keep.

Privacy Policy

Effective 16 September 2026 · Version 2026-09-16

keep. is a place to write down what you are about to do, focus on it, and then reflect on how it went. What you write in it is the most personal thing this app touches, so this page says plainly what is stored, where it lives, who can reach it, and how to take it back or leave.

The short version

Who is responsible for your data

keep. is built and run by Keep Dev, an individual developer based in India, acting as the data fiduciary under India’s Digital Personal Data Protection Act, 2023, and as the data controller under the EU and UK GDPR where those apply to you.

For anything about your data, including requests and complaints, write to supportfrompanda@gmail.com.

What keep. collects

Everything below is either something you typed, something needed to keep your account working, or something needed to sync your writing between your own devices. There is nothing collected “just in case”.

Your account

You sign in with an email link, with Google, or with Apple. keep. stores the email address associated with that sign-in. If you use Apple’s Hide My Email, the relay address is all that is ever received — your real address is never seen. Passwords are never used and never stored.

Your profile

A display name (which starts as “Friend” until you change it), your time zone, and your language. The time zone is read from your device once when the account is created, and is used to decide which day a Keep belongs to — which is what makes streaks and day summaries correct.

What you write

This is the heart of the app, and the part treated most carefully:

This text is stored so it can appear on your other devices and in your export. It is not read, mined, or used to train anything. There are no AI features in keep. today; if that ever changes, it will be a separate opt-in that names the provider, and it will be off until you say yes.

Facts about each session

How long you planned to focus, how long you actually did, when the session started and ended, which day it belongs to, whether it completed or was interrupted.

Your device

When the app first syncs, it registers the device so your Keeps can be attributed to where they were created. That record holds a random identifier generated on the device, whether it is iOS or Android, and the app version. It does not include your name, your phone number, your IMEI, an advertising identifier, or a push notification token.

Your consent history

Each time you grant or withdraw a consent, an entry is added to an append-only record: which consent, whether it was granted or withdrawn, which version of this policy was in force, and when. This exists so that “what did I actually agree to, and when?” has an honest answer years later. It is included in your export.

Subscription status

keep.+ is not yet available for purchase. When it is, whether your subscription is active will be stored. Payment itself happens through the App Store or Google Play — your card details never reach keep. and are never seen.

Usage analytics, only if you turn them on

Analytics are off by default, everywhere, not only in regions that require it. If you switch them on in Settings, keep. records structural facts about how the app is used — that a Keep was created, that a reflection was saved, which screen was opened — so that rough edges can be found without asking you.

What you wrote can never be part of that. The analytics layer carries a hard block list covering task text, reflections, check-in notes, journal text, names and email addresses, and it drops any value longer than 64 characters on the grounds that long text is free text by definition. In development the block raises an error rather than passing silently, so a well-meaning change six months from now cannot quietly start leaking your writing.

What keep. never collects

Where your data lives

Your writing is stored twice: in a database on your own device, so the app works with no connection at all, and in a hosted database so it can reach your other devices.

The hosted side runs on Supabase, on Amazon Web Services in the ap-south-1 region (Mumbai, India). This is a single region — your data is stored in India regardless of where you are. Everything travelling between your device and that database goes over an encrypted connection.

Row-level security is enforced in the database itself, scoped to your user id, so one account cannot read another account’s rows even if application code were to ask for them.

Who else touches your data

These are the services keep. relies on. Each one only receives what it needs to do its job.

ServiceWhat it doesWhen
Supabase (AWS, Mumbai)Database, sign-in, and the server functions behind sync, export and deletionAlways
AppleSign in with AppleOnly if you sign in that way
GoogleSign in with GoogleOnly if you sign in that way
Expo (EAS)Delivers app updates. Checking for one reveals your IP address and app version to ExpoOn app start
PostHogUsage analyticsOnly if you turn analytics on
RevenueCatSubscription status for keep.+Not active yet

Your writing is never sold, rented, or handed to advertisers or data brokers. It may be disclosed if the law genuinely requires it — a valid court order, for instance — and where it is lawful to tell you, you will be told.

How long it is kept

Your Keeps and reflections stay for as long as your account exists, because a record of your own work that quietly expires would defeat the point of the app.

When you delete your account from Settings, deletion is scheduled with a 7-day grace period, which you can cancel from the same screen if you change your mind. After that window the deletion is permanent and cascades through everything: your profile, Promises, Keeps, reflections, check-ins, day summaries, devices and consent records. Nothing is kept as a disabled row.

Encrypted backups of the database may still hold your data for up to 30 days after that, until they age out on their own schedule. That is stated plainly here rather than claimed as instant erasure everywhere, because instant erasure everywhere would not be true.

Your rights

Under India’s DPDP Act, and under the GDPR if you are in the EEA or UK, you have the rights below. Most of them are buttons in the app rather than a request you have to make.

Security

Sign-in tokens are held in your device’s secure keychain rather than ordinary storage. Every database query is constrained by row-level security tied to your user id. Connections are encrypted in transit. The analytics block list described above is enforced in code rather than by convention.

No system is perfect, and it would be dishonest to promise otherwise. If a breach ever affects your data, you will be told, and so will the relevant authority, within the timeframes the law requires.

Children

keep. is not intended for anyone under 18, and accounts should not be created by or for them. If you believe a child has created an account, write to the address above and it will be deleted.

Beta

keep. is currently in beta testing. The app is still changing, and features described here may move or be replaced. Your data rights do not change with it — export and deletion work the same in beta as they will at launch.

Changes to this policy

If this policy changes in a way that affects you, the new version will be shown in the app and you will be asked to acknowledge it before continuing. Every version you have agreed to is recorded with its date, and appears in your export.

Contact

Keep Dev
supportfrompanda@gmail.com
India