted after 30 days; security events are deleted after 90 days. Infrastructure providers may retain their own access or security logs under separately configured provider periods. | Protect and troubleshoot the service |
| Payment and webhook integrity records | Order, transaction and customer references, purchaser email, amount, currency, status, consent versions and hashes, the immutable confirmation snapshot, event identifiers and timestamps are not governed by the 30- or 90-day audio periods. After account deletion, the payment ledger, purchase-consent evidence, and immutable order-confirmation evidence remain disconnected from the deleted local account and project but can still contain finite identifying information needed for payment reconciliation, tax, accounting, fraud prevention, disputes, consumer rights, and legal obligations. Production deletes eligible evidence in bounded batches only after the legally reviewed payment evidence period has elapsed from both its latest update and latest provider event. Evidence remains longer while a live order, pending refund, active confirmation delivery, legal hold, dispute, or binding legal requirement applies. Processed Paddle webhook integrity records use a separate configured period. | Reconciliation and legal obligations |
| Affiliate attribution snapshots | The partner identifier, attribution timestamp, and commission amount-and-currency snapshot remain with the related Project while that Project is retained. If checkout begins, the same limited snapshot is copied to the Order. If required financial evidence later survives account or project deletion, it is copied to the payment ledger. The Project copy follows the project-deletion lifecycle; the Order and any ledger copies follow the payment-evidence retention criteria above and may remain when needed for commission, refund, chargeback, fraud, accounting, dispute, or legal reconciliation. | Verified-sale attribution and commission reconciliation |
The 30- and 90-day periods above apply to audio and abandoned-project cleanup, not to every account, support, security, or transaction record. Those other records use the separate purpose-based criteria stated in the table.
Deletion is asynchronous and failed cleanup attempts are retried. Provider backups may persist for a limited recovery cycle before being overwritten. We may preserve information subject to a legal hold, active dispute, or binding legal requirement, and delete or de-identify it when that exception ends.
6. Cookies and browser storage
We use an essential session cookie for secure sign-in and browser storage for create-flow, optional contribution sign-in, guest duplicate prevention, and checkout recovery. A signed-out browser opening a contribution invitation keeps a first-party random contribution token and sends it only to Kinvoria to check guest duplicate status and, if the contributor continues as a guest, to submit. The server keeps only a project-scoped SHA-256 digest. If the contributor signs in with Google instead, the token is ignored for that signed-in submission. It is not a MAC address, hardware identifier, or fingerprint. Clearing site data, private browsing, or changing browsers or devices can reset this limited safeguard. Contribution sign-in stores the private invitation token only in the same tab, removes it immediately after the Google return, and never sends it to Google. Create-flow recovery may also keep the active affiliate code from the creation URL in the same tab solely to preserve referral attribution while the organizer completes a requested Google sign-in. The code is not sent to Google, is not a 30-day cookie or cross-site identifier, and clears with the create-flow recovery or when the tab session ends. Create-flow recovery does not contain a recipient's or project subject's full date of birth. We do not currently use advertising or optional analytics cookies. The Cookie notice identifies each category, purpose, duration, and available control.
7. Your controls
A contributor receives a separate private removal link. Removing a voice before final render removes it from the project. Removing it later revokes the hosted version and queues a clean rebuild without that chapter where technically possible. A downloaded copy on another person's device cannot be remotely recalled.
Organizers can delete a project, and signed-in organizers or contributors can permanently delete their account from the Account page. If payment confirmation is in progress, account or project deletion may be delayed briefly and can be retried after the transaction settles. A completed project deletion revokes that project's private links, redacts its personal project and contributor details, and queues associated audio for deletion. A completed account deletion also signs out sessions, deletes the local account and remaining owned projects, and removes voices the account contributed to other projects, triggering a privacy rebuild when technically possible. Necessary payment-ledger, purchase-consent, and immutable order-confirmation records may remain as described above. They are disconnected from the local account and project but include limited purchaser and transaction identifiers and may remain linkable to Paddle's transaction records until the configured retention period ends or a legal hold is released; they are not described as anonymous.
8. Privacy rights
Depending on where you live, you may have rights to know or access your information, receive a portable copy, correct it, delete it, restrict or object to processing, withdraw consent, and appeal a decision. You may also complain to your local privacy regulator. We do not discriminate against anyone for exercising a privacy right.
We do not sell personal information or share it for cross-context behavioral advertising, so there is no sale or targeted-advertising opt-out to exercise. We do not use solely automated decisions that produce legal or similarly significant effects.
Submit a request through Contact us. We may need to verify your identity or possession of the relevant private link. An authorized agent may submit a request where local law allows. We respond within the period required by applicable law.
9. Security and changes
We use administrative, technical, and organizational safeguards designed for the sensitivity of private voice content, including encrypted transport, restricted service access, role-specific random links, file validation, rate limits, and signature-verified payment events. No system is completely secure, so keep private links secret and contact us if one may have been exposed.
People of any age may participate. When a person is below the age at which they can validly authorize the relevant processing, their parent or legal guardian must actively assist and provide the authorization required under applicable law. We may update this notice when our service or legal obligations change. Material changes will be posted here and, where appropriate, communicated directly. The effective date above identifies the version in force.