GuideTrustiPhoneMac

Privacy and your data

What stays on your device, what syncs to your account, what reaches a model provider and when, and how to take it all back.

Kept is built on a simple rule: one choice never quietly authorizes another. Granting calendar access is not a Google connection. Allowing Cloud AI is not permission to share health measurements. Connecting an agent is not permission for it to delete your notes or tasks; the most it can do is archive a goal or a habit, or edit inside a note it may write to. This page says where each kind of information lives.

On your device

Each device keeps an account-scoped cache so Kept opens instantly and works offline: your tasks, notes, habits, goals, events, meals, and plan, plus a durable queue of changes waiting to sync, widget snapshots, and scheduled reminders.

Two things are read on the device and never copied into your account as raw data: Apple Calendar events you did not create in Kept, and Apple Health measurements. Health becomes daily summaries and habit check-ins; Apple events inform your free windows and the assistant's sense of when you are busy.

Widgets, controls, and Shortcuts read a minimized snapshot. They carry no keys of any kind.

In your account

Your tasks, notes, habits and check-ins, goals, events you create, connected Google calendars and their events, meals, workouts, focus sessions, plans, memories, and settings sync through Kept's servers, hosted on Supabase. Every row is scoped to your account and protected by row-level security, so even a bug in a query cannot reach another person's data.

With a model provider

Nothing reaches OpenAI or Anthropic until you choose Allow Cloud AI. When you do, specific features send specific things, all through Kept's server as you. Cloud AI, explained lists every feature and what it sends. Turning Cloud AI off stops all of it.

Raw capture text is used to improve Kept only under a separate opt-in, Help improve Capture, which starts off.

What Kept measures

Kept records product events to keep the app working and to know what is failing: a screen was opened, a capture was committed, a sync was refused with a code. Events carry names and codes, never your content. Kept does not put your content or secrets in a URL, and does not use advertising SDKs or session replay.

Bug reports

A bug report carries your description, the screen you were on, your build and device, and a small pack of non-content facts that help reproduce the state: which modules are on, which rollout switches are on, how many changes were waiting to sync. An optional activity trail, off by default, adds event names and timestamps. Never note bodies, capture text, tokens, health details, or meal contents. Screenshots are attachments you can remove before sending. See Report a bug.

Connected agents

An agent you connect over MCP acts as you, within the permissions you approved, and every call is audited. Agents never see a password or a session token, never receive Health history without a separate permission, and have no delete tools. See Permissions and safety.

Notifications

Kept notifies you about your own briefings, reminders, goals, and agent work, and never about anyone else's. A notification never carries a note body or a task's private details beyond its title. Settings shows whether the system currently allows Kept to notify you.

Take it back

  • Disconnect a Google account, Apple Health, or an agent from Settings at any time.
  • Withdraw Cloud AI and every cloud path stops, on every device.
  • Sign out and the device's copy is cleared.
  • Delete your account and everything personal is removed from the server, from every device, and from the providers Kept connected on your behalf. Records that belong to an organization you worked in may be retained under its policies, and older Apple-created accounts confirm once more with Apple first. See Your account.

The full legal statements are at kept.do/privacy and kept.do/terms.

Did this page help?