Privacy

What we hold, and what we do not.

KIN is a pre-production tool. It holds a production’s working documents and the crew list that goes with them. This page says what that means in specifics, because a policy that could describe any product describes nothing.

Who we are

KIN is operated by Gen.Y Studios. Reach us at privacy@kinstudios.org for anything on this page, including a request to export or delete your data.

What we store about you

Your name and email address, so a call sheet can be addressed to a person and a script page can be watermarked with the name of whoever opened it. Authentication is handled by Clerk; we store the identifier they give us, never a password.

The projects you are a member of and the roles you hold on each. This is what the whole product runs on — every screen is composed from it.

An append-only record of changes you make to a script, schedule, call sheet, budget or approval: what changed, when, and who did it. It is never edited and never deleted, because a production needs to be able to answer who moved a scene.

What you put in

Scripts, schedules, call sheets, shot lists, lighting plots, boards, and any file you upload. This is your production’s material, not ours. We store it so the tool works, and we do not read it, mine it, sell it, or train anything on it.

Scripts are held in private storage and served through short-lived signed links rather than public URLs. The original file you imported is retained as the source of truth for revisions.

Who can see it

Other members of the same production, according to the role they hold. Permissions are enforced on the server for every query — see Security for the mechanisms. Actors are deny-by-default: an actor sees a scene only when it has been granted to them.

Nobody outside your production sees your material. We do not sell data, and we do not share it with advertisers — there are none.

The notepad

The notepad in the corner of every project screen is yours alone. It is never stored on our servers and there is no table for it. What you type stays in your own browser, in that tab, and disappears when the tab closes.

The one exception is the moment you press End session. Then the text is sent to us, turned into a PDF, emailed to your own address, and discarded — we keep neither the text nor the PDF. It can only ever be sent to the address on your own account; the option to send it somewhere else does not exist.

Google Calendar, if you connect it

Connecting Google Calendar is optional and off unless you turn it on. If you do, KIN requests a single narrow permission: calendar.app.created, which allows an application to create a secondary calendar and manage only the events it put there.

That means KIN creates a calendar of its own in your Google account and writes your shoot days into it. It cannot read, change or delete anything already in your Google Calendar — not your existing events, not your other calendars. We chose the narrowest scope that does the job rather than a broader one that would have been easier to build against.

The data flows one way: out of KIN and into Google. We do not read your availability from Google. We store the access and refresh tokens Google issues so the calendar can stay current, and nothing else from your Google account.

Disconnect at any time from your account settings, or revoke access directly at your Google account permissions. On disconnect we delete the stored tokens. The calendar we created stays in your account and is yours to keep or delete.

KIN’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Email we send

Call sheets and production notices go out by email through Resend, our delivery provider, addressed to the recipient list snapshotted when the sheet was published. They are production correspondence, not marketing. We do not send marketing email.

How long we keep it

For as long as the production keeps it. Delete a project and its material goes with it, except the audit log, which is retained because it exists to answer questions after the fact.

Ask us to delete your personal account and we will remove your name and email. Work you did on a production stays with the production — a call sheet does not un-publish because its author left — but it stops being attached to a named person.

Where it runs

KIN is open source under the AGPL, and a production can self-host it. If you are using someone else’s instance, that operator holds your data and this page describes the hosted service at kinstudios.org only.

Changes to this page

If what we store changes, this page changes with it in the same release. Material changes are announced in-app rather than quietly edited in.