Privacy Policy
Last updated 13 August 2026
Private, never shared, never sold, never used to train AI – and never lost.
That sentence is the whole policy in one line. Everything below explains precisely how we keep it, and it is written to be read rather than to be skipped.
Who we are
Kept is operated by Kept Studio, based in Brazil, and Kept Studio is the controller of the personal data described here. You can reach us about anything in this policy, including any request about your own data, at hello@keptdaily.app.
Part one: this website, today
Kept has not launched yet, and this website is deliberately almost inert. As of the date above:
- it sets no cookies of any kind, so there is no cookie banner to dismiss;
- it runs no analytics, no advertising pixel and no third-party tracking script;
- there are no accounts and nothing to log in to;
- the waitlist button simply opens your own email application with a message addressed to us. Nothing is collected by the site itself. If you choose to send that email, we receive your email address and whatever you write, and we use it for one purpose only: to tell you when Kept opens. You can ask us to delete it at any time and we will.
Our hosting provider, Vercel, processes standard server request data such as IP address for the technical purpose of delivering the page and protecting the service against abuse.
Part two: the Kept application, when it launches
The rest of this policy describes the application. It is published in advance so that you can read it before you ever create an account. We will update the date above when the application goes live.
What we collect
- Account data. Your email address, and an authentication credential. If you sign in with Google we receive your email address and basic profile information from Google, never your Google password.
- Your journal. The prayers you write, their titles, categories and dates, whether you marked one as answered, and what you wrote about how it was answered. This is the most personal data Kept holds and it is treated accordingly.
- Subscription status. Whether you have an active plan, which plan, and its renewal date.
- Product usage. Aggregated, product-level information about how the application is used, so that we can find what is broken and what is confusing.
We do not collect your name, your address, your phone number, your precise location, your contacts or your health data, because Kept does not need any of them.
Why we process it, and on what legal basis
- To provide the service you asked for. Storing your journal, keeping it in sync across your devices and giving you access to devotional content. Legal basis: performance of the contract between us.
- To take payment and comply with tax law. Legal basis: contract and legal obligation.
- To keep the service secure and working. Legal basis: our legitimate interest in a service that is not abused and does not lose your data.
- To send you service email such as a trial reminder or a security notice. Legal basis: contract. Marketing email, if we ever send it, is consent-based and unsubscribing is one click.
Where the content of your prayers reveals religious belief, we treat it as sensitive personal data. We process it only to give you the journal you signed up for, on the basis of your explicit consent, given when you create your account, and you may withdraw that consent by deleting your account.
What we never do
- We never sell your data. Not to anyone, for any amount, in any form.
- We never share your prayers. No advertiser, no data broker, no partner receives them.
- We never use your prayers to train artificial intelligence models. Not ours, not anyone else’s. Where Kept offers an AI feature, it works from the theme you type at that moment, and your journal is not part of any training set.
- We never build an advertising profile of you.
Security, and what encryption does and does not mean
Your data travels over encrypted connections and is encrypted at rest on our database provider’s infrastructure. Access to production data is limited to what is necessary to operate the service.
We want to be exact about one thing rather than let a marketing phrase do the work. Kept is not end-to-end encrypted, and we chose that deliberately. End-to-end encryption would mean that a forgotten password destroys your journal permanently, with no way for anyone to recover it. For a product whose central promise is that your prayers are never lost, and whose readers should not lose years of writing because of a changed phone or a forgotten password, that trade-off is the wrong one. So password recovery works normally, which necessarily means we hold the keys. We will never tell you that your data never leaves your device, because it does: that is what makes it recoverable.
Who processes data on our behalf
We use a small number of service providers, each under a data processing agreement and each limited to its stated purpose:
- Vercel, website and application hosting.
- Supabase, database and authentication, where your journal is stored.
- Paddle, payments. See below.
- Resend, transactional email.
- Cloudflare, delivery of devotional audio.
- PostHog, product analytics, used to understand how the application is used and never to profile you for advertising.
Payments
Purchases are handled by Paddle.com Market Ltd, which acts as the merchant of record and is an independent controller of the payment data it collects. Paddle processes your payment details and your billing information under its own privacy policy. Kept Studio never receives or stores your full card number. We receive only what we need to give you access: that a payment succeeded, which plan it was for, and when it renews.
How long we keep it
Your journal is kept for as long as your account exists, including after a subscription ends. This is intentional: an expired subscription freezes synchronisation and paid content, and it never deletes what you wrote.
When you delete your account, your journal is deleted from our live systems within 30 days and from encrypted backups within 90 days. Records we are required to keep for tax and accounting purposes, such as invoices, are retained for the period the law requires.
Where your data is
Our providers operate internationally, so your data may be processed outside your country, including in the United States and the European Union. Where personal data is transferred out of the European Economic Area or the United Kingdom, it is protected by Standard Contractual Clauses or another lawful transfer mechanism.
Your rights
Wherever you live, you can ask us to do all of the following, and we will do them without charge and without asking you why:
- See the personal data we hold about you.
- Correct anything that is wrong.
- Export your journal in a portable file.
- Delete your account and its content.
- Object to or restrict a particular use, or withdraw consent.
- Complain to a regulator. In Brazil that is the ANPD; in the European Economic Area or the United Kingdom, your local data protection authority.
These rights exist under the Brazilian LGPD, the GDPR in the European Economic Area and the United Kingdom, and comparable laws elsewhere, including the right of California residents to know, delete and opt out of sale. We do not sell personal information, so there is nothing to opt out of. Write to hello@keptdaily.app and we will respond within 30 days.
Children
Kept is for adults and accounts require you to be 18 or older. We do not knowingly collect data from children. If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
We may update this policy, and the date at the top always shows the current version. If a change materially affects your rights or how your journal is handled, we will tell you by email before it takes effect. The most likely near-term change is the move from part one to part two, when the application launches and analytics begin.
Contact
Kept Studio, hello@keptdaily.app. A real person reads it.