Skip to content

DOUBLE CREDITS on your first month, or your first 3 months on annual

Claim now
Kyndrify
Privacy Policy

Privacy policy.

Effective: 10 June 2026 · Last updated: 2 October 2026

This Privacy Policy explains how Kyndrify (operated by Through The Glass Creatives Global - FZCO) collects, uses, and shares information about you.

Information We Collect

To provide the service, we collect:

  • Account information: email, password (stored only as a securely salted hash; we never store plaintext), first name, billing details (held by our payments provider, not us).
  • Content you upload: photos, voice recordings, consent videos, and the files you attach in chat (video, audio, pictures and documents). We read the words in a document you attach so Kae can use them in your plan. Stored encrypted in our managed object storage.
  • Generated renders: the videos Kyndrify creates for you.
  • Usage data: render history, credit transactions, authentication events, IP addresses for security purposes, browser type. We do not sell this data.
  • Purchase agreements: when you buy a plan, credits, or storage, a record that you agreed to the Terms and the Refund Policy, with the time, the IP address, and the browser used. We keep it as proof of that agreement.
  • How you found us: the search, link, or campaign that brought you to the site, the campaign details carried in that link, and the page you landed on. We keep that much in your browser from the moment you arrive, because it is our own note about our own site and it holds nothing another company could match you against. In the EU, the UK and Switzerland, the ad click that brought you is kept only if you accept advertising cookies; everywhere else it is kept unless you turn ad measurement off (see Cookies below). If you sign up, we save what we have with your account, so we can tell which pages and which ads are worth repeating.
  • Biometric data: a face template (facial geometry) derived from your photos and consent recording, used solely to verify identity and prevent abuse. Kyndrify does not use it to train a Kyndrify model. We derive temporary face measurements during a check and do not intentionally retain the individual frame-by-frame measurements as separate customer records. We may retain encrypted face-template evidence, a numeric match score, and the consent recording to document consent and prevent misuse. Active reference templates are removed when consent is withdrawn; other verification evidence is retained only as needed for a legal record and applicable law. Full details in our Biometric Information Privacy Notice.

How We Use Information

  • To generate the renders you request
  • To enforce identity and consent on every twin
  • To detect and prevent abuse (e.g., stolen-photo twins)
  • To screen uploaded media and generated output with automated content-safety systems for illegal or prohibited material (such as CSAM), and to meet mandatory-reporting obligations under applicable law
  • To process payments via our payments provider
  • To send you transactional emails (render-ready, password reset)
  • To send occasional product updates and educational or marketing emails (tips, new features, getting-started guidance). You can opt out at any time using the unsubscribe link in any such email or through your email preferences.
  • To see which search, link, or campaign brought you to our own site, and which pages lead to sign-ups, so we know what is worth writing more of
  • To measure our own ads: which ad click brought you here, and whether that visit led to a sign-up. In the EU, the UK and Switzerland we do this only if you accept advertising cookies; everywhere else it is on unless you turn it off
  • To follow up on your sign-up and help you get started, using the customer-relationship tool our small team works from
  • To comply with legal obligations

Legal Grounds We Rely On

Where laws like the GDPR require a legal ground for processing, these are the grounds we rely on for each purpose:

  • Performance of a contract: generating the renders you request, operating your account and workspace, and processing your payments.
  • Explicit consent: biometric identifiers (the face template used to enforce identity and consent on every Digital Twin, and the voice reference used to build your voice). We collect these only after you or the consenting person expressly agree, as described in our Biometric Information Privacy Notice. Consent also covers marketing emails and, in the EU, the UK and Switzerland, non-essential cookies, and you can withdraw it at any time.
  • Legitimate interests: detecting and preventing abuse (such as stolen-photo twins), securing accounts and sign-ins, understanding product usage, and keeping our own first-party record of which search, link, or campaign brought a visitor to our site. Our interest is protecting people from non-consented digital twins, keeping the service secure, and knowing which of our own pages are worth keeping.
  • Legal obligation: screening for illegal material, mandatory reporting, and tax and accounting records.

Sub-processors

We rely on a small set of vetted sub-processors to operate Kyndrify, covering:

  • Cloud hosting (application + worker compute, database, object storage)
  • AI inference for voice, image and video generation, and for planning and understanding what you ask in chat
  • Automated content-safety screening
  • Payment processing
  • Transactional email delivery
  • Error monitoring and product analytics (privacy-preserving)
  • Ad measurement, for visitors who accept advertising cookies or, outside the EU, the UK and Switzerland, have not turned it off
  • The customer-relationship tool we use to follow up on sign-ups and answer support questions

Kyndrify does not authorize sub-processors to use your content for unrelated purposes. Their handling of personal data is governed by applicable contracts, service terms, and this policy. The current named list is available on request at privacy@kyndrify.com. Enterprise data-processing terms are being finalised with counsel; ask your Kyndrify contact for the current status before you rely on a specific contractual commitment. We provide notice of sub-processor changes where an applicable contract or law requires it.

Sharing for Ads and Follow-up

We do not sell your data, and we never hand your renders, photos, voice recordings, or scripts to anyone for their own marketing. Two kinds of sharing do happen, and here is exactly what they are.

  • Ad measurement. If you accept advertising cookies, our marketing site tells our advertising partner, Meta, that a browser viewed a page or created an account, so we can see which of our ads bring people here. What is shared is activity on our public site, not the contents of your account, your uploads, or your renders. Decline advertising cookies and nothing is sent. That is how it works in the EU, the UK and Switzerland. Everywhere else ad measurement is on from your first visit, and turning it off stops it the same way (see Cookies below).
  • Sign-up follow-up. When you create an account, we send your email address, your first name, and how you found us to the customer-relationship tool our team works from, so we can welcome you, help you get started, and answer you when you write in.

Everything else stays with the sub-processors above, and they may only use it to run the service for us.

Health Information (HIPAA)

Kyndrify is not HIPAA-eligible. The AI providers we rely on for voice cloning and talking-head video generation do not currently offer Business Associate Agreements covering those services. Do not upload Protected Health Information (PHI) and do not use Kyndrify to generate content that processes patient data. We will update this section if and when BAA-signed compute becomes available.

Your Rights

You have the right to:

  • Access: request a copy of your data
  • Correct: fix inaccurate information
  • Delete: remove your account and all twins. When you delete your account, your personal data (including face templates, uploaded photos and voice references, and renders) is erased promptly from our active systems; encrypted backups are overwritten as they age out of our backup-retention cycle. Your consent recording is retained separately as a legal record of consent (see Data Retention below); everything else is erased.
  • Restrict / object: ask us to stop certain processing
  • Portability: receive your data in a machine-readable format
  • Complain: if you are in a country with a data protection authority, you can lodge a complaint with your local authority. We would appreciate the chance to address your concern first at privacy@kyndrify.com.

Email privacy@kyndrify.com to exercise any of these rights.

Data Retention

  • Account data: while your account is active, then erased promptly on deletion
  • Consent recordings: at least life of twin + 7 years (legal record), unless the law requires longer
  • Render outputs: until you delete them
  • Authentication and security logs: at least 12 months
  • Billing records: subject to our payments provider's policy and applicable tax law

Children

Kyndrify is not directed at children under 18. We do not knowingly collect data from children. If you believe a child has provided us information, contact privacy@kyndrify.com and we will delete it.

International Transfers

Kyndrify is operated from the United Arab Emirates by Through The Glass Creatives Global - FZCO. To deliver the service we process data in the United States (application and storage infrastructure) and in Singapore (voice synthesis), and we may use providers in other regions for specific processing tasks. If you access Kyndrify from the European Union, the United Kingdom, the UAE, or another region with data-protection laws, transfers of your data to countries without an adequacy decision are made under appropriate safeguards, such as Standard Contractual Clauses or an equivalent transfer mechanism.

Cookies

Cookies come in three types here. Essential cookies keep you signed in, keep your account safe, remember your cookie choice, and note which search or link brought you to our own site, so they are always on. Analytics cookies count visits and show which pages people read. Advertising cookies record the ad click that brought you here and let us see whether that visit turned into a sign-up. In the EU, the UK and Switzerland, analytics and advertising both stay off until you accept them.

There, the banner on your first visit gives you three answers: decline everything, accept analytics only, or accept everything. Your answer is stored for 180 days, and you can change it any time with the Cookie settings link at the bottom of any page. Your browser settings work too.

Your privacy choices outside the EU, UK and Switzerland

Everywhere else, analytics and ad-measurement cookies are on from your first visit, and no banner asks first. You can turn either one off at any time with the Your privacy choices link at the bottom of any page, and your answer is kept for 180 days. If your browser sends the Global Privacy Control signal, we turn ad measurement off for you automatically. It is the same set of cookies and the same table below. Visitors in the EU, the UK and Switzerland are asked first, as described above.

Here is every cookie we can set.

Every cookie Kyndrify and our partners can set, what it does, how long it lasts, and who sets it.
CookieWhat it doesTypeHow long it lastsWho sets it
__Secure-authjs.session-tokenKeeps you signed in to the Studio.Essential30 days, and it renews while you keep using KyndrifyKyndrify
kn_mfaRemembers that you passed a two-step security check, so you are not asked again on every protected page.Essential30 daysKyndrify
ky_consentStores your cookie choice so we stop asking.Essential180 daysKyndrify
__cf_bmHelps our security network tell a person apart from a bot. It only appears when a check runs.Essential30 minutesCloudflare, our security and delivery network
cf_clearanceRecords that you passed a security check, so you are not challenged again right away.EssentialUp to 30 minutesCloudflare, our security and delivery network
_ga and _ga_<id>Counts visits and shows which pages people read, using a random id. We use it to fix the parts people get stuck on. In the EU, the UK and Switzerland it is set only after you accept analytics cookies. Everywhere else it is on from your first visit until you turn it off.AnalyticsUp to 2 yearsGoogle Analytics
_fbpLets us see whether an ad we ran led to a visit or a sign-up. In the EU, the UK and Switzerland it is set only after you accept advertising cookies. Everywhere else it is on from your first visit until you turn it off.Advertising90 daysMeta
_fbcStores the ad click that brought you here, when you arrive from one of our ads. In the EU, the UK and Switzerland it is set only after you accept advertising cookies. Everywhere else it is on from your first visit until you turn it off.Advertising90 daysMeta
ky_attrRemembers which search, link or campaign brought you to Kyndrify, and the page you arrived on, so we can see which pages are worth writing more of. No name, no email, nothing about you. When ad measurement is on for you, it also remembers the ad click that brought you, so we can tell which ads are worth running again. In the EU, the UK and Switzerland that part waits until you accept advertising cookies. Everywhere else it is on until you turn it off.Essential90 daysKyndrify
ky_expRemembers which version of a page we showed you, so it stays the same on your next visit and we can see which version people get on with better. No name, no email, nothing about you.Essential90 daysKyndrify
ky_memberRemembers that an account has signed in on this browser, so our website stops offering you a sign-up. No name, no email, nothing about you.Essential1 yearKyndrify
ky_regionRemembers whether the rules where you are ask us to get your yes before any analytics or ad cookies, so we show the right cookie choice. It holds one of two words and nothing about you.Essential180 daysKyndrify
ky_first_run_doneRemembers that you finished setting up your account, so the Studio opens on your Home instead of the setup steps. No name, no email, nothing about you.Essential1 yearKyndrify
ky_refCredits the partner who sent you if you sign up. Set when you arrive through a partner referral link.Advertising30 daysKyndrify

On a plain http connection, such as a local test build, the sign-in cookie is named authjs.session-token. If we ever switch on another analytics tool, it goes in the analytics group, it follows the same rule as the rows above for where you are, and this table is updated before it does.

The full picture, including how to change your choice, lives on our Cookie Policy page.

Security & Data Breach Notification

We protect your data with encryption in transit and at rest, strict access controls, and continuous monitoring, and we maintain an incident-response process. No system is perfectly secure. If a personal data breach occurs that is likely to affect your rights, we will notify the relevant supervisory authority without undue delay and, where the breach is likely to result in a high risk to you, we will notify you directly and explain what happened, the likely consequences, and the steps we are taking. Notifications follow the timelines required by applicable law (for example, within 72 hours of becoming aware of a qualifying breach under the EU and UK GDPR, and as required by the UAE Personal Data Protection Law).

Changes to This Policy

We may update this policy from time to time. If applicable law requires advance or direct notice, we will provide it through an appropriate channel before the change takes effect. The dates at the top show when this policy took effect and when we last changed it.

What Changed on 28 September 2026

We now follow the cookie rules of the place you visit from. In the EU, the UK and Switzerland nothing changes: the banner asks first, and analytics and advertising stay off until you accept them. Everywhere else they are on from your first visit, the Your privacy choices link at the bottom of any page turns either one off, and a browser that sends the Global Privacy Control signal has ad measurement turned off automatically.

What Changed on 19 September 2026

We split the cookie that records how you arrived. The half that notes which search, link, or campaign brought you to our own site, and the page you landed on, is now set for every visitor as a strictly necessary first-party record: it is our own note about our own pages, it is never shared, and it holds nothing another company could match you against. We keep it so we can see which pages earn sign-ups and which ones to retire. The other half, the ad networks' own click ids, still waits until you accept advertising cookies, because matching a click against an ad network's records is the step that involves someone else.

What Changed on 7 September 2026

Two retention periods now read as minimums. Consent recordings are kept for at least the life of the twin plus seven years, and authentication and security logs for at least twelve months, because the law can require us to keep either for longer and we would rather say so than promise a shorter period we might not keep. The Biometric Notice now says we email you about 60 days before a scheduled destruction, so a twin that is still in use can be kept.

What Changed on 5 September 2026

We started running ads, and this policy now says so. Our marketing site can load an advertising pixel that reports page views and sign-ups to Meta, and a first-party cookie can record the ad click that brought you here. The pixel and the ad-click half of that cookie only run if you accept advertising cookies. When you create an account, your email address, first name, and how you found us go to the customer-relationship tool our team works from, so we can follow up and help you get started. The cookie banner now offers three answers instead of two, analytics and advertising are separate choices, and the table above lists every cookie by name. Two older sentences said we used no advertising cookies and shared nothing with advertising partners. That is no longer true, so we replaced them rather than leave them standing.

Contact

The data controller is Through The Glass Creatives Global - FZCO.
Email: privacy@kyndrify.com
Mailing address: Through The Glass Creatives Global - FZCO, IFZA Business Park, Building A2, Nadd Hessa, Dubai Silicon Oasis, Dubai, United Arab Emirates.