Privacy Policy
This policy is in two parts. Part I covers this website. Part II covers the Keepiit desktop application. They are separate because the two behave very differently: the website is an ordinary website, and the application is built so that your documents never leave your machine.
Keepiit is operated by [legal entity name and registered address]. For anything in this policy, write to support [at] keepiit [dot] com.
Part I — Website Privacy Notice
This part applies to the Keepiit website. The short version: the site has no user accounts, no advertising, and currently no analytics. We collect personal data in exactly two situations: when you contact us, and when you buy a subscription.
1. Contacting us
The contact form on this site does not submit anything to a server. It opens a pre-filled email in your own mail application, and you decide whether to send it. If you do, we receive what any email contains: your name, your email address, and your message. We use it to reply to you and keep it as ordinary business correspondence.
2. Buying a subscription
When you purchase a Keepiit subscription, we collect and keep:
- Name, email address, and company, to create and manage your subscription, send invoices and renewal notices, and provide support.
- Device identifiers. When you activate the application on a computer, the app sends a one-way hash of that machine’s hardware ID. We use it only to count how many computers are active under one subscription. It is not tied to your browsing, and it reveals nothing about the device’s contents.
- Payment, handled by our payment processor. We never see or store full card numbers.
Billing records are kept as long as tax and accounting law requires. Device identifiers are kept for the life of the subscription and deleted within 30 days after it ends.
3. What we don’t do
- No advertising or tracking cookies. See the Cookies Notice for the one essential item this site stores.
- No analytics today. If we ever introduce analytics, it will be off by default, run only after you opt in through the cookie banner, and this policy and the Cookies Notice will be updated first.
- We do not sell or rent personal data. Ever.
Like every website, this site is delivered by a hosting provider whose servers process connection data (such as your IP address) in standard server logs for security and delivery. We do not use these logs to identify visitors.
4. Legal bases and sharing
Where the GDPR applies, we process subscription data to perform our contract with you (Art. 6(1)(b)), correspondence and security on legitimate interest (Art. 6(1)(f)), and any future analytics only with consent (Art. 6(1)(a)). Data is shared only with the service providers needed to run the business (payment processing, hosting, and email) under data-processing agreements, with professional advisors (lawyers, accountants) where needed to run the business, and with authorities where the law requires it. If Keepiit is ever acquired, merges, or sells its assets, subscription records may be transferred to the successor as part of that transaction, under the same protections as this policy.
5. Security and retention
We use industry-standard technical and organizational measures to protect the data we hold. No system can be guaranteed absolutely secure, so we deliberately keep the amount we hold small: for most users it is a single subscription record. Correspondence and billing records are kept as long as legal, tax, and accounting rules require; after that, they are deleted.
6. International transfers
The service providers we use (payment, hosting, email) may process data outside your country, including outside the EEA. Where that happens, the transfer is covered by recognized safeguards such as adequacy decisions or standard contractual clauses.
7. Marketing
We only send product and renewal emails connected to your subscription. If we ever send marketing email, every message will contain a working unsubscribe link, and opting out never affects your subscription.
Part II — Application Privacy Notice
This part applies to the Keepiit desktop application for Windows and macOS.
The design principle: your documents are processed entirely on your device. Detection, redaction, restoration, OCR, and metadata removal all run locally. There is no Keepiit server in the path, no copy held for processing, and the application contains no telemetry, no analytics, and no crash-reporting service.
1. What never leaves your machine
- Your documents and their content.
- Detection results and everything the engine finds.
- The records linking placeholders back to the original identifiers.
- Anything you type into drafts or the assistant before redaction.
- The app’s diagnostic log. It holds no document content, stays on your device, and is transmitted only if you choose to include it in a bug report (see section 2).
2. What the application does transmit, and when
- License activation and renewal. Your license key and the hashed device identifier described in Part I are sent to our licensing service to activate the app and enforce the seat count of your subscription.
- Update checks. The app periodically asks our release host whether a newer signed version exists. No personal data is sent beyond the standard connection itself.
- One-time engine download. On first setup, the app downloads the encrypted local detection engine after validating your license. After that, detection runs offline.
- AI requests, only when you use them, and only redacted text. The assistant and drafter connect from your machine directly to the AI provider you chose (OpenAI, Anthropic, or Google), using your own API key, under that provider’s terms. By design, only the redacted version of your text is sent: identifiers are replaced with placeholders locally before anything leaves the machine, an automatic check verifies this before each request, and the originals are restored locally when the answer comes back. Keepiit is not in that connection and never sees it.
- Bug reports and feedback, only when you send them. A report contains your description, basic system information, and recent lines of the app’s diagnostic log, which holds no document content. If you choose, you may additionally attach files, including a document that triggered a problem, to help us review it. That is entirely voluntary, never automatic, and nothing is attached unless you explicitly select it. Reports are delivered to our support channel through a third-party messaging service (currently Discord), which processes the report content as our service provider under its own terms. Before attaching any file, consider whether it contains information you would not want transmitted; you can always send a report without attachments, or redact a document with Keepiit first. Reports are used only to diagnose and fix the problem.
3. What the application stores on your device
- Settings and redacted output files.
- Restoration records, kept only within the retention window you choose. The default is the strictest one: deleted when the session ends.
- Assistant conversations, encrypted on disk.
- Your AI provider API keys, encrypted with a key derived from your own device. They are never transmitted to Keepiit.
You can change the retention window, purge stored data, and view or clear the diagnostic log at any time from within the application.
4. Your rights
Depending on where you live, applicable privacy laws (such as the GDPR) may give you the right to access, correct, delete, and receive a copy of the personal data we hold about you, which for most users is just the subscription record described in Part I, and to object to or restrict its processing. You can also lodge a complaint with your supervisory authority. To exercise any of these rights, email support [at] keepiit [dot] com.
Children
Keepiit is a professional tool. We do not offer it to children and do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact us and we will delete it.
Changes to this policy
If this policy changes in a way that matters, we will update the date above. For material changes, we will say so clearly on this site and notify subscribers by email before the change takes effect.