Draft for Andy's review — SMS enrollment is not available yet.

SMS privacy draft

How Kinpath would handle Circle messaging data

This draft describes the planned text-message program. It is not deployed policy and the program is not active. Kinpath is operated by Andrew Clifford Wassyng as a Washington sole proprietorship.

Draft updated August 14, 2026.

Review required. The retention choices, provider-access tradeoff, support contact, and exact member-facing copy must be approved before this policy can be published.

Scope

This policy is limited to the proposed Kinpath Circle messages program for recipients in the United States and Canada. The program would send non-marketing Circle logistics only after the recipient chooses SMS and proves possession of the mobile number.

Information the program would process

Kinpath Circle messages would not contain Circle speech, feedback, attendance history, private reasons, Guide memory, crisis content, health information, contact lists, access tokens, account identifiers, or a participant roster.

Why the information would be used

Kinpath would use the information to prove recipient consent, send the approved closed logistics templates, prevent duplicate or over-frequency sends, report bounded delivery state, respond to HELP, honor STOP and other reasonable revocation requests, secure the service, and account for provider cost.

Provider and carrier handling

Kinpath plans to use Twilio in its United States region. Twilio and downstream mobile carriers necessarily receive the destination number and message while routing SMS. SMS is not end-to-end encrypted, and selecting a United States provider region does not promise that carrier routing remains in one country.

Kinpath plans to enable Twilio message-body redaction before live sending. Twilio's current documentation says ordinary production access to unredacted message data can continue for up to 24 hours and that separate limited-access compliance storage remains for an unspecified period. Kinpath will not publish a guessed duration.

Twilio's standard toll-free STOP filter retains opted-out numbers needed to block later sends. During a Kinpath webhook outage, that provider backstop blocks and confirms STOP. Kinpath mirrors durable global suppression only after a primary or fallback signed webhook succeeds or the event is recovered. Kinpath therefore cannot promise complete phone-number redaction for numbers in Twilio's opt-out list.

Sharing and sale

Kinpath would disclose SMS data to Twilio and mobile carriers only as needed to route messages, operate STOP and HELP, provide delivery facts, protect the service, and meet binding legal requirements. Kinpath would not sell mobile information or use SMS consent for third-party marketing.

All the above categories exclude text messaging originator opt-in data and consent; this information won’t be shared with any third parties.

Access and security

Kinpath's planned controls encrypt phone numbers, separate encryption and fingerprint keys, restrict provider-console production-data access to an owner and one operational backup using phishing-resistant multifactor authentication, and avoid storing message bodies in application logs. Facilitators would see at most a masked last-two-digit number while an invitation is active.

Retention and deletion are not yet approved

For controlled test enrollment while the human ruling is open, evidence is deleted within 30 days after the test gate. For a future public program, the engineering draft deletes encrypted phone data 30 days after no active invitation, consent, or unresolved delivery needs it; detailed provider, send, and inbound-event rows are also deleted after 30 days after content-free counts are produced.

The proposed consent-evidence duration is 24 months after expiry or revocation, but Andy and counsel have not approved it. A suppression fingerprint may need to remain while an opt-out is in force so deletion does not cause a later text to someone who said STOP. The exact deletion treatment for that fingerprint is also unresolved.

A verified deletion request would remove the phone ciphertext and account linkages under the current design. Before deployment, Kinpath must publish whether removing the suppression fingerprint instead places the number into a separate do-not-import process. Provider and carrier retention are governed by their own systems; Twilio's limited-access compliance duration is currently unknown.

Your choices

SMS consent would be optional and separate from using Kinpath. Reply STOP to opt out of all Kinpath texts to that number. Reply HELP for help. A request made through the app, web, or support would use the same global suppression path once those routes exist.

For access, correction, or deletion questions, review the draft Help page. The candidate contact, hello@kinpath.community, is not yet verified as monitored and must not be published as a working support promise.