Privacy & Data Protection Policy
KinVeto never inspects your private personal files, keystrokes, web browsing history, or documents. Our background security agent strictly monitors and intercepts rogue remote desktop utilities (like AnyDesk or TeamViewer) to block unauthorized takeover attempts.
1. Information We Collect
When you use KinVeto services, we collect minimal operational information required to provide endpoint defense and family guardian notification channels:
- Account Information: Name, email address, password hash (scrypt salted), and role.
- Workstation Fleet Metadata: Device identifier names (e.g. "Mom's Laptop"), operating system type, agent cryptographic public verification hash, and connection heartbeat timestamps.
- Security Threat Logs: Process names of intercepted remote desktop tools, event classification (BLOCKED, ALLOWED), and timestamped approval records.
- Billing Data: Secure transaction references provided by Paddle merchant services (we do not store raw credit card numbers on KinVeto servers).
2. How We Use Information
We use collected metadata strictly to enforce zero-trust thread termination on unauthorized remote desktop software, dispatch instantaneous alerts to verified Family Guardians, facilitate cryptographic temporary assistance windows, and manage workstation fleet capacity.
3. Data Protection & Cryptography
All sensitive configuration secrets, SMTP credentials, and Single Sign-On keys are encrypted at rest using AES-256 Fernet encryption. Communication between workstations and KinVeto cloud gateways occurs exclusively over TLS 1.3 encrypted WebSockets and HTTPS.
4. Your Privacy Rights
Under GDPR and CCPA, you have the right to request export or complete deletion of your account and device logs at any time. Contact our Data Protection Officer at privacy@kinveto.com.