Privacy Policy

This Privacy Policy explains how Thesis Labs, LLC(“Thesis Labs,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with the Kept applications for iPhone and Mac and the related website at kept.do (together, the “Service”). By creating an account or using the Service, you agree to this Policy. If you do not agree, do not use the Service.

1. Who we are

The Service is operated by Thesis Labs, LLC, the data controller responsible for your information. You can reach us about privacy at privacy@thesis.do. Kept is an identity-first productivity app available for iPhone and Mac.

2. Scope

This Policy applies to information we process when you use the Kept app and our website. It does not apply to third-party products, services, or websites that we do not control, even if you reach them through the Service. The Service is offered “as is” and “as available” (see Section 14).

3. Information we collect

We collect only what we need to provide the Service. The categories below describe what we may collect depending on the features you use.

3.1 Account and identity information

3.2 Content you create

3.3 Health and fitness data (Apple Health)

If you connect Apple Health, we read selected categories you authorize, such as workouts, activity, steps, energy, heart rate, sleep, body mass, body composition, height, date of birth, and biological sex. We request read access only. We sync authorized workout records and daily summaries needed for your insights, not raw, continuous health streams. We never use Health data for advertising or share it for advertising purposes. You can disconnect at any time in the app and in iOS Settings.

3.4 Integrations

3.5 Cloud Agents organizations and company workspaces

If you use Kept Cloud Agents with a company or other organization, we store the organization profile its administrators provide (such as name, description, website, industry, size, timezone, and administrative contact), membership and invitation records (including invited email addresses, roles, access status, and acceptance times), organization policy, connected-service identities and scopes, delegated jobs, run history, approvals, artifacts, and tamper-evident audit events. Raw connector secrets are encrypted in our server-side vault and are not shown again after they are saved. Organization members can see organization information according to their role; owners and administrators can manage profiles, invitations, roles, policy, and connectors, while auditors can access governance evidence and exports.

3.6 Usage, diagnostics, and device information

4. How we use information

5. Artificial intelligence processing

Cloud AI is off when you create an account, and setting up Kept never turns it on. Kept does not send your personal data to a third-party AI provider until you open Settings, review the in-app disclosure, and explicitly choose Allow Cloud AI. If you allow it, Kept may send the information needed for the cloud feature you choose through our server to OpenAI and/or Anthropic, depending on the feature. That information can include capture text; the relevant portions of notes, tasks, goals, calendar context, saved memories, or coaching messages; meal photos and meal descriptions when you ask Kept to analyze food; and health or fitness summaries when you ask for a related plan, briefing, or coaching result. It can also include the assistant context statement you set, relevant saved contact details, and personal Skill instructions or test examples when Kept drafts, evaluates, or runs that Skill for you. If you use Cloud Agents, we also send the selected model provider the objective and operating instructions for a Cloud Agent, the reviewed schemas of tools granted to it, proposed tool-call parameters, and bounded text or structured results returned by an approved MCP call so the agent can continue. A Cloud Agent job may also draw on the context you have given it access to: the notes, saved memories, and calendar entries that its context scope selects are retrieved before the job runs and are included in what we send to the model. Kept records which items were used and why, and you can see that list on the job and exclude items from future runs. Kept executes the MCP request itself; the connected server address and bearer credential are not sent to the AI provider in this execution path. When you grant a Cloud Agent built-in web research or code workspace capabilities, the search queries it issues and the code and data it runs execute inside the model provider's hosted environment, subject to the same processing-only contract.

We do not authorize OpenAI or Anthropic to use your content to train their general models, and we contract for limited, processing-only use. Provider security and abuse-monitoring retention may still apply under their service terms. Some features also use on-device processing. You can turn Cloud AI off at any time in Settings on iPhone or Mac. Turning it off stops future third-party model requests and background AI processing for your account. Account sign-in, synchronization of your Kept items, deterministic features, and basic non-content product analytics continue to use our servers. Capture-text retention is controlled by a separate setting that remains off until you enable it.

We keep operational records of each AI request — such as the provider and model used, token counts, latency, estimated cost, and outcome — to monitor quality, reliability, and cost; these records do not include your content. AI output can be inaccurate; you are responsible for reviewing it.

Connected Google account (Cloud Agents).If you connect a Google account to Cloud Agents, Kept requests read access to Gmail only. Kept does not request the ability to send email, and it does not request the ability to create drafts either: in Google’s authorization model the scope that permits draft creation also permits sending, so Kept declines it rather than hold an ability it does not need. The practical effect is that Google itself refuses a send attempt from this connection, so the limit does not depend on Kept behaving correctly. Anything Kept drafts for you is held in Kept and never placed in your Gmail account. Kept fetches messages at the moment an agent works on them and does not store message bodies: our database schema has no column for them, and what we keep is derived, non-content structure such as message identifiers, participant addresses, subjects, timestamps, content digests (hashes), and short redacted previews. OAuth tokens are stored encrypted in our credential vault. Kept’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Mail you receive necessarily includes content written by your correspondents; Kept processes it solely to provide the Service to you, applies the same non-possession handling to it, and never uses it to train foundation models.

Calibration against your own history (the harvest).To measure how well a Cloud Agent would have handled your past decisions, Kept can replay decisions you already made (for example, how you scheduled events or handled messages) and score the agent’s agreement with what you actually did. The stored record of each replayed decision contains references, timestamps, difficulty labels, and content digests, never the underlying content, which is re-fetched from its source only while the comparison runs. These scores calibrate your own agent’s permissions and are deleted with your account. Agreement measured this way is published to you as a lower bound and is never described as accuracy.

6. How we share information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:

7. Your choices and controls

8. Your privacy rights

8.1 California residents (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to request access to and deletion or correction of your personal information, and to not be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising, and we do not knowingly process the personal information of minors for such purposes. To delete your account and associated personal information, use Delete account in Settings in the Kept app, or contact us at privacy@thesis.do. For other requests, contact the same address. We will verify your request using information associated with your account, and you may use an authorized agent.

8.2 EEA, UK, and Switzerland (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, Thesis Labs, LLC is the controller of your personal data. We process it on the legal bases of performance of our contract with you, your consent (which you may withdraw at any time), our legitimate interests in operating and improving the Service, and compliance with legal obligations. You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. Where we transfer data outside your region, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses. To erase your account data, use Delete account in Settings in the Kept app, or contact privacy@thesis.do. For other rights, contact the same address.

9. Data retention

We keep personal information for as long as your account is active or as needed to provide the Service, and afterward only as required to comply with legal obligations, resolve disputes, enforce our agreements, or support the limited deletion-safety and recordkeeping purposes described below. When you delete your account in the app or we complete a verified deletion request, we delete or de-identify your personal information from our active systems within a commercially reasonable period, typically within 30 days, except where retention is required by law or for the limited records below. Backups are purged on a rolling schedule.

Account deletion removes your Auth identity, profile, notes, tasks, events, habits, meals and meal photos, health summaries we store, memories, captures, imported meeting notes, push device tokens, connected Google Calendar tokens and synced events, MCP agent connections, assistant context, saved assistant contacts, personal Skills and their revisions, test examples, review receipts and content-free candidate signals, bug-report records, and related owner-scoped data. We also remove waitlist rows, beta-access application rows, and creator-program application rows that use the same email address as your account. Operational model-call logs may retain non-identifying metadata after the user id is cleared.

Cloud Agents keep durable, content-free operating records so that agent behavior stays auditable: run events, policy decisions, activity receipts and notification-delivery state, action receipts, the evidence ledger that underlies an agent’s published standing, and replayed-decision records (references and digests, described above). These records are the audit trail itself; they contain identifiers, verdicts, timestamps, and digests rather than your words, and they are deleted with your account. Replayed-decision records also expire on their own retention schedule without account deletion.

On your device, Kept may temporarily keep a content-free deletion recovery receipt containing the account ID and deletion time until local removal is verified. That receipt is removed after cleanup succeeds. A separate content-free deletion-safety marker associated with the account ID may remain on the device so stale app extensions or background work cannot recreate deleted-account data.

On our servers, we retain a one-way hash of the deleted account ID as a deletion-safety marker so requests using credentials issued before deletion cannot recreate account data. The device and server safety markers contain no name, email address, notes, captures, tokens, or other account content and are used only to enforce deletion.

After deletion we may retain a de-identified record of redeemed or applied financial benefits (for example Founding Practice complimentary months or discounts), including amounts, benefit type, status, and store transaction identifiers, without your email, name, or account id. We keep these records only as needed for fraud prevention, tax, accounting, and dispute handling. Deleting your Kept account does not cancel an App Store subscription; manage or cancel subscriptions in your Apple ID settings.

Company workspace records are controlled and retained at the organization level under its configured policy and any applicable legal hold. Deleting an individual account removes that person’s access and personal account data, but does not automatically delete shared organization jobs, artifacts, approvals, or audit history that other members rely on. Where practical, the departing person’s identifier is removed or retained only as needed for security, audit integrity, disputes, or legal obligations.

10. Security

We use technical and organizational measures designed to protect your information, including encryption in transit, encryption at rest, and row-level access controls so users can access only their own data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Staff access. Authorized Kept personnel may access your content when reasonably necessary for support you request, bug triage, incident response, abuse review, or legal process. Direct database access exists as a break-glass procedure limited to named people; it is procedural rather than architectural.

11. International data transfers

We and our service providers may process and store information in the United States and other countries that may have data protection laws different from those in your jurisdiction. Where required, we use appropriate safeguards for these transfers.

12. Children’s privacy

The Service is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact privacy@thesis.do and we will take appropriate steps to delete it.

13. Third-party links and services

The Service may link to or interoperate with third-party products and services. Their privacy practices are governed by their own policies, and we are not responsible for them.

14. Health and informational disclaimer

Kept’s nutrition, fitness, and coaching content is for informational and general wellness purposes only. It is not medical, nutritional, or professional adviceand is not a substitute for consultation with a qualified professional. Do not rely on the Service for medical decisions. The Service and all content are provided “as is” and “as available” without warranties of any kind, to the maximum extent permitted by law.

15. Limitation of liability and governing law

To the maximum extent permitted by applicable law, Thesis Labs, LLC and its officers, members, employees, and agents will not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, profits, or goodwill, arising out of or relating to your use of the Service. This Policy is governed by the laws of the State of California, without regard to its conflict-of-laws rules, and any dispute will be resolved in the state or federal courts located in California, unless applicable law requires otherwise. If any provision of this Policy is found unenforceable, the remaining provisions remain in full effect.

16. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

17. Contact us

Thesis Labs, LLC
Email: privacy@thesis.do
Web: thesis.do