One login for the whole family looks convenient. It quietly removes roles, child protection and any real audit trail.

The convenient default

Most family apps start the same way. One person creates the account, sets a password, and reads it out at the dinner table. Everyone types it in. It takes thirty seconds, and it feels like a family thing to do.

It also means the app has no idea who anyone is.

What you lose

The cost of a shared login is invisible until you need one of the things it makes impossible.

  • Roles. If everyone is the same user, there is no way to say that the grandparent can see the calendar but not the budget, or that the fourteen-year-old can tick off chores but not delete the shopping list. Every permission has to be everyone’s permission.
  • Child protection. A child using a shared adult login sees everything the adults see, including things about money, health and other family members that a child has no business seeing. Regulators are right to be strict about this, and a shared password makes compliance with children’s privacy rules impossible by construction.
  • An audit trail. When the budget is edited or a document disappears, “someone did it” is the only answer available. Attribution needs identity.
  • Recovery. One password, one email address, one phone. Lose access to that and the whole household is locked out together.
  • Leaving. Households change. A partner moves out, a carer stops coming, a teenager becomes an adult. With a shared password, the only way to remove someone is to change it for everyone.

What KinHolo does instead

Every member has their own credentials, including children. A parent creates a child’s account and sets it up; the child has their own way in, their own scope, and protective defaults that only a parent can widen. There is no household password anywhere in the product. We mean that literally: there is no place in the database where one could be stored, and there is a test that fails if anyone ever adds one.

Passwords are hashed with a modern, memory-hard algorithm and are never stored in a form anyone could read back. Sign-in, password reset and account recovery give the same answer whether or not an account exists, so the app cannot be used to find out who is a member. Every session can be seen and revoked from inside the app, and revoking one takes effect on the server immediately.

Every action in a household is attributed to the individual who took it, and the household’s activity log is chained so that a removed or altered entry is detectable. The log is readable in the app, in plain language, because a trail nobody can read is not much of a trail.

Why this matters more for families than for companies

Workplaces solved individual identity long ago because the stakes were obvious. Families have been treated as one blurry user because the stakes seemed low. They are not. A household holds information about children, health, money and location, and it holds it for people who did not all choose the app and cannot all consent in the same way.

Individual identity is what makes per-record visibility possible: whole household, chosen members, or you only, set on the record itself. It is what lets a co-parenting arrangement have a neutral shared space between two homes without either home seeing into the other. And it is the difference between a promise about privacy and a mechanism for it.

Want the next one?

One short letter a month. Nothing else.

Join the waitlist