Privacy Policy

Last updated 25 July 2026

This policy describes exactly what Kinetix stores about you, why, and what you can do about it. It covers the Kinetix application only.

1.What we collect

Account details. Your name, email address and a password. Passwords are never stored as you typed them — they are hashed with bcrypt, and the original cannot be recovered from what we keep.

Profile details. Anything you choose to add to your profile: a picture, job title, short bio and timezone. All of these are optional.

Your work. The content you create in the product — workspaces, projects, teams, milestones, tasks and their descriptions, due dates and statuses, comments, documents and their contents and tags, and which items you have marked as favourites.

Files you upload. Files attached to tasks and images embedded in documents, together with their filename, type and size, and a record of who uploaded them. Profile, workspace and project pictures are stored in the same way.

Session records. When you sign in we create a session identifier, store it against your account with an expiry date, and set it in a cookie on your browser.

Notifications. Records of events relevant to you, such as a task being assigned to you or its status changing.

2.What we do not collect

We do not run analytics, advertising or third-party tracking scripts. There are no advertising cookies and no tracking pixels. We do not collect your location, your contacts, or data from other sites you visit. We do not sell your data, and we do not share it for anyone else's marketing.

Kinetix does not currently support signing in with Google, GitHub or any other third-party account, so we hold no data from those providers.

3.Why we hold it

  • To give you an account and keep you signed in.
  • To show your work to you and to the people you share a workspace with.
  • To attribute work — so a comment, document or upload shows who created it.
  • To send in-app notifications about work that involves you.
  • To keep the service secure and to investigate abuse.

We do not use your content to train machine learning models, and we do not read it except where strictly necessary to support you or to investigate a security problem.

4.Cookies

Kinetix sets one cookie: a session cookie that keeps you signed in. It is marked httpOnly (so scripts on the page cannot read it), secure (so it is only sent over HTTPS) and sameSite=strict (so it is not sent from other sites). It expires 30 days after you sign in, and is removed when you sign out.

Your light or dark theme preference is kept in your browser's local storage, not in a cookie, and is never sent to us.

5.Who can see your data

People in a workspace can see the work in that workspace. Workspace owners and admins can see and manage content created by its members, including tasks, comments and attachments. Sharing a project with another workspace extends that visibility to members of that workspace.

Documents are narrower: a document is visible to the person who created it and to the collaborators they invite. Files attached to a task or document are visible to anyone who can see that task or document.

Choose carefully what you put into a shared workspace — that is the main way other people come to see your data.

6.Where it is stored

Your data is stored in a PostgreSQL database hosted by Neon (PostgreSQL, US East), and the application runs on Vercel. Uploaded files are stored in that same database rather than with a separate file host. This means your data is processed and stored outside South Africa; by using Kinetix you agree to that transfer.

7.How long we keep it

We keep your content for as long as your account is open. Deleted documents sit in the trash until you remove them permanently. Deleting a task, project or workspace removes the content inside it, including attachments, and that cannot be undone. Expired sessions stop being usable at their expiry date.

When you ask us to delete your account we remove your personal details and the content you own. Content you contributed to a workspace owned by someone else may remain there as part of that team's record.

8.Security

Connections use HTTPS. Passwords are hashed with bcrypt. Session cookies cannot be read by page scripts. Every request to the API checks your session and your membership of the workspace before returning anything, and uploaded files are served with headers that stop them being executed as pages in your browser.

No system is perfectly secure. If we discover a breach affecting your personal data we will tell you and, where required, the relevant regulator.

9.Your rights

You can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct anything inaccurate — most profile details you can edit yourself.
  • Delete your account and personal data.
  • Explain how a particular piece of data is being used.

Email support@kinetix.app and we will respond within a reasonable period. You also have the right to complain to the data protection authority in your country.

10.Children

Kinetix is a tool for work and is not intended for children. Do not create an account if you are not old enough to agree to our terms where you live.

11.Changes to this policy

If what we collect or how we use it changes, we will update this page and the date at the top. Significant changes will be flagged to you before they take effect where we reasonably can.

12.Contact

Questions about privacy, or a request about your data, can go to support@kinetix.app.