Privacy Policy

Effective: July 28, 2026 (previous version: July 6, 2026)

The short version: your focuses and cards live encrypted on your devices — never on our servers. We don't read them, sell them, or mine them, and there is no advertising model here to feed. We keep the minimum needed to run your account, plus one encryption key held only so you can recover that account — and this policy is the complete list.

Where your data lives

On your phone, in an encrypted database — and, if you keep backups on (recommended), as an encrypted file in a folder you choose — on the phone, or in a cloud folder like Drive, OneDrive or Dropbox — written directly by your device. We are never in that path and keep no copy. On Kythli Family, changes travel between your household's devices through our relay as sealed, encrypted payloads that are deleted once delivered. Routine operation never involves anyone at Kythli decrypting your content.

What we store

What we never do

Recovery, honestly

Two different things can go wrong, and they have two different owners. Your account is ours to help with: sign in again, right then, and we release your recovery key so a new phone can pick up where the old one left off. Your data is yours to own: it lives on your devices and in your own backup — we never had a copy to give back. That's the honest trade: we say we don't touch your data, not we can't, and we hold exactly one key, for exactly one purpose.

Why holding that key is safe: restoring takes two things — the key and your backup file. We have the key; your backup lives in your own storage, and we never receive it. So even if everything we hold were taken, it would decrypt nothing. That also means the reverse is true and worth saying plainly: keep a backup. Handing your key back is no help if there's nothing for it to open.

Service providers

A short list, each seeing only what its job requires — none can read your content: Supabase (accounts and sign-in), Google Cloud (our infrastructure: the sync relay and the hardened key store), Stripe (payments), Resend (service email like verification codes), and Google Play (app distribution). If you keep backups in a cloud folder, that’s your account with that provider, under their terms with you — not ours.

Children

Kythli is used by individuals and by households. Accounts are created by adults; children participate only as household members invited and managed by the account's adults, with what they can see controlled by role. We build no profiles of anyone — children included.

This website

Your family's data is private. This website is a website. We measure kythli.com like any business measures its storefront — how many people visited, which pages they read, and which link sent them — using Cloudflare Web Analytics. It sets no cookies, builds no profile of you, and cannot follow you to any other site. There is no advertising network here and no data broker.

What it cannot do is more important: site measurement cannot see into the app, cannot identify you as a Kythli user, and never touches a single card, list or person in your household. Those are separate worlds, and the one that holds your life is encrypted on your phone.

The app stays different, permanently. Kythli itself contains no analytics and no third-party SDKs, and that isn't a current setting — it's the product. The site is also served by Cloudflare, which produces standard operational logs.

Your choices & rights

If something goes wrong

If a security incident affects your information, we will notify you promptly and plainly — what happened, what it touched, and what we're doing about it.

Changes

If this policy changes in a way that matters, we'll say so plainly on this page and, for significant changes, by email — never by silently editing.

Contact

privacy@kythli.com