Effective July 31, 2026 · Version 2026-07-31-v12

Privacy notice

A voice is personal.
The rules should be plain.

This notice explains what we collect, why we use it, who receives it, how long we keep it, and the choices available to you.

1. Who is responsible

This notice describes how personal information is handled through the Kinvoria service. Privacy questions and requests may be sent to the contact published below. Google and Paddle act under their own privacy notices for their parts of the service.

Controller and service operatorKinvoriaContact: [email protected]

This notice applies to organizers, contributors, recipients, intended listeners, and visitors. The service is adult-only: each organizer, contributor, recipient, project subject, and intended listener must already be at least 18. Parent or guardian permission does not create an exception for a minor. Organizers must be authorized to provide another adult's information. Before creating the project, the organizer must actually provide each adult project subject with the Recipient and project-subject privacy notice and confirm that this was actually done before creating the project.

2. Information we collect

Organizers provide an occasion, recipient or group name, event date, prompt, collection deadline, locale, timezone, email, and explicit confirmations that the organizer and every project subject are adults, that the organizer has authority to provide the information, that the recipient privacy notice was provided before creation, and that no minor's information will be added. We do not ask for or store a recipient's or project subject's full date of birth. Birthday projects include only the whole-number adult age displayed on the gift, from 18 to 150, and whether it is a current or upcoming age. Organizers must sign in with Google, which supplies an account identifier, email, display name, optional profile image, account locale, and, when the organizer uses a Google Workspace account, its hosted-domain claim.

Contributors do not need a Google login or Kinvoria account. They use a private invitation and provide a display name, optional relationship, one final submission consent record, and one audio recording of up to 90 seconds. A recording may naturally reveal personal information about the speaker or another person. Do not submit unnecessary medical, financial, government-identifier, precise-location, or other highly sensitive information. Do not submit any minor's name, voice, story, image, or other personal information.

A person holding a valid private contribution link can view the limited project information made available through that link. At final submission, we record the contributor's explicit 18+ confirmation, privacy acknowledgment, content-rights and no-minor confirmations, policy versions and content hashes, and server time. Private listening remains subject to its separate adult-access gate.

We also receive technical and service information such as file type and duration, upload and render status, browser and device details, approximate event time, IP-derived security data, request logs, and private-link use. We do not ask for an address book or guest email list.

Paddle handles checkout, tax, and receipts. We receive the order state, amount, currency, and transaction identifiers needed to reconcile delivery and support; we do not receive raw card details.

3. Purposes and legal bases

We process account, project, contribution, and order information to provide the service and perform our contract with organizers; to act on a contributor's request to submit or remove a recording; and to take steps requested before a purchase.

We rely on legitimate interests where appropriate to secure private links, prevent fraud and abuse, diagnose failures, improve reliability, and answer support requests. Those interests are balanced against the limited, private nature of the service. We rely on legal obligations for tax, accounting, consumer, fraud, dispute, and regulatory records. Where applicable law requires consent for a particular use, we ask for it separately and it may be withdrawn for future processing.

Voice recordings are used only to receive, validate, normalize, assemble, host, play, download, rebuild, and delete the private gift. We do not sell recordings or personal information, use them for targeted advertising, train AI models with them, identify a speaker biometrically, or infer health or other sensitive traits.

4. Access, sharing, and international processing

An organizer can see contributor names, manage inclusion and order, and access or download the finished radio. An eligible adult recipient or intended adult listener given the private listening link can hear the finished radio after completing the adult-access gate. A person holding a valid private contribution link can view its limited project details while collection is open and gives one explicit set of confirmations when finally submitting. Private links act as credentials and should be shared only with the intended people.

We use the following recipients or categories of recipients only for the work identified. The location column states the processing location we can accurately disclose; provider-managed services may use the locations described in their own privacy documentation.

RoleRecipient or categoryProcessing location
Core service hosting and private media storageCloud infrastructure and private storage providerSingapore
Organizer identityGoogleLocations described in Google’s privacy documentation
Checkout, tax, and payment supportPaddleLocations described in Paddle’s privacy documentation
Essential transactional emailTransactional email delivery providerLocations described in the provider’s privacy documentation

We may also disclose limited information to professional advisers, regulators, courts, or law enforcement when lawfully required, or in connection with a business reorganization subject to appropriate protections.

These providers may process information outside the country where it was collected. Where transfer rules apply, we use an available legal mechanism such as an adequacy decision or approved contractual safeguards. Contact us to request more information about safeguards relevant to your data.

5. Retention

InformationTypical retentionWhy
Original uploadsQueued for deletion 30 days after the first final renderShort recovery and rebuild window
Adult eligibility and access evidenceProject-level adult, data-authority, privacy-notice-provided, and no-minor confirmations remain with active project metadata and are deleted or redacted with the project or account. We do not retain a full date of birth for a project subject. Private-listening access grants expire after 30 minutes; their evidence rows are deleted with the project. Versioned contribution confirmations follow the project deletion lifecycle.Enforce and demonstrate the adult-only gate
Processed chapters and final MP3Hosted for 90 days, then queued for deletionPrivate playback and download
Unpaid unfinished projectsProject details are redacted and associated audio is queued for deletion 30 days after the collection deadlineShort recovery without indefinite storage
Active and completed project metadataRecipient, occasion, prompt, contributor, consent, status, and project-history records remain while the organizer account is active, including after hosted audio expires. A project deletion immediately replaces the main personal project and contributor fields and revokes private links. A second retention pass removes or redacts remaining project content 30 days after the completed deletion, once physical media cleanup is confirmed. Versioned consent evidence may remain linked to the organizer account until account deletion.Library history, support, deletion evidence, and order delivery
Organizer account and profileWhile the account is active, then deleted on account deletion except for required recordsSign-in, library, and account support
Essential email delivery recordsRecipient address, subject, body, provider message identifier, and last error are purged 30 days after a message reaches a terminal sent or failed state. This clears the delivery outbox copy; it does not delete the separate immutable order confirmation and purchase-consent evidence described below. A minimal notification type, status, attempt count, and timestamps remain with the related account until account deletion. The email provider may keep its own delivery records under its documented retention rules.Deliver essential links and hosted-expiry reminders
Security and diagnostic logsApplication operational events are deleted after 30 days; security events are deleted after 90 days. Infrastructure providers may retain their own access or security logs under separately configured provider periods.Protect and troubleshoot the service
Payment and webhook integrity recordsOrder, transaction and customer references, purchaser email, amount, currency, status, consent versions and hashes, the immutable confirmation snapshot, event identifiers and timestamps are not governed by the 30- or 90-day audio periods. After account deletion, the payment ledger, purchase-consent evidence, and immutable order-confirmation evidence remain disconnected from the deleted local account and project but can still contain finite identifying information needed for payment reconciliation, tax, accounting, fraud prevention, disputes, consumer rights, and legal obligations. Production deletes eligible evidence in bounded batches only after the legally reviewed payment evidence period has elapsed from both its latest update and latest provider event. Evidence remains longer while a live order, pending refund, active confirmation delivery, legal hold, dispute, or binding legal requirement applies. Processed Paddle webhook integrity records use a separate configured period.Reconciliation and legal obligations

The 30- and 90-day periods above apply to audio and abandoned-project cleanup, not to every account, support, security, or transaction record. Those other records use the separate purpose-based criteria stated in the table.

Deletion is asynchronous and failed cleanup attempts are retried. Provider backups may persist for a limited recovery cycle before being overwritten. We may preserve information subject to a legal hold, active dispute, or binding legal requirement, and delete or de-identify it when that exception ends.

6. Cookies and browser storage

We use an essential session cookie for secure sign-in and browser storage for create-flow and checkout recovery. Create-flow recovery does not contain a recipient's or project subject's full date of birth. We do not currently use advertising or optional analytics cookies. The Cookie notice identifies each category, purpose, duration, and available control.

7. Your controls

A contributor receives a separate private removal link. Removing a voice before final render removes it from the project. Removing it later revokes the hosted version and queues a clean rebuild without that chapter where technically possible. A downloaded copy on another person's device cannot be remotely recalled.

Organizers can delete a project or permanently delete their account from the Account page. If payment confirmation is in progress, account or project deletion may be delayed briefly and can be retried after the transaction settles. A completed project deletion revokes that project's private links, redacts its personal project and contributor details, and queues associated audio for deletion. A completed account deletion also signs out sessions, deletes the local account, and removes the remaining project records. Necessary payment-ledger, purchase-consent, and immutable order-confirmation records may remain as described above. They are disconnected from the local account and project but include limited purchaser and transaction identifiers and may remain linkable to Paddle's transaction records until the configured retention period ends or a legal hold is released; they are not described as anonymous.

8. Privacy rights

Depending on where you live, you may have rights to know or access your information, receive a portable copy, correct it, delete it, restrict or object to processing, withdraw consent, and appeal a decision. You may also complain to your local privacy regulator. We do not discriminate against anyone for exercising a privacy right.

We do not sell personal information or share it for cross-context behavioral advertising, so there is no sale or targeted-advertising opt-out to exercise. We do not use solely automated decisions that produce legal or similarly significant effects.

Submit a request through Contact us. We may need to verify your identity or possession of the relevant private link. An authorized agent may submit a request where local law allows. We respond within the period required by applicable law.

9. Security and changes

We use administrative, technical, and organizational safeguards designed for the sensitivity of private voice content, including encrypted transport, restricted service access, role-specific random links, file validation, rate limits, and signature-verified payment events. No system is completely secure, so keep private links secret and contact us if one may have been exposed.

The service is exclusively for adult organizers, contributors, recipients, project subjects, and intended listeners. We do not knowingly permit a minor to create, contribute to, be the subject or recipient of, or access a project, and users must not submit any minor's personal information. We may update this notice when our service or legal obligations change. Material changes will be posted here and, where appropriate, communicated directly. The effective date above identifies the version in force.