Privacy Policy

Last updated: 21 May 2026

Kindly (“we”, “us”, “our”) is operated by Jaco Rossouw. This policy explains what data we collect, how we use it, and your rights.

Who we are

Kindly is an end-of-life planning assistant. We are based in South Africa and governed by the Protection of Personal Information Act (POPIA).

Data we collect

Account data (signed-in users only)

  • Name and email address, provided by Google or Apple at sign-in. If you use Sign in with Apple and choose to hide your email, Apple provides us with a private relay address instead of your real email address.
  • A stable unique identifier from your sign-in provider (Google sub or Apple sub), used to recognise you on subsequent sign-ins.
  • If you sign in with Apple: an Apple refresh token, stored solely to fulfil Apple's requirement that we revoke it if you delete your account. We do not use it for any other purpose.

On iOS, sign-in uses Apple's and Google's native APIs rather than a browser redirect. The data collected and stored is identical to the above.

Plan data

  • Your responses to the intake questionnaire (jurisdiction, mode, estate details)
  • Task completion progress

AI chat content

Messages you send to the Ask Kindly assistant and the responses you receive are stored in our database and associated with your plan.

When you use Ask Kindly, your messages and any context from your plan are transmitted to Anthropic for processing. Anthropic processes this content under its own privacy terms (linked below) and does not train on submitted data. We do not use your content to train AI models.

Payment

When you pay for full access, you are directed to PayFast (a registered South African payment processor) to complete the transaction. We do not store your card number or banking details — these are handled exclusively by PayFast. We receive a payment notification confirming a successful transaction, which we use to unlock full access for your account.

Payment records may be retained for up to 7 years as required by South African financial regulations.

Usage and technical data

IP address, browser type, device information, and access logs are collected automatically by our hosting and infrastructure providers (Vercel, Supabase) for security and operational purposes. We do not use analytics, advertising cookies, or tracking pixels.

Third-party services

Your data is transmitted to these services only as necessary to deliver the features described. We do not sell your data.

ServicePurposePrivacy policy
SupabaseDatabase and storagesupabase.com/privacy
AnthropicAI responses (Ask Kindly)anthropic.com/privacy
GoogleSign in with Googlepolicies.google.com/privacy
AppleSign in with Appleapple.com/legal/privacy
VercelHosting and deploymentvercel.com/legal/privacy-policy

Each provider has their own privacy policy governing how they handle data passed to them. We encourage you to review those policies.

Data storage and security

Your data is stored on Supabase, which uses PostgreSQL with row-level security policies that restrict access to your own data only. All data is encrypted in transit using TLS.

No system is perfectly secure. While we take reasonable steps to protect your information, we cannot guarantee absolute security and accept no liability for unauthorised access resulting from events beyond our reasonable control.

We will notify affected users without undue delay if we become aware of a security breach involving their personal information, as required by section 22 of POPIA.

International data transfers

Some of the third-party providers we use to operate Kindly — including Anthropic, Supabase, and Vercel — process data on servers located outside South Africa, primarily in the United States and the European Union. By using Kindly, you consent to your personal data being transferred to and processed in these jurisdictions. We rely on each provider's contractual commitments and applicable safeguards (such as Standard Contractual Clauses and equivalent protections) to ensure that your data continues to be protected to a standard comparable to that required under the Protection of Personal Information Act 4 of 2013 (POPIA).

Data retention

We retain your data for as long as your account exists. If you delete your account, all personal data and plan content is permanently deleted within 30 days. Payment records are retained for up to 7 years as required by South African financial regulations.

Account deletion

You can delete your account at any time at https://kindly.potfiction.com/account/delete. Account deletion is permanent and cannot be undone.

If you signed in with Apple, your Sign in with Apple authorisation will also be revoked via Apple's API at the time of deletion.

If that route is unavailable, email potfiction@gmail.com with the subject “Account deletion request” and we will process it within 30 days.

Your rights (POPIA)

You have the right to:

  • request a copy of the personal data we hold about you;
  • delete your account and all associated data — directly within the app at the account deletion page, or by emailing us;
  • correct inaccurate personal information;
  • object to the processing of your personal information in certain circumstances;
  • withdraw consent to processing (note: this may mean we can no longer provide the service to you);
  • lodge a complaint with the Information Regulator of South Africa if you believe we have not handled your personal information lawfully.

To exercise any of these rights, email potfiction@gmail.com. We will respond within 30 days.

Information Regulator (South Africa)

Website: inforegulator.org.za
Email: complaints.IR@justice.gov.za
Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Information Officer

For the purposes of the Protection of Personal Information Act 4 of 2013 (POPIA), the designated Information Officer for Kindly is Jaco Rossouw. The Information Officer can be contacted at potfiction@gmail.com.

Age

Kindly is intended for users aged 18 and over. We do not knowingly collect data from minors. If you become aware that a child has provided us with personal information, please contact us at potfiction@gmail.com and we will take steps to delete that information.

Cookies

Kindly uses session cookies only, set by NextAuth for authentication. These cookies are necessary for you to stay signed in and are not used for tracking or advertising. We do not use third-party analytics or advertising cookies.

Contact

Questions or concerns about this Privacy Policy? Email potfiction@gmail.com.