Kennect is in testing. This notice will be replaced by Kennect's full Privacy Policy before Kennect launches to the public.

Beta Privacy Notice

Version beta-6 · Effective 2026-09-30

This notice explains, in plain words, what Kennect collects while it is being tested, why, who helps run it, how long it is kept, and what you can do about it. It describes what the app actually does today. Kennect is owned by its founder, Martin Garcia. Questions about your privacy: privacy@kennectapp.com.

What Kennect collects

When you create an account:

  • Your email address, your name, the @username you choose, and your date of birth.
  • Your password — stored only as a scrambled one-way code (a hash), never as the password itself.

If you turn on two-factor sign-in: the secret key your authenticator app shares with Kennect, stored encrypted; your backup codes, stored only as scrambled one-way codes; and a count of wrong codes, used to pause code entry after too many. If you tick “Don't ask for a code on this device”, Kennect keeps a record that the device is trusted until the period you were shown ends. Turning two-factor off deletes the key, the backup codes and every trusted-device record.

When you use Kennect:

  • What you post: posts, comments, polls, pieces of work, and the photos you upload. If you add a place to a post, it is the words you typed — Kennect does not read your device's location.
  • Who you follow, your kennections, the communities you join, who you block, and your settings.
  • Whether you're online and when you were last active, if your settings allow it to be shown. Which friends you've marked as close friends. Requests to follow a private account, and whether you approved or declined them.
  • Who viewed your story, and when — shown only to you, the person who posted it.
  • Show-up check-ins: when you tell Kennect you're somewhere, and who you tagged as being there with you.
  • Which posts you tell Kennect you want to see less of. Kennect also remembers roughly where you left off in your feed, so it can pick back up from there next time.
  • Your messages to other people, and messages you send in a community's group chat.
  • Gifts and K-Coin records. Buying K-Coins and withdrawing money are switched off during testing, so no card or bank details are collected.
  • Reports you file, and any decisions made about your account.
  • Your sign-in sessions: the IP address and device or browser type each one was started from. A session record is deleted a day after the session ends.
  • Kennect Live: what you type in a live room's chat is passed to the people in the room and is not kept as a chat history. If a live room has voice, your audio is passed to the people listening and is never recorded or stored. Live rooms have no video yet.
  • Technical records when something breaks (see “Error reports” below).
  • How you use Kennect, unless you turn it off: which screens you open, how long they take to load, and that you did things like post, message or join a community. Never what you wrote or searched for, and never whose profile you looked at (see “Usage records” below).
  • Request logs: Cloudflare, which runs Kennect's servers, logs each request to Kennect with your IP address, an approximate location worked out from it (city, postal code and map area), your network provider and your browser or app type. Cookie contents are hidden from these logs.

On the phone app, Kennect asks for your photo library only when you choose a picture to upload. It does not use your camera, microphone, contacts or location, and it does not send push notifications.

Why Kennect uses it

  • To run your account and show your posts, messages and connections to the people you choose.
  • To check your age at sign-up (see “Ages” below).
  • To keep Kennect safe: reviewing photos, handling reports, blocking, and preventing abuse such as spam and repeated login attempts.
  • To find and fix problems while Kennect is being tested.

Kennect does not sell your information, does not show ads, and does not share your information for advertising.

Photos are checked by a person

Every photo you upload stays private to you until a person at Kennect has reviewed it. Only then can other people see it. Photo location data (EXIF) is removed from uploads.

Automated tools and AI

Kennect uses AI models run by Cloudflare (Workers AI). They are used in two places:

  • Screening text. Kennect may check the text of posts (whoever they are shared with, not only public ones), comments, display names, and community names and descriptions with an automated safety model. During testing it runs in a test mode: it never hides or removes anything by itself — anything it flags goes to a person. Private messages are never screened by it.
  • Screening photos and videos. An automated model checks uploaded photos and videos for things like nudity, the same test-mode way text is screened: it never removes anything by itself, and a person makes every real decision.
  • Checking uploads against known illegal-content fingerprints. Before a photo or video is ever shown to anyone — including a private message, a story, or a show-up — Kennect checks it against a list of known illegal-content fingerprints (a scrambled code of the file, not the file itself). A match is blocked outright; this check cannot be turned off by any setting.
  • Migo, the AI help assistant. Migo is an AI, not a person. When you ask Migo something, your question, your last few messages in that chat, and your display name are sent to the AI model so it can answer. Kennect does not store your Migo conversation: it records only technical details of each reply, such as how long it took, not the words. When Migo cannot answer a question, Kennect keeps a note that it happened and which help page came closest — without your name or the words you typed — for 30 days, to learn which help pages to write. If Kennect ever keeps those words, this notice will say so first.

Kennect's feed order is worked out by a formula — not by an AI model. It uses how recent a post is and its recent likes, comments, reposts and saves, and it gives a lift to posts from people you follow, people you have recently liked or commented on, communities you are in, and hashtags you use.

Messages

Messages are private between the people in the conversation, but they are not end-to-end encrypted: they are stored on Kennect's servers, and a person at Kennect may read a message that has been reported, to review the report. Deleting a message hides it; the stored copy is not yet erased.

What other people can see

Your profile, name, @username and public posts can be seen by anyone, including people who are not signed in, unless you change who can see your profile in Settings, Privacy. When someone shares a link to a public post, apps like iMessage may show a preview with your name and the first part of the post. Your email address and date of birth are never shown to other people.

Usage records (“Help improve Kennect”)

While Kennect is being tested, it records how the app is used so it can find what is broken or confusing: which screens you open, how long they take to load, and that you made a post, sent a message, joined a community and so on. It never records what you write — not your messages, posts, comments or searches — and never whose profile you opened.

  • Each record is stored with your account (if you are signed in), your age group (13–15, 16–17 or 18 and over — not your date of birth), the country you are in, and whether it came from the website or the phone app. Kennect does not store your IP address with it.
  • It stays in Kennect's own database. It is never sold, never shared with advertisers, and never sent to an outside analytics company. People under 18 are treated the same way.
  • Kennect uses it in totals — for example, how many people finished signing up, or how long a screen takes to open — not to follow one person's activity.
  • Turn it off at any time in Settings, Privacy, “Help improve Kennect”. Kennect also treats your browser's Global Privacy Control setting as turning it off.
  • Deleting your account deletes these records, and “Download your data” includes them.

Cookies

Kennect's website uses cookies only to keep you signed in — including, with two-factor sign-in, a short-lived cookie between your password and your code, and, if you ask for it, one that lets this device skip the code for a while. There are no advertising cookies and no outside tracking scripts. For “Help improve Kennect”, the website keeps a random code in your browser's storage (not a cookie) so it can tell one visit from the next, and the phone app keeps one on your phone; the code says nothing about you and is not sent anywhere but Kennect. The website loads its fonts from Google Fonts, which means Google receives your IP address when a page loads.

Who helps run Kennect

These companies handle information for Kennect so the service can work:

  • Cloudflare — hosts the website and app service, keeps its request logs, stores uploaded photos, and runs the AI models described above.
  • Neon — hosts Kennect's database.
  • Have I Been Pwned — checks whether a new password has appeared in a known data breach. Only the first 5 characters of a scrambled code of the password are sent, never the password.
  • Google Fonts — serves the website's fonts (see “Cookies”).
  • Tekavra Creative — the company building and operating Kennect for its owner during testing. It has access to the systems above and receives a daily summary of errors, which can include account IDs.
  • Apple (TestFlight) and Google (Google Play testing) — if you test the phone app and have agreed on your device to share crash reports and feedback with app developers, Apple or Google passes those to Kennect. That is set on your device, not in Kennect.

Kennect does not send you marketing email or text messages. If you ask to reset a forgotten password, that one email is sent through Brevo, an email delivery company, which receives your email address to deliver it. A payment provider will be added to this list before buying or withdrawing money switches on.

Error reports

When something breaks in the website or the app, it sends Kennect an error report. Emails, passwords, long codes and long numbers are removed from it first. A limited number of reports each day are kept with the account ID of the person who hit the error, so the problem can be traced. These samples are deleted after 90 days; the daily count of errors is kept, without them.

How long Kennect keeps information

  • Sign-in: you are signed out after 24 hours without use, and after 7 days at most. The session record (with its IP address and device) is deleted a day after the session ends.
  • Your account: until you delete it.
  • Two-factor sign-in: the key and backup codes until you turn two-factor off or delete your account; a trusted device until its period ends, you turn two-factor off, or you delete your account.
  • Deleting your account: there is a waiting period of 30 days in which you can change your mind. After that your account is deleted. During testing the final step is carried out by a person rather than automatically.
  • What stays after deletion: messages you sent stay in the other person's conversation with your name removed; comments that others replied to stay without your name; gift and K-Coin records; and reports and safety decisions about an account, which Kennect keeps to protect people and meet legal duties.
  • Photos you uploaded are not yet removed from storage automatically when an account is deleted. Contact us and they will be removed.
  • Request logs (see “What Kennect collects”): 7 days.
  • A data export file you request can be downloaded for 7 days; after that the file is deleted.
  • Error-report samples: see “Error reports”.
  • Usage records: the detailed record described in “Usage records” above is deleted after 90 days. After that, only daily totals that don't identify anyone are kept, for up to 24 months.

Ages

Minimum age: 13. If the date of birth you give is under it, no account is created. People under 16 need a parent or guardian's approval, and that approval step is not built yet — so an account with a birth date under 16 is refused at sign-up, and is signed out and refused at login too, until that approval exists. Age is taken from the date of birth you type in; it is not checked against an ID.

Your choices

  • Change who can see your profile, message you, tag you and more in Settings, Privacy.
  • Block anyone, and report posts, comments, messages, accounts and communities.
  • Turn off usage records in Settings, Privacy, “Help improve Kennect” (see “Usage records”).
  • Turn two-factor sign-in on or off in Settings, Two-factor sign-in. If you lose your phone and your backup codes, Kennect staff can turn it off for you after checking it's really you; Kennect records which staff member did it, when and why, and tells you in your notifications.
  • Download a copy of your information in Settings, Your data.
  • Delete your account in Settings, Delete your account.
  • Ask a question, or ask Kennect to correct or remove information, at privacy@kennectapp.com.

Keeping it safe

Kennect uses encrypted connections (HTTPS), stores passwords only as one-way codes, offers two-factor sign-in, and removes personal details from its error logs. No system is perfectly secure; if something goes wrong that affects your information, Kennect will tell you.

Where

Kennect's test is intended for people in the United States. Kennect's database is stored in the United States, and uploaded photos in Cloudflare's Eastern North America storage region. Cloudflare serves the website and app from its data center nearest to you, so a request can pass through a Cloudflare location outside the United States on its way.

Changes and contact

This notice has a version number and a date at the top. When Kennect changes what it collects or how it uses it, this notice changes first. Before Kennect launches to the public, it will be replaced by Kennect's full Privacy Policy. Contact: privacy@kennectapp.com.

Back to Kennect