KEPT

Privacy policy

Last updated: August 10, 2026

Kept reads your conversations to find the promises in them. That is an unusual amount of access to ask for, so this page tries to be specific rather than reassuring: what is read, what is written down, who else sees it, and how to get it all back or destroyed.

What Kept does

Kept connects to messaging accounts you explicitly authorize — Slack, and Gmail if you connect it — and reads the conversations you choose, in order to find commitments: promises made by you or to you. It shows them on a board, and at the end of the day it offers drafts you can send.

Kept's connections are read-only until you ask otherwise. The permission to post is requested separately, the first time you approve a message, and never at sign-up. Kept never posts, sends, edits, reacts, or marks anything as read on its own. Every outgoing message is one you approved.

What Kept reads

Kept does not store your message history. Conversations are read, used to detect commitments, and discarded. What persists is described next.

What Kept stores

CategoryWhat it holds
AccountYour email address, name and avatar URL from the provider you sign in with; your timezone, close time and settings.
ConnectionsOAuth tokens, encrypted at rest. The workspace or account label, its identifiers, which conversations you watch, and a position marker per conversation so Kept knows where it left off.
CommitmentsA short description, direction (owed by you or to you), due date, status, and Kept's confidence score.
QuotesThe verbatim sentence a commitment came from, where it was said (channel or thread name), when, and a link to the original message.
PeopleFor everyone a commitment involves: name, email address and/or Slack ID, avatar URL, and your per-person settings for how Kept may chase them.
NotificationsWhen someone else moves a promise you are part of: that person's name and an excerpt of what they said.
Drafts and sendsText Kept drafted, the recipient or channel fixed at draft time, whether it sent, and any error.
HistoryWhat happened to each commitment and when — the receipts and activity trail.
OperationalBackground job records; scan progress, which can briefly include conversation names and email subject lines; and fingerprints of threads already read, which are hashes, not content.

Kept stores no passwords. There are none — signing in is an OAuth handshake with Slack or Google.

Other people's messages

This is the part most privacy policies skip, so it gets its own section.

Kept reads group channels and direct messages. That means it reads messages written by colleagues who do not use Kept, have never seen this page, and have agreed to nothing. When one of those messages contains a promise, Kept writes down that person's name — with their email address or Slack ID from your workspace directory — and the sentence they wrote, verbatim, as the evidence behind an item on your board. Those excerpts are sent to the model providers listed below exactly as your own messages are.

Because these people have no account, they cannot export or delete anything themselves. Two things can be done on their behalf:

Kept never contacts these people on its own. It cannot: nothing leaves without your per-message approval, and Kept sends as you, from your account, not from Kept.

Your side of this. Connecting a conversation to Kept means asserting you are allowed to. If you are using Kept with a work account, whether these conversations may be processed by an outside service is often your employer's decision rather than yours. Kept has no way to check that, so it relies on you.

Who else processes your data

Model providers — these receive message excerpts

Detecting commitments and drafting replies is done by large-language-model providers acting as our subprocessors. Kept routes each job to a primary provider and falls back to others when one is unavailable or rate-limited, so any of the following may receive excerpts of your conversations:

ProviderUsed for
AnthropicPrimary for filtering, extraction, drafting, and bulk backfill.
OpenAIFirst fallback for extraction and drafting; fallback for bulk backfill.
Google (Gemini)Fallback for filtering and extraction.
GroqLast-resort fallback.

Kept uses these providers through their APIs and does not enrol your content in any training programme.

Infrastructure

ProviderRole
Google CloudRuns the Kept API; stores container images and secrets.
NeonThe Postgres database — where everything in the table above lives.
CloudflareServes the web app and this site; DNS; and the waitlist endpoint described below.
SentryError reports, when enabled. Configured not to send request bodies or user identifiers.
Email providerReminder and receipt email, when enabled. Receives your email address and the reminder text.

Where your data is

Kept's application and database run in a single region on Google Cloud and Neon. The model providers process excerpts on their own infrastructure, which for all four is primarily in the United States.

If you are in the EEA, the UK, or Switzerland, using Kept therefore involves transferring your data outside it.

How long Kept keeps things

Backups

Our database provider takes automatic backups. A backup made before you delete your account can still contain your data until it ages out of their retention window, and we cannot selectively erase a row from a backup.

What we can do, and do: when an account is deleted, Kept keeps a record consisting of a keyed hash of your email address and the time — not the address itself, and not anything else about you. If a backup is ever restored, that record is what stops the restored account from quietly coming back to life; Kept recognises it and destroys it again at the next sign-in attempt.

Your controls

Your rights

Depending on where you live, you may have rights to access, correct, export, delete, or restrict the processing of your personal data, and to object to it. The export and delete controls above are built to satisfy the access, portability and erasure rights directly and immediately. For anything else, write to support@allkept.ai.

Kept does not sell personal information, does not share it for cross-context behavioural advertising, and has no advertising relationships of any kind.

Security

The waitlist

If you enter your email address on the Kept home page, it is stored — the address and the time, nothing else — in Cloudflare's key-value store, and used only to send you an invite. To limit abuse, the endpoint counts recent submissions against a hashed form of your IP address; that counter expires within hours and is never attached to your address. Ask support@allkept.ai to remove you and we will.

Cookies and tracking

Kept sets one cookie: the session cookie that keeps you signed in. There are no analytics, no tracking pixels, no advertising tags, and no third-party scripts on this site or in the app — the typeface is served from our own domain rather than a font CDN, precisely so that loading a page does not hand your IP address to anyone else. The app stores a few display preferences (theme, for instance) in your browser; those never leave it.

Changes

Changes are published here with a new date at the top. If a change materially affects what Kept reads or who processes it, we will say so plainly rather than adjusting a sentence quietly.

Contact

Questions, data requests, or a message about a colleague's data: support@allkept.ai.