Skip to main content

Privacy Policy

Last updated: April 2026

The short version

Your studio owns its member data. We never sell it, and we never use it to train AI models. You can export everything Kyndra holds at any time. When an account closes we delete its records within 30 days, apart from billing records we have to keep for seven years. This summary is written for humans and does not replace the sections below, which are the ones that bind us.

Kyndra ("we," "our," or "us") operates the Kyndra platform, a studio management SaaS for salons, beauty, pilates, yoga, dance, fitness, wellness, and hybrid studios. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

1. Information We Collect

Account Information

When you create an account, we collect your name, email address, and studio details (studio name, type, address). Instructors and staff accounts include name, email, and role information.

Student & Family Data

Studio owners and instructors may enter student information including names, dates of birth, contact details, emergency contacts, and medical notes. This data is entered and controlled by the studio owner.

Usage Data

We automatically collect information about how you interact with the platform, including pages visited, features used, timestamps, device type, browser, and IP address.

Payment Data

Payment processing is handled entirely by Stripe. We do not store credit card numbers or sensitive payment credentials on our servers. We retain Stripe customer IDs and subscription status for billing management.

2. How We Use Information

  • Provide, maintain, and improve the Kyndra platform
  • Process subscriptions and billing through Stripe
  • Send transactional emails (account verification, billing receipts, class reminders)
  • Power AI features such as studio insights and recommendations
  • Analyze usage patterns to improve functionality and user experience
  • Respond to support requests and communicate about your account
  • Enforce our Terms of Service and protect against fraud

3. Data Sharing

We do not sell your personal information. We share data only with the sub-processors listed below as necessary to operate the platform. Each entry names the service, the data it receives, and the primary hosting region. Studio owners signing a Data Processing Addendum (DPA) receive this list incorporated by reference and are notified at least thirty (30) days before any sub-processor change.

Supabase Inc.
Database, authentication, and object storage for all application data. Hosted US-East-1. Supabase DPA.
Stripe, Inc.
Payment processing and Connect-account custody of member card data. Card numbers and bank credentials never touch Kyndra servers; they remain in Stripe’s PCI DSS Level 1 environment. Global processing footprint with primary US region. Stripe DPA.
Zeabur
Application hosting. Operates the servers that run the Kyndra application; request logs may contain IP addresses. Hosted in the United States. Contact: [email protected].
Resend
Transactional and notification email delivery. Receives recipient email addresses and message content. Hosted in the United States. Resend DPA.
Knock Labs, Inc.
Notification orchestration across email, SMS, and in-app channels. Receives recipient email/phone and notification content. Hosted in the United States. Knock DPA.
Twilio Inc.
SMS delivery when a studio enables text reminders. Receives recipient phone numbers and message content. Opt-in only; members can opt out at any time from Profile → Notifications. Hosted in the United States. Twilio DPA.
OpenRouter, Inc.
AI routing layer for the in-product agent surface. Routes redacted prompts to the upstream model (Anthropic or OpenAI per routing tier). Hosted in the United States. Contact: [email protected].
OpenAI, L.L.C.
Upstream AI provider (gpt-4o-mini) for triage and selected insights. Receives redacted prompts only; student names, birthdates, and medical notes are stripped before any call. API customer inputs are excluded from training by default. Hosted in the United States. OpenAI DPA.
Anthropic, PBC
Upstream AI provider (Claude Haiku family) for the default agent surface, accessed via OpenRouter. Same redaction rules as OpenAI above; API inputs excluded from training. Anthropic DPA.
Functional Software, Inc. (Sentry)
Error tracking and application monitoring. Receives error messages, stack traces, and limited request metadata. PII redaction is enabled; we do not send request bodies, and session replay (sampled at 1%) masks all text and form input. Hosted in the United States. Sentry DPA.
PostHog Inc.
Product analytics. Receives anonymised event-level usage data tied to a randomised distinct ID; we do not send member names or contact details. Hosted in the United States (EU region available on request). PostHog DPA.

We may also disclose information if required by law, to protect our rights, or in connection with a merger or acquisition.

4. AI Features and Your Data

Kyndra uses AI providers (Anthropic and OpenAI) for select features: the optional Copilot chat surface, automated insights generation, and tool-grounded chat. AI-feature inference is governed by each provider’s data-retention policy:

  • Your data is never used to train models. Both providers’ API terms exclude API customer inputs and outputs from model training by default; we do not opt in to any training program on your studio’s behalf.
  • Providers honor their published retention windows. Requests are processed transiently and discarded per the provider’s posted policy.
  • We send the minimum data necessary. Student names, birthdates, and medical notes are redacted before any AI call; only aggregated counts and structural data (class schedules, enrollment totals, attendance rates) are sent.
  • Specific AI features can be enabled or disabled by Kyndra at the platform level. Per-studio AI controls are on the product roadmap for a future release. Until then, contact [email protected] if you require AI features fully disabled on your account.

5. Security Practices

  • Encryption in transitAll traffic to and from Kyndra uses TLS 1.2 or higher. HSTS is enforced. HTTP is not accepted.
  • Encryption at restDatabase records and object storage use AES-256 encryption at rest through our hosting providers (Supabase and Zeabur).
  • Access controlsRow-level security is enforced at the database layer: a studio’s data is only readable by members of that studio. Optional two-factor authentication (TOTP) is available for every account.
  • Payment dataCard numbers never touch our servers. Stripe handles all payment data under PCI DSS Level 1 compliance.
  • Audit loggingDestructive actions and admin operations are written to an immutable audit log available to studio owners.
  • Vulnerability reportingReport suspected vulnerabilities to [email protected]. We commit to acknowledging reports within 2 business days.

6. Data Breach Notification

If we become aware of a personal-data breach that is likely to affect your data, we will notify you by email without undue delay and in any event within 72 hoursof discovery, as required by GDPR Article 33. The notification will describe the nature of the breach, the categories of data affected, the likely consequences, and the remediation steps we’re taking. Studio owners are contractually responsible for onward notification to their members where applicable under their local law.

7. International Data Transfers

Kyndra is operated from the United States. If you are located in the European Economic Area, the United Kingdom, or any other region with data-protection laws that differ from those in the US, your personal data is transferred to and processed in the US. We rely on Standard Contractual Clauses (SCCs) and our subprocessors’ SCCs for GDPR-compliant cross-border transfers. A Data Processing Addendum (DPA) is available on request for studio owners acting as data controllers.

8. GDPR — Legal Basis for Processing (EU/UK)

If you are in the EU or UK, we process personal data under the following legal bases:

  • Contractto provide the service to studio owners, instructors, and members under our Terms of Service.
  • Legitimate intereststo secure the platform, prevent fraud, monitor reliability, and improve functionality — balanced against individual rights.
  • Consentfor optional channels such as SMS reminders; opt-in is required and can be withdrawn at any time from Profile → Notifications.
  • Legal obligationfor tax, accounting, and anti-money-laundering recordkeeping.

Data controllers for student records are the studio owners. Kyndra acts as a data processor on their behalf. If you are a member and wish to exercise your rights, contact your studio first; if unresolved, contact us and we will coordinate.

9. California Residents (CCPA / CPRA)

California residents have specific rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including:

  • Right to knowthe categories and specific pieces of personal information we collect.
  • Right to deletepersonal information we hold, subject to legal retention.
  • Right to correctinaccurate personal information.
  • Right to opt outof the sale or sharing of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising.
  • Non-discriminationfor exercising these rights. We will not deny service or raise prices.

To submit a verified consumer request, email [email protected]. We will respond within 45 days.

10. Data Retention

We retain personal data only as long as necessary to provide the service or comply with law. Specific retention periods:

  • Account + studio recordsFor the life of the account. Deleted within 30 days of account closure.
  • Student + family recordsControlled by the studio. Studios can delete member records at any time from the dashboard; scrubs propagate immediately. Names, emails, phones, medical notes, photos, and signed-document identities are zeroed. A retained shell (family id + invoice/payment history) stays for the 7-year tax window. Members can also self-initiate erasure from their portal.
  • Billing records7 years, as required by US tax law. Stripe retains payment records independently under its own retention policy.
  • Audit logsKept for the life of the studio account. Kyndra does not age out or delete audit rows automatically; they are removed when the account and its data are deleted.
  • Attendance + class photosFor the life of the studio account. Studios can bulk-delete older records from Settings → Data.
  • Session replays90 days, per Sentry’s default retention. Session replay is sampled at 1% and fully masked: no text or form input is captured.
  • Anonymized analyticsRetained indefinitely in aggregate form; no personal identifiers.

11. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • AccessRequest a copy of the personal data we hold about you.
  • CorrectionRequest correction of inaccurate or incomplete data.
  • DeletionRequest deletion of your personal data, subject to legal retention requirements.
  • PortabilityRequest your data in a structured, machine-readable format.
  • Opt-outUnsubscribe from non-essential communications at any time — every promotional email carries a one-click List-Unsubscribe header (RFC 8058), honored by Gmail, Apple Mail, and every major mailbox provider. The studio can also flag a family as “do-not-contact” which suppresses every non-transactional email, SMS, and in-app nudge regardless of category preferences.

Self-service

Members can download a JSON export of everything Kyndra holds about their family, or request account deletion, directly from Portal → Profile → Your data. Studio owners can fulfill access and erasure requests from Dashboard → Families → (select family) → Data rights. Erasure scrubs name, email, phone, photos, medical notes, and signed-document identities; it retains financial shells (invoices, payment records) for 7 years as tax law requires.

For anything those surfaces can’t handle, or if you need a verified identity check, email [email protected]. We respond within 30 days.

12. Children's Privacy

Kyndra is designed for use by studio owners, instructors, and parents/guardians. Many studios serve children under 13. In compliance with COPPA (Children's Online Privacy Protection Act), we do not knowingly collect personal information directly from children. Student records, including names and dates of birth, are entered and managed by studio owners and parents/guardians, who act as the data controllers for their students.

Verifiable parental consent

Before any under-13 student record is created or enrolled through Kyndra, we capture the parent/guardian’s consent via either: (a) a direct assertion from the parent filling out the portal enrollment form, with their name, IP address, and timestamp recorded as an audit trail, or (b) the studio owner’s attested consent under COPPA’s “internal-use” carve-out, where the owner vouches that they obtained consent off-platform (intake paperwork, verbal at drop-off). The attesting owner’s identity and timestamp are recorded. No attendance, photo, or medical-note write is permitted against an under-13 student without a consent row.

Parent rights

Parents and guardians may review, correct, or delete their child's records at any time via the studio’s member portal (Profile → Your data) or by contacting their studio. They may also contact [email protected] directly to escalate, revoke consent, or remove the studio’s ability to collect further data from their child.

13. Cookies

We use essential cookies to maintain your session and authentication state. We also use a performance cookie to cache studio status and reduce database queries. We do not use third-party advertising or tracking cookies. You can manage cookie preferences through your browser settings, but disabling essential cookies may prevent you from using the platform.

14. Contact

If you have questions about this Privacy Policy or our data practices, contact us at:

[email protected]

This privacy policy is effective as of April 2026. We may update this policy from time to time. Changes will be posted on this page with an updated revision date.