Privacy policy

Your reading should remain yours.

This policy explains what Kept processes when you use its iPhone app, public website, account, catalog, capture, Ask, focus, support, and subscription features.

Effective September 20, 2026 · Version 2026-09-20

Information Kept processes

Kept processes only the information needed for the features you choose:

  • Account details such as name, email, internal account ID, sign-in provider, email-verification state, reading preferences, languages, and session records.
  • Your library: exact book editions, cover references, progress, notes, highlights, passages, reflections, voice transcripts, extracted page text, collections, and source relationships.
  • Ask conversations: questions, response-style preferences, bounded conversation context, generated answers, cited sources, attachments you select, and quota records.
  • Media you intentionally capture, retain, or consent to send, including privacy-normalized page images and retained files. Temporary audio used by the submitted iPhone transcription flow remains on the device and is not collected by Kept.
  • Optional Community data such as age-eligibility confirmation, region, policy acceptance, handle, display name, bio, discovery and streak settings, connection state, bounded shared activity, Board and verification events, blocks, reports, appeals, and moderation outcomes.
  • Subscription state from Apple, including product, transaction, entitlement, renewal, and trial status. Kept does not receive your full payment-card number.
  • Support messages and limited security data such as request identifiers, timestamps, pseudonymous rate-limit hashes, and technical edge-request data.

Launch-interest list

When you join through the public Kept website, Kept stores the email address you enter, the page location where you joined, the consent wording version, the time of consent, and whether the address is subscribed or unsubscribed. Joining the list does not create a Kept app account.

Kept uses this record only to send launch and occasional product emails you requested, manage duplicate signups, and respect withdrawal. The address and subscription state are also synchronized with Resend for contact-list and email delivery operations. You can unsubscribe from any list email or contact kais.thedev@gmail.com. The active address remains until you unsubscribe, the list closes, or it is no longer needed. A minimal suppression record may remain so Kept does not contact an address that opted out.

The public website does not currently use advertising trackers or analytics cookies. Ordinary hosting and security systems can still process technical request data needed to deliver and protect the site.

On-device data and permissions

The iPhone app keeps its core reading library in an account-scoped store on the device, protected by iOS file protection. When you are signed in and Kept’s personal-streak service is available for your account, Kept automatically synchronizes an authenticated, owner-scoped copy of library changes and saved reading state with its Cloudflare-hosted service. That account sync is not app-level end-to-end encrypted. Session credentials and the opaque App Store account link use the device-only Keychain.

Camera, microphone, photo-library, speech-recognition, notification, and Live Activity access are requested only when the related feature needs them. You can revoke system permissions in iOS Settings. A selected profile photo is re-encoded to remove embedded metadata and stays in the active private device scope.

A reading-focus Live Activity can show remaining time, focus or break state, and a note cue on the Lock Screen or Dynamic Island. Kept offers controls for this presentation.

Purposes and legal bases

Kept uses information to provide and secure the service, preserve source relationships, find public book metadata, process an action you request, answer questions, maintain context, enforce plan limits, verify purchases, provide support, manage the requested pre-launch list, export or delete data, and prevent abuse.

Where applicable law requires a legal basis, Kept relies on performance of the service contract, your consent for waitlist email and optional external processing, legitimate interests in security and reliability where permitted, and legal obligations. You may withdraw waitlist consent by unsubscribing and optional processing consent in the app; withdrawal does not undo processing already completed.

AI, voice, and photo processing

Provider credentials stay on Kept's server and are not embedded in the iPhone app. Kept requires a signed-in account and the matching purpose-specific permission before private material can be sent for external AI synthesis or page-photo analysis.

An ordinary Ask turn can send the current question, custom response-style instructions, bounded recent context, and only the relevant library excerpts retrieved for that turn. An explicit book-recommendation request can additionally send a bounded profile of up to 30 prioritized books (title, author, reading status, description, and tags) and up to 200 owned title-and-author pairs so the provider can personalize suggestions and avoid duplicates. Kept checks returned recommendations against the full library available for that request. Page processing sends the normalized images you reviewed and the selected task. Kept is not end-to-end encrypted while one of these requested operations is being processed.

Voice transcription in the submitted iPhone release runs on the device. Kept and an external AI provider do not receive the voice recording through that flow. If a future release offers optional server transcription, it will require a separate disclosure and consent before a recording is sent.

Current external service providers and recipients can include Moonshot AI (Kimi) for AI and page understanding. OpenAI is identified for an optional server-transcription capability that is disabled in the submitted iPhone release. Their legal roles, processing locations, retention, training, subprocessor, and transfer terms can differ from Kept's. Do not submit highly sensitive material unless you understand and accept the processing notice shown before the feature is enabled.

Community safety and visibility

Community is optional, restricted to eligible people age 18 or older, and private and non-searchable by default. If you enable discovery, the bounded public profile fields and visibility choices explained in the app can be shown to other eligible members. Kept does not intentionally expose your private library, book titles, passages, notes, photos, recordings, or files through Community.

Kept screens public profile text before publication, applies rate and integrity controls, and lets members report and block other discoverable members. Authorized reviewers can examine the reported profile, the reporter's selected reason and detail, relevant relationship and integrity records, and prior enforcement needed to decide the report or appeal. Blocking and safety restrictions can change discovery, connection, Together, and Board visibility. Reports are not monitored as an emergency service.

Read the Community Guidelines for the conduct, report, block, enforcement, and appeal rules.

Email verification and account recovery

When email access is available, Kept uses the address you provide to verify ownership, deliver time-limited verification and recovery messages, prevent account enumeration, and protect the account. Verification and reset secrets are stored as keyed one-way hashes, expire after 15 minutes, allow only a bounded number of attempts, and become unusable after successful use. A successful password reset revokes existing Kept sessions.

Kept uses Resend (Plus Five Five, Inc.) to deliver these transactional messages. Resend receives the destination address, sender and reply address, message content containing the one-time code, delivery status, and ordinary email-routing metadata. Kept does not send Resend your password, library, passages, notes, photos, recordings, purchases, or access tokens for this purpose.

Services that can receive data

  • Cloudflare: website and service hosting, request protection, waitlist and other D1 structured records, and private R2 objects.
  • Apple: Sign in with Apple, StoreKit subscriptions, purchase verification, device services, and device backups you enable.
  • Google: Google sign-in identity claims when you choose that sign-in method and mailbox delivery when you email Kept support. Google Books catalog and cover fallback is disabled in the public release.
  • Resend: launch-list contact management and requested product email delivery, plus transactional email delivery for account verification and password recovery.
  • Moonshot AI (Kimi): optional Ask, reviewed-text organization, and page-image processing after consent.
  • OpenAI: reserved for optional server voice transcription; disabled in the submitted iPhone release.
  • Open Library / Internet Archive: public title, author, ISBN, edition, and catalog requests. Current clients use exact Open Library cover URLs. A bounded compatibility path can relay exact public cover bytes for older clients without retaining a server-side or R2 copy. The iPhone app and browser can keep ordinary local image caches for performance. Direct requests expose ordinary device network data to Open Library; relayed requests expose the public cover identifier and relay network data. Private notes and reading history are not intentionally included.

Resend's privacy policy is available at resend.com/legal/privacy-policy. These providers may process data outside your country. Kept does not promise a particular national storage location. International transfers remain subject to applicable safeguards and the provider terms disclosed for the enabled service.

Retention and deletion

On-device records remain until you remove them, delete the relevant account space, uninstall the app, or erase the device. Server account and library records generally remain while the account or relevant item exists. Expired email verification and recovery challenges are removed or rendered unusable under the service retention schedule. Recoverable AI-operation results expire after up to seven days and active usage reservations expire after about ten minutes. Support requests submitted through Kept's structured in-app or service form are scheduled to expire after 180 days unless a documented legal hold applies. Direct email is controlled by the sender's and recipient's mailbox providers and is not covered by that automated database cleanup.

You can remove individual items and conversations in the app. You can initiate permanent account deletion in Profile → Account → Delete account. Deleting a Kept account does not cancel an Apple subscription. Limited pseudonymous security, deletion-evidence, Community moderation and appeal, fraud-prevention, tax, or billing records may remain where legally or operationally required.

Read the account deletion guide for the exact steps and support fallback.

Your privacy rights

Depending on where you live, you may request access, correction, deletion, portability, restriction, objection, or withdrawal of consent, and you may complain to your local data-protection authority. Kept will verify requests proportionately before disclosing or changing account data.

Use the controls in the app or email kais.thedev@gmail.com. Do not email book files, passwords, payment details, or private journal text. Kept does not sell personal information, use reading content for behavioral advertising, or include cross-app advertising tracking in the current product.

Age and younger readers

Kept is not adults-only, but a person under 13 may not create or use a Kept account. If local law requires a higher age or valid permission from a parent or guardian, that higher local requirement applies.

Kept does not knowingly build advertising profiles for children. Contact support if you believe a child provided personal information contrary to these requirements.

Security and changes

Kept uses owner-scoped storage, HTTPS-only production configuration, restrictive security headers, request and file validation, rate limits, hashed credentials, protected local files, and authenticated private-object access. No service can guarantee perfect security.

If this policy changes materially, the effective date and version will change and Kept will provide any additional notice or consent required for the affected feature. Questions can be sent to kais.thedev@gmail.com.