Skip to main content

Last Updated: August 18, 2026

Privacy Policy

This is a working version, currently under legal review. If anything here is unclear or concerns you, write to us at hello@kindtru.org — a person reads it.

KindTru provides organizational health assessments for community-based nonprofits, plus free public-record tools anyone can use. This policy explains what we collect, why, and what we promise — for three kinds of people: organizations that use KindTru, board members and staff who answer surveys, and visitors who use our free tools. We've tried to write it the way we write everything: plainly.

If You're Answering a Survey, Start Here

Your organization's administrator invited you, which means we hold your name and email address (they provided it) and, once you respond, your survey answers. Here is what we promise about those answers:

  • Your individual responses are never shown to anyone — not your executive director, not your board chair, not us in any routine course of business. Reports show only group-level patterns.
  • If fewer than 3 people from your group (board or staff) respond, that group's data is excluded from analysis entirely. With 3–4 respondents, reports show organization-wide aggregates only. Only at 5 or more does a report note that perspectives differ — and even then it never says which group scored higher or lower.
  • More than a dozen automated checks scan every generated report for language that could attribute a view to a group or person, and a final scrubbing pass runs when the report is displayed.
  • If you have been invited but have not submitted yet, you can ask us to remove your invitation and we will. Once you submit, your answers stop being separable from everyone else's: there is no screen anywhere in KindTru that can show your responses on their own, which is the same design that keeps them anonymous from your own leadership. That means we cannot pull a submitted response back out, and we would rather tell you that plainly before you answer than discover it together afterward.

Concerns about your data? Write to us directly at hello@kindtru.org.

What We Collect from Organizations

  • Account information: your name, email address, and organization name.
  • Organizational context: what you tell us during intake — budget range, board size, staffing, mission focus, and similar — used to tailor your assessment.
  • Optional EIN:if you add your Employer Identification Number in Settings, we use it to link your account to your own public IRS filings. It's public data.
  • Survey and check-in responses: answers from the people you invite, during assessments and the 30/60/90-day check-ins.
  • Assessment outputs: scores, reports, action plans, and documents you generate (facilitation kits, stakeholder communications, saved grant drafts). Two generated documents — the Board Welcome Pack and Policy Starter Shelf drafts — are never stored: they exist only in your browser until you copy them.
  • Payment information: processed entirely by Stripe. We never see or store card numbers.
  • Feedback:if you're a pilot organization or reviewer, the feedback you submit through our forms.

What We Collect from Free-Tool Visitors

  • Public-record lookups are not stored. When you look up an organization or paste a grantee list, we fetch public IRS data, show it to you, and keep nothing about the search.
  • If you ask us to email you something— the free guide or a snapshot PDF — we keep your name, email, and organization name, and we'll send a short series of follow-up emails about organizational health. Every one includes a working unsubscribe link, and unsubscribing sticks.

What We Collect from Everyone, in Small Amounts

  • Essential cookies keep you signed in. We have no advertising trackers, and our analytics are cookieless.
  • Usage events:first-party counts of steps like “viewed the guide page” or “completed signup,” tied to a random per-tab session ID, so we can see where the product loses people.
  • IP addresses, held briefly to rate-limit sign-in attempts, code guesses, and lookup traffic.
  • Error reports (Sentry), with personally identifying information stripped and survey content redacted before anything is sent.

How We Use Artificial Intelligence

We use Anthropic's Claude API to draft the narrative documents you ask for: report sections, facilitation kits, stakeholder communications, grant narrative drafts (including any funder description you paste in), cohort insights for foundations, board welcome packs, and policy starter drafts.

  • What crosses to Anthropic is what the document needs: aggregated scores, your organizational context, and the inputs you provide. Individual survey responses are not sent — generation works from aggregates.
  • Anthropic does not train its models on this data. Anthropic retains API inputs and outputs briefly under its commercial data policies before automatic deletion; see Anthropic's published data-retention terms for specifics.
  • Generated documents are stored in our database (except the two ephemeral ones noted above) and are visible only to your organization's account.

How We Protect Confidentiality

Protecting individual respondents is central to how KindTru works. We enforce confidentiality through layered safeguards:

  1. Group suppression in single-org reports:if fewer than 3 people respond from any group (board or staff), that group's data is excluded from analysis entirely. Full unlabeled-divergence reporting requires at least 5 respondents in total; with 3–4, the report shows aggregate scores only.
  2. No individual attribution: when a report notes differing perspectives, it never identifies which group scored higher or lower.
  3. Validation checks: every AI-generated narrative is screened against more than a dozen confidentiality patterns before it reaches you; failures are regenerated.
  4. Render-time sanitization: a final scrubbing pass runs when the report is displayed.
  5. Cohort confidentiality (foundation learning cohorts): every category requires at least 5 participating organizations before any data is shown, and cohort segments start at 10 organizations per segment and can never be set below the 5-organization category floor. Below those floors, foundations see a locked placeholder rather than partial signal.

We also keep a plain-language walk through these protections, including the places where they stop, on our Confidentiality page.

Foundations and Learning Cohorts

If your organization joins a foundation's learning cohort, you choose category by category what to share into the cohort aggregate, and you can withdraw at any time. The foundation never sees your individual results, your consent choices, or even how much you chose to share — only cohort aggregates that clear the 5-organization floor.

The Services We Rely On

Each processes data only to run KindTru, under its own privacy policy: Supabase (database and sign-in), Stripe (payments), Anthropic (AI drafting), Resend (email delivery), Vercel (hosting and cookieless analytics), Sentry (error monitoring, with PII stripped), ProPublica's Nonprofit Explorer API (public-record lookups — your searched name or EIN reaches ProPublica from our servers; your identity does not), and Google Workspace (our mailboxes, when you email us).

How Long We Keep Things

  • Assessment data (responses, scores, reports): for the life of your account; deleted on request or at account closure.
  • Email delivery logs: 12 months, purged automatically.
  • Free-tool leads: until you unsubscribe or ask us to delete you.
  • Usage events: 12 months, purged automatically.
  • Rate-limit records (the ones holding IP addresses): 30 days, purged automatically.

Your Rights

Whether you're an organization, a respondent, or a visitor on our email list, you can ask us to export what we hold about you, correct it, or delete it: hello@kindtru.org. We respond within 30 days.

A Few More Things

  • Children: KindTru is a workplace tool for organizations and is not directed to children under 13.
  • Security:encryption in transit, row-level access controls in the database, least-privilege service keys, and error monitoring. No system is perfectly secure, and we won't pretend otherwise.
  • If something goes wrong: we will notify affected organizations promptly.
  • Where processing happens: the United States.
  • Changes:we'll post updates here with a new date, and email account holders about material changes.

Contact Us

Questions about this policy or how we handle your data: hello@kindtru.org. A person reads it.