Privacy
Privacy statement
Last updated: 22 July 2026
This statement is written in plain language so families, care subjects, supporters and professionals can understand how Kinovo handles information.
The short version
Kinovo uses information to provide and protect private care-team workspaces. Access depends on current membership, permissions and item visibility.
Your choices and rights
You can update profile information, choose visibility, export available data and ask for access, correction or help with a privacy complaint.
1. Who this privacy statement is for
This privacy statement explains how Kinovo handles personal information for people who visit the website, join the early access list, contact support, create an account or use a Kinovo care-team workspace.
Kinovo is operated in Australia. You can request the operator's current legal and contact details through privacy@kinovo.com.au.
Kinovo is designed as a private care-team coordination workspace. It is not a medical record, clinical treatment system, payroll system or plan-management system.
2. The kinds of information we collect
Website and early access information can include your name, email address, role or interest type, organisation details, feedback and the coordination problems you choose to describe.
Account information can include your name, email address, phone number, profile details, professional role, organisation or business name, profile photo and app preferences.
Care-team workspace information can include participant or care-subject details, family and supporter details, team roles, care protocols, goals, tasks, messages, updates, comments, document metadata, uploaded files and activity history.
Support information can include the support request you submit, your email address, the page you were on, workspace context you choose to include and technical details that help diagnose the issue.
Some information in a workspace may be sensitive, including disability, health, support, safety, routine, communication, therapy, NDIS or care-related information. Users should only add information they are authorised to share with that care team.
3. How we collect information
We collect information directly from you when you submit a form, create an account, accept an invite, upload a document, send a message, create a task, update a profile or contact support.
Other invited members of a care team may add information about the care subject, team members, goals, documents, protocols or tasks. Team leaders control who is invited into a workspace.
We may collect basic technical information such as pages visited, browser details, device information, IP-related logs and error information to operate, secure and improve the service.
Kinovo's current product analytics use a fixed first-party event catalogue and authoritative workspace records. Analytics events do not include names, emails, care content, task descriptions, document titles or filenames, messages, protocol instructions or other free-text care information.
4. Why we use information
We use personal information to provide the Kinovo workspace, manage accounts and invites, show the right care-team information to the right users, send notifications, deliver support, improve the product and maintain security.
We use early access and website information to respond to enquiries, invite people into research or alpha testing, send occasional product updates and understand whether Kinovo is solving the right care coordination problems.
We use support request information to investigate the issue, reply to the person who contacted us and keep a record of support activity.
Kinovo does not sell personal information or use care-team information for advertising. The current product does not use care-team content to train AI models.
5. Who information may be shared with
Care-team workspace information is shared with the invited members of that workspace according to their role, permissions and item visibility settings.
We may use service providers to operate Kinovo, including hosting, database, file storage, authentication, email delivery, logging, analytics and support tooling. These providers only receive information needed to provide their service to Kinovo.
We do not sell personal information. We do not make care-team workspace information public.
We may disclose information if required by law, to protect security, to investigate misuse or with your consent.
6. Overseas service providers
Some service providers used to operate Kinovo may process or store information outside Australia. This may include infrastructure, authentication, email, analytics, logging or support providers.
Current core providers include Supabase for database, authentication and private file storage; Render for application hosting; Resend for application email; and Cloudflare Turnstile for bot protection. Provider locations and subprocessors can change, so Kinovo reviews this list and its contracts periodically.
Where we use overseas or cloud service providers, we aim to use reputable providers, limit the information sent to what the service requires and configure access so information is available only to authorised people and systems.
7. Security and confidentiality
Kinovo uses invite-based access, role-based permissions, authentication, database Row Level Security, private file access controls and application-level safeguards to protect workspace information. Normal application traffic uses HTTPS.
No online service can guarantee absolute security. Users should use strong passwords, keep account access secure and avoid adding information that does not need to be shared with the care team.
Invited users may be asked to accept a confidentiality agreement before opening a care-team workspace.
8. Accessing or correcting information
You can update some account and profile information inside Kinovo. Team leaders can update care-team details and manage access for their workspace.
You can export your account data from Settings → Account and data. Team leaders can also export an authorised care workspace before archiving or deletion.
You can ask us to help access or correct personal information we hold by contacting privacy@kinovo.com.au. We may need to confirm your identity and check workspace permissions before making changes.
9. Retention and deletion
Removing a member or leaving a care team ends access to that workspace but does not delete the person's Kinovo account. Shared messages, task activity, comments, documents and completed work remain in the workspace history.
Archived documents and workspaces remain available to authorised people in read-only form and can be restored. Deleting a document, closing an account or deleting a workspace ends normal access immediately and uses a 30-day cancellation period before verified live-data purge.
After account closure, private account information is removed or de-identified while shared care-team history keeps a neutral former-member attribution. Identifiable raw analytics are retained for 90 days, de-identified aggregates for up to 730 days, and minimal completed lifecycle audits for 730 days.
Deleted information may remain beyond ordinary use in encrypted or managed disaster-recovery backups until those backups age out under the provider's configured lifecycle. If a restore reintroduces previously deleted data, Kinovo must reapply the deletion before normal service resumes.
An owner support administrator may pause deletion only for a verified legal or security reason, with an audit record. For an urgent privacy request, contact privacy@kinovo.com.au without attaching the sensitive content itself.
10. Complaints and questions
If you have a privacy question, access request, correction request or complaint, contact privacy@kinovo.com.au and include enough detail for us to understand the issue.
We will acknowledge a privacy complaint and aim to provide a substantive response within 30 days. More complex requests may take longer; if so, we will explain the reason and next step.
If a complaint is not resolved, you may have the right to contact the Office of the Australian Information Commissioner at oaic.gov.au.