Privacy Policy
DRAFT — pending legal review. This text is a working draft and is not final. Version 2026-10-11-draft.
Who we are
BesideKin is operated by BesideKin ([Legal entity name — to be added]). Privacy questions and requests: privacy@besidekin.app.
The short version
- We do not ask for your phone number, location or any health information.
- We ask for your real first and last name when you sign up. It is private: never shown to other members, never shown on your posts (named or anonymous), and never sent to AI tools. Only the BesideKin admin can see it, and only to identify someone for safety or abuse reasons.
- We do ask for an email address. It is private: never shown to other members, never shown next to your posts (named or anonymous), and never sent to AI tools. We use it only to confirm your account, reset your password, and send essential account notices — no newsletters or marketing.
- We do not sell your data, show ads, or track which pages or posts you view.
- During the beta we store the date of your last visit (just the date — not what you looked at) so we can tell whether people come back. This is turned off and the stored dates are deleted after the beta.
- Please don't post health details or anything that identifies you or the person you care for. BesideKin is not designed to store health records.
What we store
- Beta only: the date of your last visit, and whether you came back on your second day and in your first week (yes/no). No page or thread history.
- Account: your pseudonymous username, your real first and last name (private, see below), your email address (and whether it's confirmed), a hashed password (never the password itself), signup date, which version of the Terms you agreed to, and the beta invite code you used (if any).
- What you post: threads, replies, whether you posted anonymously, reports, appeals, blocks and feedback you send.
- Optional profile: a short bio and a profile photo, if you add them. The photo is stored as a small square image with hidden details such as location data removed.
- Optional photos on your posts (up to 4). Each is resized and re-saved with all hidden details (such as location and camera data) removed, checked by OpenAI's image moderation, and shown with the post. On anonymous posts, photos carry nothing that links them to you. Please don't share photos that show faces, names, addresses or medical records. Photos you upload but don't post are deleted after 24 hours, and deleting a post deletes its photos.
- Safety and moderation records: when a post triggered crisis resources or a moderation decision, and automated safety results flagged as uncertain for the admin to look at (scores, categories, urgency and decisions — not extra copies of the text).
- A login cookie that keeps you signed in. No advertising or analytics cookies.
Your email address
- Used for: confirming the address is yours, password-reset links, and essential account notices (for example “your password was changed”).
- Not used for: marketing, newsletters, or matching you with other members. Not shown publicly, to other members, or in anonymous posts. Not sent to AI providers.
- Account emails are delivered through an email service provider, Resend, which processes your address only to deliver them. Links in these emails work once and expire (new-account confirmation: 2 hours; adding an email to an existing account: 24 hours; password reset: 1 hour). We store only a scrambled (hashed) form of each link's code.
- When you sign up, your account isn't created until you confirm your email. Until then we keep a pending signup (your chosen username, email, hashed password, invite code and Terms agreement). If you don't confirm, it is deleted automatically shortly after the link expires.
- The admin does not see email addresses in the moderation or metrics views; they could be accessed in the database if strictly needed (for example, a security issue on your account).
Your real name
- We collect your first and last name at signup.
- It is kept private: never shown to other members, never on public pages or next to your posts (named or anonymous), never sent to AI providers, and never included in emails to other people.
- Only the BesideKin admin can see it, in admin tools, and it is used only to identify someone for safety or abuse reasons (for example, threats or harassment reported to the admin).
Bio and photo (optional)
- If you add a bio or photo, other members can see them next to your username and on your profile. They are never shown on anonymous posts or replies.
- Please leave out health details and anything that identifies you or the person you care for. A real photo of you makes you less anonymous; a picture of something you love works too.
- Before saving, bios are checked by the same automated safety screening as posts (crisis detection and spam/harassment checks), and photos are checked by OpenAI's image moderation (see AI processing). You can remove either at any time, and the admin can remove them.
Anonymous posts
Anonymous posts show as “Anonymous” to other members, and features like blocking and recommendations are built so they never reveal who wrote them. Anonymous posts are still linked to your account in our database so that safety features, moderation and your own access work. Your photo and bio are never shown on anonymous posts. The admin can access the database.
How we use it
- To run the community, show crisis resources, and moderate content.
- “Threads you might find helpful” uses only the topics you post or reply in and recent thread activity.
- Admin metrics are aggregate counts (signups, posts per day, crisis-flag and moderation counts) with no post text or usernames.
AI processing (safety screening and features)
- When switched on, the text of your posts, replies, feedback and bio, your profile photo and post photos (for image moderation only), and, once the private journal is built, journal entries are sent to an AI provider, OpenAI, for automated safety screening (crisis detection and spam/harassment checks) and for features such as thread summaries and reply-draft suggestions.
- Names and emails are removed: we never send your username, real name or email address. The text itself is sent as you wrote it, so please leave out names and other identifying details.
- The AI only classifies text so the app can show resources (988, 911, Adult Protective Services). It does not counsel anyone, and neither the AI nor BesideKin contacts anyone on your behalf.
- Uncertain safety results are listed for the BesideKin admin to look at. This is not a clinical review. A step where a qualified reviewer looks at flagged safety items is planned [scope, reviewer qualifications and timing — pending decision].
- [OpenAI API data-use and retention terms — pending legal review; confirm the current terms before launch.]
- [Placeholder — journal: the journal page, when built, must show this AI disclosure before the first entry is saved.]
Adults only (18+)
BesideKin is only for people 18 or older, and signing up requires confirming that you are. We do not knowingly collect information from anyone under 18. If you believe someone under 18 has an account, please tell us at privacy@besidekin.app and we will delete it.
Retention and deletion
[How long data is kept, how to delete your account and posts, and what happens to anonymous posts on deletion — pending decision and legal review.] Until then, email privacy@besidekin.app to request deletion.
Contact
privacy@besidekin.app. See also the Terms of Use (draft).