Privacy Policy
Effective date: May 27, 2026
This policy describes how Kear Continuity Office ("we", "us", "our") collects, uses, and protects personal information when you use the Kear Continuity client portal.
1. Who we are
Kear Continuity Office provides digital continuity planning services to individuals and households. We operate the client portal at this domain and manage all client engagements through it. For privacy inquiries, contact us at privacy@kearcontinuity.com.
2. Information we collect
We collect the following categories of information:
- Account information. Your name, email address, and authentication credentials when you create an account or are invited to the portal.
- Engagement data. Information you provide in the course of your continuity planning engagement — including the accounts and services you use, household structure, device inventory, and preferences. This information is provided voluntarily as part of delivering the service.
- Usage data. Basic technical information such as browser type, pages visited, and timestamps of actions within the portal, collected to operate and improve the service.
- Communications. Records of messages you send to us through the support system or by email.
We do not collect passwords, recovery codes, seed phrases, MFA secrets, or any credential that would allow access to your external accounts. Our system is not designed to receive these materials and our guides explicitly instruct you to retain them yourself.
3. How we use your information
We use your information to:
- Deliver and manage your continuity planning engagement
- Communicate with you about your plan, tasks, and support requests
- Authenticate your access to the portal
- Generate written analysis and summaries as part of your continuity plan (using anonymized data — see Section 6)
- Improve the reliability and security of the platform
- Comply with legal obligations
We do not use your information for advertising, behavioral profiling, or any purpose beyond delivering the services you have engaged us to provide.
4. What we do not do
- We do not sell your personal information to any third party.
- We do not share your information with advertisers or data brokers.
- We do not use your data to train machine learning models or AI systems without explicit consent.
- We do not send unsolicited marketing communications.
5. Data storage and security
Your data is stored in Supabase, a cloud database platform with SOC 2 Type II certification. All data is encrypted at rest using AES-256 and in transit using TLS. Access to your records within the portal is controlled by row-level security policies that restrict visibility to you and your assigned advisor.
Authentication is managed by Supabase Auth. Your password is hashed and never stored in readable form. We do not have access to your password in any form.
We limit access to personal data to personnel who need it to deliver your engagement. All access is logged.
6. Third-party services
We use a limited number of third-party services to operate the portal. Where personal data is shared with these providers, it is limited to what is necessary for that function:
- Supabase — database, authentication, and file storage
- Resend — transactional email delivery (e.g., login confirmations, plan updates)
- Vercel — application hosting and delivery
- Anthropic — AI-powered analysis and document generation. Data transmitted to this service has personal identifiers removed prior to transmission. Anthropic processes this data under a zero-data-retention agreement and does not store, log, or use it beyond generating the requested output.
These providers are contractually bound to use your data only to provide their services to us and not for any independent purpose.
7. Data retention
We retain your personal information for as long as your engagement is active and for a reasonable period afterward to allow for follow-up, legal compliance, and dispute resolution. If you request deletion of your account and data, we will fulfill that request within 30 days and confirm when it is complete. Certain records may be retained longer if required by law.
8. Your rights
You have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — request that inaccurate information be corrected
- Deletion — request that your data be deleted from our systems
- Portability — request your data in a structured, machine-readable format
- Objection — object to any processing you believe is not justified
To exercise any of these rights, contact privacy@kearcontinuity.com. We will respond within 30 days.
9. Cookies
The portal uses session cookies required for authentication and to keep you signed in. These are strictly necessary and cannot be disabled without preventing access to the service. We do not use advertising or tracking cookies.
10. Changes to this policy
If we make material changes to this policy, we will notify you by email and update the effective date above. Continued use of the portal after notification constitutes acceptance of the updated policy. We will not make retroactive changes that reduce your rights without explicit consent.
11. Contact
For any questions about this policy or about how your data is handled:
For a plain-language overview of our data practices, see How we protect your data.