Privacy policy
Last updated: August 10, 2026
Kept reads your conversations to find the promises in them. That is an unusual amount of access to ask for, so this page tries to be specific rather than reassuring: what is read, what is written down, who else sees it, and how to get it all back or destroyed.
What Kept does
Kept connects to messaging accounts you explicitly authorize — Slack, and Gmail if you connect it — and reads the conversations you choose, in order to find commitments: promises made by you or to you. It shows them on a board, and at the end of the day it offers drafts you can send.
Kept's connections are read-only until you ask otherwise. The permission to post is requested separately, the first time you approve a message, and never at sign-up. Kept never posts, sends, edits, reacts, or marks anything as read on its own. Every outgoing message is one you approved.
What Kept reads
- Slack — only the channels and DMs you select. When you pick coverage, Kept lists your conversations using channel names and member counts alone; it does not read a single message before you have chosen. Conversations you exclude are filtered out of both the picker and every scan.
- Gmail — messages in a recent date window, using a read-only scope that cannot send, modify, or delete. Promotions and social mail are skipped.
Kept does not store your message history. Conversations are read, used to detect commitments, and discarded. What persists is described next.
What Kept stores
| Category | What it holds |
|---|---|
| Account | Your email address, name and avatar URL from the provider you sign in with; your timezone, close time and settings. |
| Connections | OAuth tokens, encrypted at rest. The workspace or account label, its identifiers, which conversations you watch, and a position marker per conversation so Kept knows where it left off. |
| Commitments | A short description, direction (owed by you or to you), due date, status, and Kept's confidence score. |
| Quotes | The verbatim sentence a commitment came from, where it was said (channel or thread name), when, and a link to the original message. |
| People | For everyone a commitment involves: name, email address and/or Slack ID, avatar URL, and your per-person settings for how Kept may chase them. |
| Notifications | When someone else moves a promise you are part of: that person's name and an excerpt of what they said. |
| Drafts and sends | Text Kept drafted, the recipient or channel fixed at draft time, whether it sent, and any error. |
| History | What happened to each commitment and when — the receipts and activity trail. |
| Operational | Background job records; scan progress, which can briefly include conversation names and email subject lines; and fingerprints of threads already read, which are hashes, not content. |
Kept stores no passwords. There are none — signing in is an OAuth handshake with Slack or Google.
Other people's messages
This is the part most privacy policies skip, so it gets its own section.
Kept reads group channels and direct messages. That means it reads messages written by colleagues who do not use Kept, have never seen this page, and have agreed to nothing. When one of those messages contains a promise, Kept writes down that person's name — with their email address or Slack ID from your workspace directory — and the sentence they wrote, verbatim, as the evidence behind an item on your board. Those excerpts are sent to the model providers listed below exactly as your own messages are.
Because these people have no account, they cannot export or delete anything themselves. Two things can be done on their behalf:
- You can delete the commitment. Its quotes go with it, immediately.
- They — or you — can write to support@allkept.ai and ask us to remove records that reference them. We will, and we will tell you when it is done.
Kept never contacts these people on its own. It cannot: nothing leaves without your per-message approval, and Kept sends as you, from your account, not from Kept.
Your side of this. Connecting a conversation to Kept means asserting you are allowed to. If you are using Kept with a work account, whether these conversations may be processed by an outside service is often your employer's decision rather than yours. Kept has no way to check that, so it relies on you.
Who else processes your data
Model providers — these receive message excerpts
Detecting commitments and drafting replies is done by large-language-model providers acting as our subprocessors. Kept routes each job to a primary provider and falls back to others when one is unavailable or rate-limited, so any of the following may receive excerpts of your conversations:
| Provider | Used for |
|---|---|
| Anthropic | Primary for filtering, extraction, drafting, and bulk backfill. |
| OpenAI | First fallback for extraction and drafting; fallback for bulk backfill. |
| Google (Gemini) | Fallback for filtering and extraction. |
| Groq | Last-resort fallback. |
Kept uses these providers through their APIs and does not enrol your content in any training programme.
Infrastructure
| Provider | Role |
|---|---|
| Google Cloud | Runs the Kept API; stores container images and secrets. |
| Neon | The Postgres database — where everything in the table above lives. |
| Cloudflare | Serves the web app and this site; DNS; and the waitlist endpoint described below. |
| Sentry | Error reports, when enabled. Configured not to send request bodies or user identifiers. |
| Email provider | Reminder and receipt email, when enabled. Receives your email address and the reminder text. |
Where your data is
Kept's application and database run in a single region on Google Cloud and Neon. The model providers process excerpts on their own infrastructure, which for all four is primarily in the United States.
If you are in the EEA, the UK, or Switzerland, using Kept therefore involves transferring your data outside it.
How long Kept keeps things
- Commitments, quotes, people, drafts and receipts — for as long as your account exists, or until you delete the individual item.
- Scan records, including the progress detail that can contain conversation names — 30 days.
- Background job records — 14 days once completed, 30 days if they failed.
- Thread fingerprints (hashes that stop Kept re-reading the same conversation) — 90 days.
- Deletion record — kept indefinitely. See below; it contains no readable email address.
Backups
Our database provider takes automatic backups. A backup made before you delete your account can still contain your data until it ages out of their retention window, and we cannot selectively erase a row from a backup.
What we can do, and do: when an account is deleted, Kept keeps a record consisting of a keyed hash of your email address and the time — not the address itself, and not anything else about you. If a backup is ever restored, that record is what stops the restored account from quietly coming back to life; Kept recognises it and destroys it again at the next sign-in attempt.
Your controls
- Export — download everything Kept holds about you as JSON, or your commitments as CSV, from Settings. It is the complete contents of your account, minus the encrypted tokens themselves.
- Delete — one action in Settings erases every row: commitments, quotes, people, drafts, receipts, settings and tokens. It also asks Slack and Google to revoke Kept's access. If a provider cannot be reached, Kept tells you so and points you at the page where you can remove it yourself — it will not report a revocation that did not happen.
- Disconnect one source — revokes Kept's access at that provider and deletes the stored token, while keeping the commitments Kept already found.
- Change coverage — add or remove conversations, or exclude them entirely, at any time.
Your rights
Depending on where you live, you may have rights to access, correct, export, delete, or restrict the processing of your personal data, and to object to it. The export and delete controls above are built to satisfy the access, portability and erasure rights directly and immediately. For anything else, write to support@allkept.ai.
Kept does not sell personal information, does not share it for cross-context behavioural advertising, and has no advertising relationships of any kind.
Security
- All traffic is encrypted in transit (TLS). Outbound mail requires STARTTLS and fails rather than falling back to plaintext.
- OAuth tokens are encrypted at rest with a key held outside the database.
- Kept requests the narrowest scopes that work: read-only at connection, write only when you first approve a message.
- Access to production systems is limited to the operator of the service.
The waitlist
If you enter your email address on the Kept home page, it is stored — the address and the time, nothing else — in Cloudflare's key-value store, and used only to send you an invite. To limit abuse, the endpoint counts recent submissions against a hashed form of your IP address; that counter expires within hours and is never attached to your address. Ask support@allkept.ai to remove you and we will.
Cookies and tracking
Kept sets one cookie: the session cookie that keeps you signed in. There are no analytics, no tracking pixels, no advertising tags, and no third-party scripts on this site or in the app — the typeface is served from our own domain rather than a font CDN, precisely so that loading a page does not hand your IP address to anyone else. The app stores a few display preferences (theme, for instance) in your browser; those never leave it.
Changes
Changes are published here with a new date at the top. If a change materially affects what Kept reads or who processes it, we will say so plainly rather than adjusting a sentence quietly.
Contact
Questions, data requests, or a message about a colleague's data: support@allkept.ai.