Skip to content

Privacy

Privacy statement

Last updated: 19 August 2026

This statement is written in plain language so families, care subjects, supporters and professionals can understand how Kinovo handles information.

The short version

Kinovo uses information to provide and protect private care-team workspaces. Access depends on current membership, permissions and item visibility.

Your choices and rights

You can update profile information, choose visibility, export available data and ask for access, correction or help with a privacy complaint.

1. Who this privacy statement is for

This privacy statement explains how Kinovo handles personal information for people who visit the website, request optional typed help, subscribe to resources or updates, contact support, create an account or use a Kinovo care-team workspace.

Kinovo is operated in Australia. You can request the operator's current legal and contact details through privacy@kinovo.com.au.

Kinovo is designed as a private care-team coordination workspace. It is not a medical record, clinical treatment system, payroll system or plan-management system.

2. The kinds of information we collect

Website and optional enquiry information can include your name, email address, role or interest type, organisation details, feedback and the coordination problems you choose to describe.

Account information can include your name, email address, phone number, profile details, professional role, organisation or business name, profile photo and app preferences.

Care-team workspace information can include participant or care-subject details, family and supporter details, team roles, care protocols, goals, tasks, messages, updates, comments, document metadata, uploaded files and activity history.

Support information can include the support request you submit, your email address, the page you were on, workspace context you choose to include and technical details that help diagnose the issue.

Some information in a workspace may be sensitive, including disability, health, support, safety, routine, communication, therapy, NDIS or care-related information. Users should only add information they are authorised to share with that care team.

3. How we collect information

We collect information directly from you when you submit a form, create an account, accept an invite, upload a document, send a message, create a task, update a profile or contact support.

Other invited members of a care team may add information about the care subject, team members, goals, documents, protocols or tasks. Team leaders control who is invited into a workspace.

We may collect basic technical information such as pages visited, browser details, device information, IP-related logs and error information to operate, secure and improve the service.

When you visit a Kinovo marketing page, a signed first-party cookie may keep a random journey identifier, recognised campaign tags, the landing page path, the referring website's hostname and first- and last-seen times for up to 90 days. It does not keep the full referring URL, arbitrary query strings, care-team content or participant information.

Kinovo may record allowlisted first-party funnel events such as a marketing page view, stable CTA selection, Starter Pack request or download, optional typed enquiry, confirmed account and first useful workspace milestone. These events do not contain raw IP addresses, browser fingerprints, participant or care-team names, task or message text, health details, document names, form free text or other care content. Measurement failure never blocks the action you chose.

Kinovo's current product analytics use a fixed first-party event catalogue and authoritative workspace records. Analytics events do not include names, emails, care content, task descriptions, document titles or filenames, messages, protocol instructions or other free-text care information.

4. Why we use information

We use personal information to provide the Kinovo workspace, manage accounts and invites, show the right care-team information to the right users, send notifications, deliver support, improve the product and maintain security.

We use website and optional enquiry information to respond to enquiries, offer typed product help, invite people into research or MVP testing, send occasional product updates and understand whether Kinovo is solving the right care coordination problems.

Where you explicitly submit a marketing or resource form, we record the consent wording and version shown, when and where it was submitted, and whether an earlier unsubscribe means no optional email should be sent. Creating an account alone does not subscribe you to marketing.

New Kinovo accounts receive a small, state-aware set of practical setup reminders by default. We recheck whether the relevant setup step is still incomplete before sending, cap the sequence, keep care-team details out of these messages and let you turn the reminders off in Settings at any time. Creating an account does not subscribe you to newsletters, sales campaigns, product updates or research invitations.

For optional resource emails, our email provider may receive your email address, first name, broad role category and the email topics you selected. We do not send your coordination-problem text, participant information or care-team workspace content for marketing. You can unsubscribe without signing in, and optional-email unsubscribe does not stop required account, security or operational messages.

We use support request information to investigate the issue, reply to the person who contacted us and keep a record of support activity.

Kinovo does not sell personal information or use care-team information for advertising. The current product does not use care-team content to train AI models.

5. Who information may be shared with

Care-team workspace information is shared with the invited members of that workspace according to their role, permissions and item visibility settings.

We may use service providers to operate Kinovo, including hosting, database, file storage, authentication, email delivery, logging, analytics and support tooling. These providers only receive information needed to provide their service to Kinovo.

We do not sell personal information. We do not make care-team workspace information public.

We may disclose information if required by law, to protect security, to investigate misuse or with your consent.

6. Overseas service providers

Some service providers used to operate Kinovo may process or store information outside Australia. This may include infrastructure, authentication, email, analytics, logging or support providers.

Current core providers include Supabase for database, authentication and private file storage; Render for application hosting; Resend for application email; and Cloudflare Turnstile for bot protection. Provider locations and subprocessors can change, so Kinovo reviews this list and its contracts periodically.

Where we use overseas or cloud service providers, we aim to use reputable providers, limit the information sent to what the service requires and configure access so information is available only to authorised people and systems.

7. Security and confidentiality

Kinovo uses invite-based access, role-based permissions, authentication, database Row Level Security, private file access controls and application-level safeguards to protect workspace information. Normal application traffic uses HTTPS.

No online service can guarantee absolute security. Users should use strong passwords, keep account access secure and avoid adding information that does not need to be shared with the care team.

Invited users may be asked to accept a confidentiality agreement before opening a care-team workspace.

8. Accessing or correcting information

You can update some account and profile information inside Kinovo. Team leaders can update care-team details and manage access for their workspace.

You can export your account data from Settings → Account and data. Team leaders can also export an authorised care workspace before archiving or deletion.

You can ask us to help access or correct personal information we hold by contacting privacy@kinovo.com.au. We may need to confirm your identity and check workspace permissions before making changes.

9. Retention and deletion

Removing a member or leaving a care team ends access to that workspace but does not delete the person's Kinovo account. Shared messages, task activity, comments, documents and completed work remain in the workspace history.

Archived documents and workspaces remain available to authorised people in read-only form and can be restored. Deleting a document, closing an account or deleting a workspace ends normal access immediately and uses a 30-day cancellation period before verified live-data purge.

After account closure, private account information is removed or de-identified while shared care-team history keeps a neutral former-member attribution. Pseudonymous raw product and acquisition analytics are retained for 90 days, optional enhanced journey events for no more than 30 days, de-identified aggregates for up to 730 days, and minimal completed lifecycle audits for 730 days. Acquisition aggregate dimensions are kept only when at least five journeys share them.

Help improve Kinovo is an optional preference that is initially off. If enabled, Kinovo records content-free navigation and interaction patterns such as controlled step IDs, action categories, device-size buckets, validation reason codes and whether a flow was observed incomplete. It never records care content, form values, names, email addresses, messages, filenames, raw button text or complete URLs. You can turn it off in Settings at any time, which immediately stops new enhanced journey collection and does not affect your access.

The marketing attribution cookie expires no later than 90 days after its first touch. Converted lead, consent and account-acquisition records are retained only for their marketing-consent, attribution and legal-accountability purposes and remain subject to an authorised access, correction or deletion request.

Deleted information may remain beyond ordinary use in encrypted or managed disaster-recovery backups until those backups age out under the provider's configured lifecycle. If a restore reintroduces previously deleted data, Kinovo must reapply the deletion before normal service resumes.

An owner support administrator may pause deletion only for a verified legal or security reason, with an audit record. For an urgent privacy request, contact privacy@kinovo.com.au without attaching the sensitive content itself.

10. Complaints and questions

If you have a privacy question, access request, correction request or complaint, contact privacy@kinovo.com.au and include enough detail for us to understand the issue.

We will acknowledge a privacy complaint and aim to provide a substantive response within 30 days. More complex requests may take longer; if so, we will explain the reason and next step.

If a complaint is not resolved, you may have the right to contact the Office of the Australian Information Commissioner at oaic.gov.au.

For product support, use the support form. For privacy requests, email privacy@kinovo.com.au. Read the Security and Trust Centre for current safeguards and honest limitations.