Privacy Policy
Last updated: April 2026
The short version
Your studio owns its member data. We never sell it, and we never use it to train AI models. You can export everything Kyndra holds at any time. When an account closes we delete its records within 30 days, apart from billing records we have to keep for seven years. This summary is written for humans and does not replace the sections below, which are the ones that bind us.
Kyndra ("we," "our," or "us") operates the Kyndra platform, a studio management SaaS for salons, beauty, pilates, yoga, dance, fitness, wellness, and hybrid studios. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
1. Information We Collect
Account Information
Student & Family Data
Usage Data
Payment Data
2. How We Use Information
- Provide, maintain, and improve the Kyndra platform
- Process subscriptions and billing through Stripe
- Send transactional emails (account verification, billing receipts, class reminders)
- Power AI features such as studio insights and recommendations
- Analyze usage patterns to improve functionality and user experience
- Respond to support requests and communicate about your account
- Enforce our Terms of Service and protect against fraud
3. Data Sharing
We do not sell your personal information. We share data only with the sub-processors listed below as necessary to operate the platform. Each entry names the service, the data it receives, and the primary hosting region. Studio owners signing a Data Processing Addendum (DPA) receive this list incorporated by reference and are notified at least thirty (30) days before any sub-processor change.
We may also disclose information if required by law, to protect our rights, or in connection with a merger or acquisition.
4. AI Features and Your Data
Kyndra uses AI providers (Anthropic and OpenAI) for select features: the optional Copilot chat surface, automated insights generation, and tool-grounded chat. AI-feature inference is governed by each provider’s data-retention policy:
- Your data is never used to train models. Both providers’ API terms exclude API customer inputs and outputs from model training by default; we do not opt in to any training program on your studio’s behalf.
- Providers honor their published retention windows. Requests are processed transiently and discarded per the provider’s posted policy.
- We send the minimum data necessary. Student names, birthdates, and medical notes are redacted before any AI call; only aggregated counts and structural data (class schedules, enrollment totals, attendance rates) are sent.
- Specific AI features can be enabled or disabled by Kyndra at the platform level. Per-studio AI controls are on the product roadmap for a future release. Until then, contact [email protected] if you require AI features fully disabled on your account.
5. Security Practices
- Encryption in transitAll traffic to and from Kyndra uses TLS 1.2 or higher. HSTS is enforced. HTTP is not accepted.
- Encryption at restDatabase records and object storage use AES-256 encryption at rest through our hosting providers (Supabase and Zeabur).
- Access controlsRow-level security is enforced at the database layer: a studio’s data is only readable by members of that studio. Optional two-factor authentication (TOTP) is available for every account.
- Payment dataCard numbers never touch our servers. Stripe handles all payment data under PCI DSS Level 1 compliance.
- Audit loggingDestructive actions and admin operations are written to an immutable audit log available to studio owners.
- Vulnerability reportingReport suspected vulnerabilities to [email protected]. We commit to acknowledging reports within 2 business days.
6. Data Breach Notification
If we become aware of a personal-data breach that is likely to affect your data, we will notify you by email without undue delay and in any event within 72 hoursof discovery, as required by GDPR Article 33. The notification will describe the nature of the breach, the categories of data affected, the likely consequences, and the remediation steps we’re taking. Studio owners are contractually responsible for onward notification to their members where applicable under their local law.
7. International Data Transfers
Kyndra is operated from the United States. If you are located in the European Economic Area, the United Kingdom, or any other region with data-protection laws that differ from those in the US, your personal data is transferred to and processed in the US. We rely on Standard Contractual Clauses (SCCs) and our subprocessors’ SCCs for GDPR-compliant cross-border transfers. A Data Processing Addendum (DPA) is available on request for studio owners acting as data controllers.
8. GDPR — Legal Basis for Processing (EU/UK)
If you are in the EU or UK, we process personal data under the following legal bases:
- Contractto provide the service to studio owners, instructors, and members under our Terms of Service.
- Legitimate intereststo secure the platform, prevent fraud, monitor reliability, and improve functionality — balanced against individual rights.
- Consentfor optional channels such as SMS reminders; opt-in is required and can be withdrawn at any time from Profile → Notifications.
- Legal obligationfor tax, accounting, and anti-money-laundering recordkeeping.
Data controllers for student records are the studio owners. Kyndra acts as a data processor on their behalf. If you are a member and wish to exercise your rights, contact your studio first; if unresolved, contact us and we will coordinate.
9. California Residents (CCPA / CPRA)
California residents have specific rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including:
- Right to knowthe categories and specific pieces of personal information we collect.
- Right to deletepersonal information we hold, subject to legal retention.
- Right to correctinaccurate personal information.
- Right to opt outof the sale or sharing of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising.
- Non-discriminationfor exercising these rights. We will not deny service or raise prices.
To submit a verified consumer request, email [email protected]. We will respond within 45 days.
10. Data Retention
We retain personal data only as long as necessary to provide the service or comply with law. Specific retention periods:
- Account + studio recordsFor the life of the account. Deleted within 30 days of account closure.
- Student + family recordsControlled by the studio. Studios can delete member records at any time from the dashboard; scrubs propagate immediately. Names, emails, phones, medical notes, photos, and signed-document identities are zeroed. A retained shell (family id + invoice/payment history) stays for the 7-year tax window. Members can also self-initiate erasure from their portal.
- Billing records7 years, as required by US tax law. Stripe retains payment records independently under its own retention policy.
- Audit logsKept for the life of the studio account. Kyndra does not age out or delete audit rows automatically; they are removed when the account and its data are deleted.
- Attendance + class photosFor the life of the studio account. Studios can bulk-delete older records from Settings → Data.
- Session replays90 days, per Sentry’s default retention. Session replay is sampled at 1% and fully masked: no text or form input is captured.
- Anonymized analyticsRetained indefinitely in aggregate form; no personal identifiers.
11. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- AccessRequest a copy of the personal data we hold about you.
- CorrectionRequest correction of inaccurate or incomplete data.
- DeletionRequest deletion of your personal data, subject to legal retention requirements.
- PortabilityRequest your data in a structured, machine-readable format.
- Opt-outUnsubscribe from non-essential communications at any time — every promotional email carries a one-click
List-Unsubscribeheader (RFC 8058), honored by Gmail, Apple Mail, and every major mailbox provider. The studio can also flag a family as “do-not-contact” which suppresses every non-transactional email, SMS, and in-app nudge regardless of category preferences.
Self-service
Members can download a JSON export of everything Kyndra holds about their family, or request account deletion, directly from Portal → Profile → Your data. Studio owners can fulfill access and erasure requests from Dashboard → Families → (select family) → Data rights. Erasure scrubs name, email, phone, photos, medical notes, and signed-document identities; it retains financial shells (invoices, payment records) for 7 years as tax law requires.
For anything those surfaces can’t handle, or if you need a verified identity check, email [email protected]. We respond within 30 days.
12. Children's Privacy
Kyndra is designed for use by studio owners, instructors, and parents/guardians. Many studios serve children under 13. In compliance with COPPA (Children's Online Privacy Protection Act), we do not knowingly collect personal information directly from children. Student records, including names and dates of birth, are entered and managed by studio owners and parents/guardians, who act as the data controllers for their students.
Verifiable parental consent
Parent rights
14. Contact
If you have questions about this Privacy Policy or our data practices, contact us at:
This privacy policy is effective as of April 2026. We may update this policy from time to time. Changes will be posted on this page with an updated revision date.