Kynosis
Privacy

Privacy policy

Last updated 9 October 2026

Kynosis keeps your archive so you can find it again. This page says exactly what that involves: what we collect, who helps us process it, how long it stays, and how to take it back.

01

Who is responsible

Kynosis is made and run by Natalia Sirichenko, an individual developer (“we”). She is the controller of the personal data described here. Questions about privacy go to privacy@kynosis.com.

Natalia Sirichenko, 47 Coill Diarmada, Castledermot, Co. Kildare, R14 Y563, Ireland · +353 87 333 1370

02

On Core, your archive stays on your iPhone

On the free Core plan — with or without an account — your saves stay on your iPhone only. We receive nothing about them, apart from the web page previews your phone fetches directly from the sites you save. An account on Core holds only your email, name and plan.

03

With Kynosis Pro (Kynosis Cloud)

Kynosis Pro adds Kynosis Cloud: your archive is stored with us so it syncs between your devices and the web app. Only then do we hold the items below.

04

What we collect

  • Account: your email address, your name if you give it, and an identifier from Sign in with Apple or Google if you use them.
  • Your archive (Pro only): the links, text, notes, images, audio and files you save, and the tags, collections, summaries and answers made from them.
  • Purchases: your plan, the App Store transaction identifier and its expiry date. We never see your card or Apple ID password.
  • Devices: the name of each signed-in device and when it last synced, so you can sign it out.
  • Usage metering: how much of the daily AI allowance you used, so the limit can be enforced.
  • Diagnostics (off by default): if you turn on “Share diagnostics”, crash, hang and performance reports from Apple’s MetricKit, with the app version and device model — never the content of your saves.
  • Support: what you write to us and anything you attach.
05

Anonymous daily usage report

Once a day the app can send us a short report so we can tell whether Kynosis is working for people and what it costs to run. It is built so that it cannot point to you. This is the complete example of what is sent:

{
  "v": 1,
  "plan": "pro",
  "app": "1.0.3",
  "os": "27.0",
  "saves": "6-20",
  "images": "1-5",
  "ai_requests": "6-20",
  "ai_quality": "standard",
  "sync": true
}

What it contains: your plan (Core or Pro), the app version and iOS version (only the first two numbers), and ranges for how many things you saved, how many pictures, and how many AI requests you made that day, whether AI is at best, standard or light quality, and whether Kynosis Cloud sync is on. It sends ranges, never exact numbers.

What it never contains: your name, email, account number, device or advertising identifier, IP address, location, links, titles, notes, pictures, tags, search words or anything you wrote or saved. There is no identifier of any kind in it, so we cannot tell two reports from the same person apart, and we cannot link a report to your account.

How we store it: the report is not tied to your sign-in and your address is not saved with it. The server only adds one to a counter for that combination of ranges (for example "pro, 1.0, iOS 27, 6-20 saves": 14 reports today), so individual reports are not kept. Any group of fewer than five reports is shown to us only as "fewer than 5".

Your choice: Settings › Help › Share anonymous usage turns it off at any time, and Offline mode (same place) stops every background call the app makes to Kynosis: feature updates, account refresh, crash reports and this report. Nothing else in the app depends on any of them. The app also shows the exact text it would send today.

06

How we use it

  • On Pro, to run Kynosis Cloud: store your archive, sync it between your devices and the web app, and back it up.
  • To make tags, summaries, transcripts, digests and answers to your questions, when you save something or ask.
  • To send the sign-in and password-reset codes you ask for, and service messages about your account.
  • To verify purchases with Apple and apply your plan.
  • To keep the service safe: rate limits, abuse prevention, and fixing errors.

We do not show ads, we do not track you across other apps or websites, and we do not sell or rent your data. Your archive is never used to train a model of ours.

07

Who processes it for us

We use a small number of providers, each bound by a data-processing agreement and only allowed to use your data to provide their service to us:

  • Railway — application hosting and database.
  • Cloudflare — file storage (R2), DNS and network protection, including the Turnstile check on the web sign-in page.
  • Resend — delivery of sign-in and reset emails.
  • AI model providers — Google (Gemini API) and OpenRouter — only for Kynosis Pro accounts: they receive the text of a save or a question only to return a tag, summary, digest or answer, and receive no account details. OpenRouter passes each request on to the maker of the model it runs — only makers based in the US or the EU (such as OpenAI, Google or Mistral), and only providers that neither keep prompts nor train on them. Nothing a Core account saves is ever sent to an AI provider.
  • Apple — payments, subscriptions and Sign in with Apple. Google — Sign in with Google, if you choose it. The web sign-in page shows Google’s own sign-in button, which your browser loads from Google.

Some of these providers process data outside the European Economic Area. Where they do, the transfer is covered by the European Commission’s Standard Contractual Clauses or an adequacy decision.

08

Legal basis

We process your data to perform our contract with you (running the account and the features you use), to meet legal obligations (for example, tax records of purchases), and in our legitimate interest in keeping the service secure. Diagnostics are sent only with your consent, which you can withdraw in the app at any time.

09

How long we keep it

  • A save you delete stays in Trash for 30 days, then is erased permanently.
  • When Pro ends (cancelled, refunded or a renewal that could not be charged), your cloud copy stays readable for 30 days so you can download it to your iPhone, then it is erased. We email you when it starts and a week before.
  • If you delete your account in the app (You › Account › Delete account), it is closed at once and everything is erased within 30 days.
  • Server logs are kept for up to 30 days. Records of purchases are kept as long as tax law requires.
10

Your rights

You can see, correct, export and delete your data. Export the whole archive as Markdown and JSON from You › Export your archive; delete your account from You › Account. You can also ask us for a copy of your data, to correct or erase it, to restrict or object to processing, or to move it elsewhere — write to privacy@kynosis.com and we will answer within 30 days. If you are in the EU you may also complain to your data-protection authority; in Ireland that is the Data Protection Commission (dataprotection.ie).

11

Cookies and storage in your browser

kynosis.com sets no cookies and loads nothing from other companies. The web app at app.kynosis.com keeps your sign-in in your browser’s storage, and its sign-in page uses Cloudflare Turnstile to tell people from bots, which may set a security cookie. Both are needed for the service to work, so they need no consent; there are no analytics or advertising cookies.

12

Security

Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to the people who run the service and is logged. If a breach ever puts your data at risk, we report it to the Data Protection Commission within 72 hours and tell you without undue delay.

13

Children

Kynosis is not meant for children under 16, and we do not knowingly collect their data. If you believe a child has given us data, write to us and we will delete it.

14

Changes

If we change this policy in a way that matters, we will say so in the app and update the date at the top before the change takes effect.