Your data, your terms
Effective 25 June 2026 · Last updated 25 June 2026
Kinfolder is built to protect your family's most important information. This Privacy Policy explains what personal data we process, why we process it, how we protect it, how long we keep it, and what rights you have. Kinfolder is designed around encryption. Content you place inside your Kinfolder is encrypted before it is stored by us. In normal operation, we store the encrypted folder but cannot read its contents. This Privacy Policy should be read together with our Terms of Service.
This summary is here to make the policy easier to understand. The full Privacy Policy below contains the detailed terms.
Kinfolder is a brand of Web2000 BV, registered in the Netherlands with the Dutch Chamber of Commerce under KvK number 64465284.
For privacy questions, contact us at help@kinfolder.com.
Kinfolder helps you store important family, personal, practical, and emergency information in a secure digital folder.
You may also choose a trusted person who can receive selected information if a release process is triggered.
Your folder content is encrypted.
This means we are designed not to read the documents, notes, wishes, passwords, instructions, or other information you place inside your encrypted folder.
We store the encrypted data needed to provide the service, but not the readable contents of your folder.
We may process information such as:
We cannot normally see the readable contents of your encrypted folder.
This includes your uploaded documents, private notes, wishes, instructions, family information, and other encrypted folder content.
If you invite or configure a trusted person, we process their contact details so we can send invitations, security messages, release messages, or related service communications.
You are responsible for making sure you have a lawful reason to provide their details to Kinfolder.
Payments may be processed by third-party payment providers such as Stripe.
We do not store full card details.
We do not use advertising cookies.
If we use analytics, we aim to use privacy-friendly analytics with minimal or no personal data.
Where consent is legally required, we will ask for it.
Depending on your situation, you may have the right to access, correct, erase, export, restrict, or object to the processing of your personal data.
You can contact us at help@kinfolder.com.
You also have the right to complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or another competent supervisory authority.
Kinfolder is a brand of Web2000 BV, registered in the Netherlands with the Dutch Chamber of Commerce under KvK number 64465284.
For the personal data described in this Privacy Policy, Web2000 BV is generally the data controller.
Contact details:
Web2000 BV / Kinfolder
KvK: 64465284
Registered in: The Netherlands
Email: help@kinfolder.com
This Privacy Policy applies to personal data processed through:
This Privacy Policy does not apply to third-party websites, services, or platforms that have their own privacy policies.
In this Privacy Policy:
Kinfolder is designed so that your Folder Content is encrypted before it is stored by us.
In normal operation:
This is an important part of how Kinfolder protects your privacy.
However, encryption also means that if you lose your passkey, device, recovery method, or other required access method, we may not be able to recover or decrypt your Folder Content.
Even where Folder Content is encrypted, some information may still be processed outside the encrypted folder so the Service can work.
This may include:
We aim to minimise this information and use it only where needed.
We may process the following categories of personal data.
This may include:
This may include encrypted versions of information you add to Kinfolder, such as:
We store this as encrypted data. In normal operation, we cannot read the contents.
This may include:
If you invite or configure a trusted person, we may process:
If you use paid features, we may process:
Payments may be processed by third-party payment providers such as Stripe.
We do not store full card numbers or full payment-card details.
If you contact us, we may process:
Please do not send us sensitive information in support messages unless it is necessary.
We may process limited logs needed to keep the Service secure and reliable, such as:
We may process limited usage information, such as:
Where possible, we use aggregated or privacy-friendly analytics.
Kinfolder may allow you to store information that is sensitive or highly private.
Depending on what you choose to add, your encrypted Folder Content may include information about:
We do not ask you to store sensitive information unless you decide to do so.
Because this information may be highly sensitive, you should carefully decide what to store, who to designate as a trusted person, and what should be released.
In normal operation, this information is stored as encrypted Folder Content that we cannot read.
You may choose to add information about other people to your Kinfolder, such as family members, trusted persons, beneficiaries, advisers, doctors, lawyers, notaries, executors, or emergency contacts.
You are responsible for ensuring that you have a lawful basis or appropriate permission to provide and store personal data about other people where required.
You should not upload information about another person if doing so would be unlawful, unfair, misleading, harmful, or contrary to that person’s rights.
We process personal data only where we have a legal basis under the GDPR.
The GDPR requires personal data to be processed lawfully, fairly, transparently, and on a valid legal basis. It also gives people rights such as access, correction, erasure, restriction, objection, and portability.
| Purpose | Examples | Legal basis |
|---|---|---|
| Create and manage your account | Account creation, login, authentication, account administration | Contract: GDPR Article 6(1)(b) |
| Provide encrypted storage | Store and sync your encrypted folder | Contract: GDPR Article 6(1)(b) |
| Provide trusted-person features | Invite trusted persons, manage release settings, send release communications | Contract: GDPR Article 6(1)(b); legitimate interests: Article 6(1)(f); your instructions |
| Process payments | Subscription status, entitlement, invoices, payment confirmation | Contract: Article 6(1)(b); legal obligation: Article 6(1)(c) |
| Provide support | Respond to questions, troubleshoot, resolve issues | Contract: Article 6(1)(b); legitimate interests: Article 6(1)(f) |
| Keep the Service secure | Authentication logs, abuse prevention, fraud detection, incident response | Legitimate interests: Article 6(1)(f); legal obligation where applicable: Article 6(1)(c) |
| Improve the Service | Aggregated analytics, performance monitoring, error correction | Legitimate interests: Article 6(1)(f) |
| Comply with law | Tax, accounting, legal claims, regulatory obligations | Legal obligation: Article 6(1)(c); legitimate interests: Article 6(1)(f) |
| Send service messages | Security alerts, account notices, release messages, policy updates | Contract: Article 6(1)(b); legitimate interests: Article 6(1)(f) |
| Send marketing, if any | Product updates or newsletters where applicable | Consent: Article 6(1)(a), or legitimate interests where permitted |
The GDPR gives extra protection to certain categories of personal data, such as health information, biometric data, religious or philosophical beliefs, and similar sensitive data.
Kinfolder does not require you to provide special-category data. However, you may choose to store such information inside your encrypted Folder Content.
Where you choose to store special-category data inside your encrypted Folder Content, you are intentionally placing that information in your folder for safekeeping and possible release according to your settings.
Because we cannot normally read encrypted Folder Content, we generally do not know what special-category data you store.
If you configure a trusted-person release, we may process personal data to:
Release may involve processing personal data about you, your trusted person, and possibly other people named in your configuration or support communications.
We may delay, suspend, or refuse release-related processing where reasonably necessary for security, fraud prevention, identity verification, legal compliance, dispute handling, or protection of users and third parties.
We may send you service-related communications, including:
These messages are part of the Service and are generally not marketing.
If we send marketing emails, we will do so only where legally permitted.
You can unsubscribe from marketing emails at any time.
Even if you unsubscribe from marketing, we may still send service-related communications.
We do not use advertising cookies.
We may use cookies or similar technologies that are necessary to:
If we use analytics, we aim to use privacy-friendly analytics with minimal personal data.
Where consent is legally required for cookies or similar technologies, we will ask for your consent before using them.
We use carefully selected third-party service providers to operate Kinfolder.
These may include providers for:
Our processors may process personal data only according to our instructions and under appropriate contractual safeguards.
They are not permitted to use your personal data for their own unrelated purposes.
They cannot read encrypted Folder Content where they only receive encrypted data and do not have the decryption key.
Current key providers may include:
We may update our providers from time to time as the Service develops.
We aim to host encrypted Folder Content and backups in the European Union.
Some service providers may process limited personal data outside the European Economic Area, for example for payment processing, email delivery, support, security, or technical operations.
Where personal data is transferred outside the EEA, we will use appropriate safeguards where required, such as:
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
| Data category | Typical retention |
|---|---|
| Account data | For as long as your account exists, then deleted or anonymised unless retention is required |
| Encrypted Folder Content | For as long as your account/folder exists, then deleted according to our deletion process |
| Trusted-person data | For as long as needed for your release configuration, account operation, security, dispute handling, or legal compliance |
| Payment and invoice data | As required for tax, accounting, fraud prevention, chargebacks, and legal obligations |
| Support communications | As long as needed to handle the request and maintain reasonable business records |
| Security logs | For a limited period needed for security, fraud prevention, investigation, and legal compliance |
| Backups | Retained for a limited backup cycle before being overwritten or deleted |
| Marketing consent records | Until withdrawn, then retained as necessary to respect your choice |
When you delete your account or folder, deletion may not be immediate from backups, logs, audit records, payment records, or systems where retention is required or permitted by law.
Where available, you may export or delete your data through the Service.
Deleting your folder may permanently remove your ability to access the encrypted Folder Content.
Because of encryption, we may not be able to help you recover deleted content, lost keys, lost passkeys, or inaccessible encrypted data.
If data has already been released to a trusted person, deletion from Kinfolder may not delete copies already received, downloaded, stored, printed, forwarded, or otherwise processed by that trusted person.
We use technical and organisational measures designed to protect personal data.
These may include:
No system is completely secure. We cannot guarantee that unauthorised access, disclosure, loss, misuse, or security incidents will never occur.
You are responsible for protecting your own devices, email account, passkeys, recovery methods, and trusted-person settings.
If we become aware of a personal-data breach, we will assess it and take appropriate steps.
Where required by law, we will notify the relevant supervisory authority.
Where required by law, we will also notify affected individuals.
Because Folder Content is designed to be encrypted, a breach involving only encrypted Folder Content may have a different risk profile than a breach involving readable personal data or account metadata.
Depending on your location and the circumstances, you may have the right to:
You can exercise your rights by contacting help@kinfolder.com.
We may need to verify your identity before responding.
We will respond within the timeframe required by applicable law, usually within one month for GDPR requests.
Some rights may be limited, for example where we must keep data for legal reasons, security reasons, fraud prevention, dispute handling, or where we cannot identify or access encrypted Folder Content.
Because Folder Content is encrypted, we may not be able to:
Where you can access your account, you may be able to export, correct, or delete Folder Content yourself using the Service.
If you have a privacy concern, please contact us first at help@kinfolder.com.
You also have the right to complain to a data-protection authority.
In the Netherlands, this is the Autoriteit Persoonsgegevens:
https://autoriteitpersoonsgegevens.nl
You may also contact the supervisory authority in your EU country of residence, place of work, or place of the alleged infringement.
Kinfolder is intended for adults.
You must be at least 18 years old to use Kinfolder.
Kinfolder is not directed at children.
We do not knowingly allow children to create accounts.
If you believe a child has provided personal data to us, please contact us at help@kinfolder.com.
We do not use your encrypted Folder Content for automated decision-making.
We may use automated systems for security, fraud prevention, rate limiting, authentication, spam prevention, payment-risk checks, or abuse detection.
These systems are used to protect users and the Service.
We may update this Privacy Policy from time to time.
If we make material changes, we will take reasonable steps to notify you, such as by email, in-app notice, or website notice.
The updated Privacy Policy will apply from the date stated at the top of the page.
For privacy questions or requests, contact:
Kinfolder / Web2000 BV
KvK: 64465284
Registered in: The Netherlands
Email: help@kinfolder.com
This Privacy Policy will be reviewed by qualified counsel before public launch. It is not legal advice.