Privacy policy

This policy says what KinAuth collects, why, who else handles it and for how long. It covers this website and the KinAuth service.

Who we are

KinAuth is made and run by VTS Services Inc., Ann Arbor, Michigan, USA (“we”). Write to us at legal@kinauth.com.

Two roles

For this website, and for the people who sign up an organization or speak with us, we decide what is collected and why.

For everything an organization keeps in KinAuth about its own people (its directory, their sign-ins, its applications), we act on that organization’s behalf and on its instructions. The organization decides who is in it and what it is used for. If you sign in to KinAuth through your employer or another organization, ask that organization first about your data; we help it answer.

This website

This website sets no cookies, has no analytics and loads nothing from any other site. Like any web server, ours keeps technical logs, such as the address a request came from and when, to keep the service running and secure. They are kept for up to 90 days.

What the service keeps

  • The directory: names, email addresses, groups, roles and the state of each account, as the organization or its administrators enter them, or as they are read from a directory the organization connects, such as Google Workspace.
  • Credentials: passwords are kept only as an Argon2id hash, which nobody can read back. The secret of an authenticator app is kept encrypted; for passkeys and the KinAuth app, only public keys are kept.
  • Sessions and sign-ins: when someone signs in, the time, the network address and the browser’s description of itself, and which application they signed in to.
  • The audit log: who changed what, and when, so that the organization can see it.
  • The KinAuth app: the public key of each phone, and the token Apple or Google gives the phone for notifications.
  • Email: the address a message goes to and the message, which holds a link and no secret.

What we use it for

Only to provide KinAuth: to sign people in to their organization’s applications, to keep their accounts safe, and to show each organization its own records. We do not sell personal information, we do not share it for advertising, we do not build profiles, and we do not use it to train machine learning models.

Data from Google

When an organization’s administrator connects its Google Workspace, KinAuth reads, with that administrator’s consent and read-only access, the users and groups of that organization’s Google directory. It uses them only to keep the organization’s KinAuth directory in step with Google. The administrator can disconnect at any time, and KinAuth then gives up its access.

KinAuth’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

Who else handles it

  • Amazon Web Services hosts the service, in the United States.
  • Resend delivers the service’s email.
  • Apple and Google deliver notifications to the KinAuth app. A notification says only that a sign-in is waiting; it carries nothing about the sign-in.

Each handles only what its part needs. We may also disclose information when the law requires it.

How long it is kept

  • Sessions, sign-in challenges and other short-lived records are deleted a day after they end.
  • The directory, credentials and the audit log are kept while the organization uses KinAuth.
  • Encrypted backups are kept for up to a year, and can be read only with a key we keep offline.
  • When an organization stops using KinAuth, its data is deleted from the service on request, and leaves the backups as they expire.

Security

How we protect it is described in detail on how KinAuth is built.

Your choices

You may ask to see, correct or delete information about you. If your account belongs to an organization, it decides, and we help it. For anything else, write to us at legal@kinauth.com. We will not treat you differently for asking.

KinAuth is meant for organizations and is not directed at children under 16.

Changes

If this policy changes, we update this page and its date, and tell organizations’ administrators of any change that matters. Last updated: October 7, 2026.