kept.

Privacy Policy

Last updated 13 August 2026

Private, never shared, never sold, never used to train AI – and never lost.

That sentence is the whole policy in one line. Everything below explains precisely how we keep it, and it is written to be read rather than to be skipped.

Who we are

Kept is operated by Kept Studio, based in Brazil, and Kept Studio is the controller of the personal data described here. You can reach us about anything in this policy, including any request about your own data, at hello@keptdaily.app.

Part one: this website, today

Kept has not launched yet, and this website is deliberately almost inert. As of the date above:

Our hosting provider, Vercel, processes standard server request data such as IP address for the technical purpose of delivering the page and protecting the service against abuse.

Part two: the Kept application, when it launches

The rest of this policy describes the application. It is published in advance so that you can read it before you ever create an account. We will update the date above when the application goes live.

What we collect

We do not collect your name, your address, your phone number, your precise location, your contacts or your health data, because Kept does not need any of them.

Why we process it, and on what legal basis

Where the content of your prayers reveals religious belief, we treat it as sensitive personal data. We process it only to give you the journal you signed up for, on the basis of your explicit consent, given when you create your account, and you may withdraw that consent by deleting your account.

What we never do

Security, and what encryption does and does not mean

Your data travels over encrypted connections and is encrypted at rest on our database provider’s infrastructure. Access to production data is limited to what is necessary to operate the service.

We want to be exact about one thing rather than let a marketing phrase do the work. Kept is not end-to-end encrypted, and we chose that deliberately. End-to-end encryption would mean that a forgotten password destroys your journal permanently, with no way for anyone to recover it. For a product whose central promise is that your prayers are never lost, and whose readers should not lose years of writing because of a changed phone or a forgotten password, that trade-off is the wrong one. So password recovery works normally, which necessarily means we hold the keys. We will never tell you that your data never leaves your device, because it does: that is what makes it recoverable.

Who processes data on our behalf

We use a small number of service providers, each under a data processing agreement and each limited to its stated purpose:

Payments

Purchases are handled by Paddle.com Market Ltd, which acts as the merchant of record and is an independent controller of the payment data it collects. Paddle processes your payment details and your billing information under its own privacy policy. Kept Studio never receives or stores your full card number. We receive only what we need to give you access: that a payment succeeded, which plan it was for, and when it renews.

How long we keep it

Your journal is kept for as long as your account exists, including after a subscription ends. This is intentional: an expired subscription freezes synchronisation and paid content, and it never deletes what you wrote.

When you delete your account, your journal is deleted from our live systems within 30 days and from encrypted backups within 90 days. Records we are required to keep for tax and accounting purposes, such as invoices, are retained for the period the law requires.

Where your data is

Our providers operate internationally, so your data may be processed outside your country, including in the United States and the European Union. Where personal data is transferred out of the European Economic Area or the United Kingdom, it is protected by Standard Contractual Clauses or another lawful transfer mechanism.

Your rights

Wherever you live, you can ask us to do all of the following, and we will do them without charge and without asking you why:

These rights exist under the Brazilian LGPD, the GDPR in the European Economic Area and the United Kingdom, and comparable laws elsewhere, including the right of California residents to know, delete and opt out of sale. We do not sell personal information, so there is nothing to opt out of. Write to hello@keptdaily.app and we will respond within 30 days.

Children

Kept is for adults and accounts require you to be 18 or older. We do not knowingly collect data from children. If you believe a child has given us personal data, write to us and we will delete it.

Changes to this policy

We may update this policy, and the date at the top always shows the current version. If a change materially affects your rights or how your journal is handled, we will tell you by email before it takes effect. The most likely near-term change is the move from part one to part two, when the application launches and analytics begin.

Contact

Kept Studio, hello@keptdaily.app. A real person reads it.