Privacy Policy
Last updated: August 18, 2026
1. Who We Are
Keepli is operated by Keepli Technologies Inc. ("Keepli", "we", "us", or "our"), based in Ontario, Canada. We are the organisation responsible for the personal information described in this policy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Keepli mobile application (the "App") and the website at keepli.app (the "Site").
We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. Where you are located in another region, additional rights may apply (see Section 11).
Privacy Officer. We have designated a Privacy Officer who is accountable for our compliance with this policy and applicable privacy law. You can reach them at support@keepli.app.
2. Information We Collect
2.1 Information You Provide Directly
- Onboarding data: Your first name, last name, and chosen focus areas provided during setup.
- Vault content: Documents, subscriptions, passwords, receipts, and personal records you save in the App. Stored locally on your device by default.
- Journal and notes: Text you write in program dashboards, the daily journal, or the planning hub.
- Health and wellness data: Data you manually enter or import from Apple Health / Android Health Connect for programs such as sleep, fitness, or cycle tracking.
- Family Hub data: Names, shared documents, and messages within your family group — stored server-side only when you use the Family Hub feature.
- Financial data (statement import): If you use subscription detection, you may upload a bank or card statement, or connect Gmail, so Keepli can identify recurring charges. Keepli does not link directly to your bank and never receives your online-banking credentials. See Sections 3 and 6 for how imported content is processed.
2.2 Information Collected Automatically
- Device identifier: A randomly generated device ID (not linked to your Apple ID or Google account) used to associate your data with your device for cloud features.
- Push tokens: If you grant permission, an Expo push token is stored to deliver notifications.
- Analytics events (anonymised): Anonymised in-app events such as screen views and feature taps. No personally identifiable information or vault content is attached.
- Crash reports (anonymised): Diagnostic crash reports containing device model, OS version, and a stack trace — never your vault data.
2.3 Information From Third-Party Services
When you connect third-party services (Gmail, Google Drive, Apple Health, Android Health Connect), we receive only the data necessary to provide the requested feature, and only after you authorise the connection. See Section 6 for details.
3. How We Use Your Information
We use information we collect only for the purposes we identify to you, namely to:
- Provide, operate, and improve the App and its features.
- Personalise your experience based on your chosen focus areas and programs.
- Detect recurring subscriptions from a statement or connected Gmail account, when you use that feature.
- Send push notifications, including daily re-engagement reminders (only with your permission).
- Sync data between your devices when you enable cloud features.
- Process subscription payments through RevenueCat.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
- Generate aggregated, anonymised product analytics.
We do not sell your personal information, and we do not use your vault content, journal, health data, or messages to train AI models. If we ever wanted to use your information for a materially new purpose, we would identify that purpose and obtain your consent first.
4. Consent & Legal Basis
Under PIPEDA, we collect, use, and disclose personal information with your consent, except where the law permits or requires otherwise. The form of consent we rely on reflects the sensitivity of the information:
- Express consent for sensitive information and optional features — for example, enabling health tracking, cloud backup, AI features, Family Hub sharing, or location sharing. You choose to turn these on.
- Implied consent for the basic operation you request — for example, storing an item you add to your vault on your own device.
- Withdrawal. You may withdraw consent at any time by turning a feature off, deleting the relevant data, or closing your account, subject to legal or contractual limits we will explain if they apply.
Where the EU/UK GDPR applies to you, our legal bases are your consent, the performance of our contract with you (providing the App), and our legitimate interests in keeping the App secure and reliable.
5. Data Storage & Security
5.1 Local-First Architecture
By default, all vault data, journal entries, and personal records are stored exclusively on your device. This data does not leave your device unless you explicitly enable a cloud feature such as:
- Encrypted Cloud Vault Backup
- Family Hub
- My Circle / community features
- Cross-device sync
5.2 Cloud Storage
When cloud features are active, your data is transmitted over HTTPS (encrypted in transit) and stored in a PostgreSQL database with encryption at rest. We restrict access to production data to personnel who need it to operate the service.
5.3 Encrypted Vault Backup
When you use Encrypted Cloud Vault Backup, your data is encrypted on your device using AES-256-GCM with PBKDF2 key derivation before transmission. Your passphrase is never sent to our servers — we cannot decrypt your backup. This is a server-blind backup: we hold only ciphertext.
5.4 Safeguards
We maintain physical, organisational, and technological safeguards appropriate to the sensitivity of the information, including encryption in transit and at rest, biometric app locks for sensitive categories, access controls, and breach-response procedures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Third-Party Services & Subprocessors
Keepli relies on the following service providers ("subprocessors") to operate specific features. Each processes personal information only as needed to provide its service, and each has its own privacy policy:
- OpenAI & Anthropic (AI): power the AI document scanner, program insights, subscription detection, and the Ask Keepli (Melo) assistant. When you use an AI feature, the relevant content and the minimum context needed to answer are sent to the applicable provider to generate a response. The provider is selected by feature and may fail over between the two. They process your input on our behalf and do not use it to train their models. OpenAI · Anthropic.
- RevenueCat (subscriptions): receives your device ID and purchase information to manage subscriptions. Policy.
- Google — Gmail & Google Drive (optional imports): if you connect them, we receive read-only access limited to what you authorise, used only to detect subscriptions or import files. We do not retain this content beyond what you save to your vault. Policy.
- Apple HealthKit / Android Health Connect: if you grant access, Keepli reads metrics (steps, heart rate, sleep, etc.) solely to display them in your program dashboards. We do not share this data with third parties or use it for advertising.
- Cloudflare R2 (object storage): stores your encrypted cloud backups and any media you upload for cloud features.
- LiveKit (live audio): provides real-time audio infrastructure if and when you join a live audio Pod (voice room).
- Sentry (crash reporting): receives diagnostic crash reports that do not contain vault content or personal identifiers. Policy.
- Expo (push notifications): transmits push tokens to deliver notifications to your device. Policy.
We do not use advertising networks and do not sell or share your personal information for advertising.
7. Where Your Data Is Processed
Keepli is operated from Canada. When you use cloud features, your information may be stored or processed in Canada, the United States, or other countries where our service providers (Section 6) operate. Personal information processed or stored in another country is subject to the laws of that country, including lawful access by courts, law enforcement, and national-security authorities. We take reasonable steps, through contractual and technical safeguards, to protect your information wherever it is processed.
8. Data Retention
We keep personal information only as long as needed for the purposes described in this policy, or as required by law:
- On-device data stays on your device until you delete it or uninstall the App.
- Server-side account data (including encrypted backups and Family Hub data) is retained while your account is active and is deleted within 30 days of account closure.
- Anonymised analytics that cannot identify you may be retained for up to 24 months.
You can delete your data at any time via Settings → Danger Zone → Delete Account in the App. Note that deleting your data does not retroactively remove anonymised analytics that can no longer be linked to you, and new anonymised analytics are generated as you continue to use the App unless you turn off the "Share Analytics" toggle in Settings.
9. Analytics & Crash Reporting
Keepli collects a minimal set of anonymised diagnostics to keep the app reliable:
- Usage analytics: Anonymised in-app events such as screen views and feature taps. No vault content, names, or personal identifiers are included.
- Crash reporting: Unhandled exceptions send a diagnostic report to Sentry, including device model, OS version, and a code stack trace. No personal data is included.
Neither stream can identify you or read your vault. You can turn off usage analytics with the "Share Analytics" toggle in Settings.
10. Cookies & Tracking Technologies
The Keepli mobile app does not use cookies. Our website (keepli.app) uses only essential, first-party cookies necessary for site operation. We do not use advertising cookies, cross-site tracking, or third-party analytics cookies. We do not display advertising and do not work with advertising networks that set cookies.
11. Your Rights & Choices
Subject to applicable law, you have the right to:
- Access: Request a copy of the personal information we hold about you, and information about how it has been used and disclosed.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Delete on-device data via Settings → Danger Zone → Delete Account. For server-side deletion, email support@keepli.app with subject "Data Deletion Request".
- Withdraw consent: Turn off any optional feature, or close your account, at any time.
- Opt out of analytics: Disable the "Share Analytics" toggle in Settings.
- Push notifications: Disable via your device's system settings or Settings → Notifications.
To protect your privacy, we may need to verify your identity before acting on a request — typically by confirming the request comes from the email address associated with your account. We will respond within 30 days, and will explain if we need more time or cannot fulfil a request.
Residents of the European Economic Area, the UK, and California have additional rights under the GDPR, UK GDPR, and CCPA respectively, including rights to portability and to object to certain processing.
12. Children & Family Data
Children as users. Keepli is not directed at children under 13 (or under 16 in the EEA), and we do not knowingly collect personal information from children to create their own account. If you believe a child has provided us information, contact us and we will delete it promptly.
Information you store about others. Keepli lets you keep records about your family — for example, a child's care records, medications, or documents. When you add information about another person, you are responsible for having the authority to do so, and that information is treated with the same safeguards as your own. In a Household or Family Hub, content you share is visible to the members you invite; you can remove shared content or members at any time. When you close your account, the server-side data you own is deleted as described in Section 8.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page with an updated "Last updated" date and, where practicable, an in-App notice. Your continued use of Keepli after changes take effect constitutes acceptance of the updated policy.
14. Contact & Complaints
If you have questions, requests, or complaints about your privacy or this policy, please contact our Privacy Officer:
- Keepli Technologies Inc. — Privacy Officer
- Ontario, Canada
- Email: support@keepli.app
We will work with you to resolve any concern. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada, or your provincial or regional privacy regulator.