KINTAG

Privacy notice

Version 2026-09-12c · Effective September 12, 2026

KINTAG is a free service that stores your emergency information and shows the parts you choose when someone scans your tag's QR code. This notice explains what we hold, why, and the control you have. In plain terms: it's your information, almost nothing is public unless you turn it on, and you can take it or erase it at any time.

What we collect

  • To identify your account: your phone number, a PIN and a one-time recovery code (the PIN and recovery code are stored only as irreversible hashes — we can never read them).
  • Emergency and health information you enter: optional name, blood type, allergies, medications, conditions, implants, blood-thinner status, weight, and free-text notes.
  • Your people: up to two emergency contacts and whether you allow a rescuer to message each of them.
  • Your bike and insurance: motorcycle details and insurance details you choose to add.
  • Your email address, which is required. It has two jobs, both about this account and neither about marketing: getting you back in if you lose your PIN, and telling you when something changes the keys to your account — a new PIN, a new recovery code, a change of phone, email or name, a copy of your account downloaded, a new tag code, or your tag paused. It is not shown when someone scans your tag unless you switch that on yourself — it starts off, like every field, and the switch says beside it that this is the address your recovery link goes to. It is encrypted where we store it, and nothing else is ever sent to it — no newsletter, no product mail, nothing.
  • Optional: your date of birth, if you provide it.
  • Scan events: we keep only the time of the most recent opening of your tag, and nothing about who opened it — no IP address, no location, nothing about their phone or browser. There is no history: each opening replaces the last time, so all that exists is one moment per rider.
  • Account activity: when someone signs in as you, and when the keys of your account change — a new PIN, a new recovery code, a change of phone, email or name, a copy of your account downloaded, a new tag code, your tag paused or switched back on. Each entry is what happened and when, and nothing else: no IP address, no location, nothing about your phone or browser. It is there so you can see activity that was not yours; you read it on your account page and it comes with you when you export.

Why we hold it

We process this information solely to provide the emergency-info service you asked for. We ask for your explicit consent to store health information when you sign up, and you can withdraw it at any time by deleting your account.

Your email address is the one exception to that sentence, and it is a narrower one: it exists so you can recover your account and so we can tell you when the keys to it change, and it is used for those two things and nothing else. If you ask for a recovery link, we send you one message with a link that works once and expires in 30 minutes.

What a scan can show

Every field starts private. Nothing about you is shown until you switch it on in your Privacy settings. That is now true of every field we hold, with no exceptions at all. Some of them identify you rather than help treat you — your email address, your date of birth, your weight, your full insurance, policy or member numbers, and your bike's VIN — and those help identity thieves more than they help responders. They are grouped on their own on the Privacy page, with that said plainly beside them, and like everything else they start off. The decision is yours. Until September 12, 2026 it was ours: those fields could not be published at all, whatever you set, and the honest description of that is that we were deciding for you.

We never sell or share it

We do not sell, rent, or share your information for advertising. There are no third-party advertising or analytics trackers on our pages — we set only the cookies strictly needed to keep you signed in, remember your language, and remember whether you chose the light or dark view. The single third-party script in the whole product is the bot check, and it runs on exactly four pages: our contact page, the sign-up page, the sign-in page and the account-recovery page. It sets no cookie. Cloudflare states that it sets no cookie and never uses what it sees to profile you, and that is the right way to read it: the challenge runs in a frame of its own, but the small script that loads it runs in the page like the rest of the page's code. So this is Cloudflare's undertaking about your phone, your email, your name and your PIN — not something the page makes impossible. What Cloudflare does learn is that some visitor loaded one of those four pages. It runs nowhere else, and above all it never runs on the page a rescuer opens when they scan your tag: that page makes no outside request at all.

When you write to us

If you use the contact form, your name, your address and your message are emailed to our inbox. KINTAG is free, so messages are answered as and when we can: it can take a long time, and we promise nothing about when. Nothing is stored on the site: there is no submissions table, so there is nothing to export, erase or leak. The only record a message leaves is a timestamp against a hashed, non-identifying key, kept for one hour so nobody can flood the form.

Five providers are involved, and here they are by name. Vercel runs the application. Supabase hosts the database. Between them they hold everything this notice describes, which is what hosting means — and they hold it in the state we hold it: the sensitive fields are the same ciphertext there that they are everywhere else, and the key that opens them is kept somewhere they are not. Resend delivers the account-recovery link and the account notices described above, so it handles your email address for those messages and nothing else; it never sees your emergency or health information. Cloudflare Turnstile runs the cookie-less bot check on the four pages named above, and learns only that somebody loaded one of them — never a form field, and never anything from your tag. Help Scout is the inbox a contact-form message arrives in, so it holds what you wrote and the address you wrote from. That is the whole list, and not one of them is on the page a rescuer opens when they scan your tag. We described the first two by role rather than by name until September 12, 2026, on the grounds that we were not tied to one. Naming them is the better answer: if we move, that is a change to this notice, rather than something you would have to think to ask about.

How long we keep it

We keep your information for as long as your account exists. When you delete your account, it is erased from our database immediately — the whole record, not a flag that hides it.

Our database is backed up, as any database is, and a deleted account survives in those backups until they roll off. That takes at most 30 days. Backups are never used to bring a deleted account back; if we ever had to restore one after a failure, the deletions are re-applied. And the sensitive fields in a backup are the same ciphertext they are in the database — the key that opens them is kept somewhere the backups are not.

Your rights

These are self-serve — no request or waiting on us. Depending on where you live (for example under the CCPA/CPRA, Washington's My Health My Data Act, Canada's Law 25, Mexico's LFPDPPP, Brazil's LGPD, and similar laws across the Americas) you may have additional rights.

To ask for one of those, write to us through the contact form. We answer within 45 days. If a request is complicated enough to need longer we will tell you inside those 45 days, say why, and take at most another 45.

First we have to know the account is yours, and we can only do that one way. Everything on the list above is self-serve because it sits behind your PIN — that is the check. A message arriving by email carries no PIN, so if you write asking us to hand over or erase an account and we cannot tie the request to that account, we will refuse it. That refusal is protecting you: acting on an unverified email is exactly how somebody else would delete your account or get a copy of it. If you have lost your PIN, the recovery page gets you back in, and once you are in, every right on this list is one click away with nothing to prove.

If we refuse a request, we will say why, and you can ask us to reconsider by replying to that answer. We will look at it again and give you a decision. If you are still not satisfied, you can complain to the data-protection authority where you live; the answer we send you will not pretend otherwise.

  • Access & portability: download your full account as a JSON file from your Privacy settings.
  • Erasure: delete your account and all its data instantly, from the same screen.
  • Correction: edit any field in your dashboard at any time.
  • Withdraw consent: deleting your account withdraws consent and removes the data.

How we protect it

Your PIN is stored as an argon2id hash; your recovery code and any recovery link are stored as keyed SHA-256 hashes. Never in the clear, either way: both kinds are one-way and both are mixed with a secret key that is not in the database, so neither can be read back. The difference is only which tool fits which secret — your PIN is short and chosen by you, so it gets the deliberately slow one; a recovery code is long and generated by us, where slowness would buy nothing. Traffic is encrypted over HTTPS, sign-in is rate-limited, we minimize what we collect, and a scan record holds nothing but your tag and a timestamp.

The most sensitive fields are also encrypted in the database itself: your name, allergies, medications, conditions, implants, notes, weight, email and date of birth, plus your emergency contacts’ names, numbers and relationships, your insurance member and policy numbers and your bike’s VIN. Each value is encrypted with a key our server holds and is tied to your record, so it cannot be moved to someone else’s. What this protects against, precisely: someone who obtains the database alone — a stolen backup or snapshot, or over-broad access at our hosting provider — gets ciphertext, not your information. What it does not protect against: our server itself. It has to be able to decrypt, because your tag has to open for a stranger holding a phone and no key. We would rather say that plainly than imply a protection we do not have.

Children

KINTAG is for adults: you must be 18 or older to have an account, and that is what you confirm when you register. Do not create an account for anyone under that age. If you believe a minor has an account, write to us and we will delete it.

Changes

If we change this notice materially we will publish a new version here. Your account records which version you accepted.

Contact

Questions or requests: write to us .