SECURITY
Protection built around family life
Family schedules, routines and photos deserve careful protection. Kinalumi uses layered controls across the app, devices, database and private file storage.
Last updated 26 August 2026Kinalumi is still in development. Security controls are reviewed throughout testing, before each store release and when the service architecture changes. We do not claim that any connected service can be completely risk-free.
Household isolation and server-side permissions
Every household-scoped request is checked against the signed-in member and their role. Database row-level security and server-side functions enforce household boundaries independently of the mobile interface. Parent-only actions, child visibility and carer access are checked again when data is read or changed.
Authentication and device protection
Adult accounts use Supabase authentication with secure session renewal. Refresh tokens, device keys, biometric preferences and household PIN material are kept in protected device storage rather than ordinary app storage. Sessions and registered devices can be reviewed or revoked.
Private media and safe uploads
Chore proof, family noticeboard media, task attachments, school documents and other family files use private storage. Uploads are restricted by type, size and household path. Where photos are prepared by the app, they are re-encoded to reduce retained source metadata. Access links are short-lived rather than permanently public.
Offline information
Only an allowlisted subset of recently used family information is kept for offline access. Those snapshots are encrypted on the device, tied to the signed-in account and removed on explicit sign-out. Sensitive categories such as private media links, proof photos and Kid Mode tokens are excluded from the offline snapshot.
Administrative access and auditability
Application-owner administration is separated from household views and does not display private family schedules or child profiles. Important administrative and household changes create audit records. Operational access is limited to authorised people who need it for security, support or service operation.
Monitoring, updates and incident handling
Kinalumi uses operational diagnostics to identify failures and suspicious activity, applies dependency and platform updates, and reviews security-sensitive changes before release. If a confirmed incident is likely to create a material risk, affected people and regulators will be notified as required by applicable law.
Report a security concern
Email security@kinalumi.com with a clear description, the affected page or feature and safe steps to reproduce the issue. Do not access another family’s data, disrupt the service, use automated high-volume testing or include real child information in a report. We will acknowledge genuine reports and work with the reporter on a responsible resolution.
For account access or general assistance, use Kinalumi Support. Do not send passwords, family PINs or payment details by email.