Legal
Privacy Policy
Last updated: August 8, 2026
This Privacy Policy explains how Thesis Labs, LLC(“Thesis Labs,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with the Kept applications for iPhone and Mac and the related website at kept.do (together, the “Service”). By creating an account or using the Service, you agree to this Policy. If you do not agree, do not use the Service.
1. Who we are
The Service is operated by Thesis Labs, LLC, the data controller responsible for your information. You can reach us about privacy at privacy@thesis.do. Kept is an identity-first productivity app available for iPhone and Mac.
2. Scope
This Policy applies to information we process when you use the Kept app and our website. It does not apply to third-party products, services, or websites that we do not control, even if you reach them through the Service. The Service is offered “as is” and “as available” (see Section 14).
3. Information we collect
We collect only what we need to provide the Service. The categories below describe what we may collect depending on the features you use.
3.1 Account and identity information
- Account identifiers.An email address and a unique account ID. You can sign in with an email one-time code, a one-click sign-in link emailed to that same address, Sign in with Apple, or Sign in with Google. A sign-in link and a sign-in code are the same one-time credential: whichever you use, it works once and expires, and using one retires the other. If you use Sign in with Apple, Apple may share a name and a relay email at your choice. If you use Google, Google’s sign-in software processes the account and device information needed to authenticate you, including a user identifier and an IP address that may be used to estimate general location for fraud prevention. The embedded Google SDK’s privacy declaration also covers linked phone-number and analytics identifiers; Kept requests only your basic profile and email address, does not request a phone number, and does not request Core Location.
- Profile and identity details you provide. Display name, an optional profile photo (stored in our private cloud storage), your identity statement and goals, life areas, preferences, time zone, and unit settings.
- Optional personal characteristics. Date of birth, biological sex, gender identity, height, body composition, and activity baseline, where you choose to provide them for health and nutrition features.
3.2 Content you create
- Captures and the items they create.Tasks, subtasks, comments, goals, notes (including images you embed), folders, labels, calendar events, habits, focus sessions, mood entries, and saved “memories.” To prevent loss if the app is interrupted while saving, Kept temporarily keeps an account-scoped recovery copy of a pending capture on your device. It is retired after the created item is confirmed and removed during journal cleanup. Retaining the original capture text on our service for routing improvement is optional and off by default; you control that separate retention with the “Store my capture text” setting.
- Meal photos and nutrition data. Photos you take for meal logging, the foods we identify, and estimated macros. Photos are processed for analysis and, if you save the meal, stored in our private cloud storage.
- Assistant personalization and personal Skills. If you use these features, we store the assistant context statement you choose, contact names and email addresses you save or confirm through an invitation, and personal Skill instructions and test examples you approve. We also keep immutable Skill revisions, activation and safety-review status, and content-bound evaluation receipts so an unreviewed edit cannot silently replace a reviewed version. A saved contact is used to help resolve recipients you name; Kept still shows an outward-action confirmation before sending.
3.3 Health and fitness data (Apple Health)
If you connect Apple Health, we read selected categories you authorize, such as workouts, activity, steps, energy, heart rate, sleep, body mass, body composition, height, date of birth, and biological sex. We request read access only. We sync authorized workout records and daily summaries needed for your insights, not raw, continuous health streams. We never use Health data for advertising or share it for advertising purposes. You can disconnect at any time in the app and in iOS Settings.
3.4 Integrations
- Google Calendar (optional).If you connect it, we store OAuth tokens and sync event details (including titles, times, locations, descriptions, and attendee information) so your calendar appears in Kept. Kept can also create, change, or remove an event on a calendar you marked writable when you ask it to. A Cloud Agent can do this only through a per-action approval that shows you the exact event first; after you approve, Kept sends those details to Google Calendar, reads the event back to confirm it matches, and keeps a receipt containing the operation’s identifiers, the outcome, and how to undo it · not the event’s own text, which stays in the approval you were shown. No one is invited by this path.
- Apple Calendar (optional). On iPhone, if you grant full access, Kept can read and display events and can add, update, or remove an event when you direct it to. The Mac integration is read-only. Apple Calendar records are not synced to or persisted as part of your Kept account. If you invoke the cloud assistant on iPhone or Mac after allowing Cloud AI, Kept may transmit a bounded snapshot of relevant calendar names and events through our server to OpenAI or Anthropic for that request, subject to the AI processing terms below.
- Push notifications (optional). If you enable them, we store a device push token to deliver reminders and nudges. For Cloud Agents, Kept also creates a content-free activity receipt when a job needs an approval or clarification, or reaches an outcome. If external Cloud Agent alerts are enabled for your account and deployment, the lock-screen alert uses fixed generic copy and a closed link to the signed-in Work page; it does not contain a job title, objective, approval parameters, artifact content, or a customer-supplied URL. Delivery status is operational metadata and is not treated as evidence that you read the update.
- Customer-configured MCP servers (optional). If you connect a Model Context Protocol server for Cloud Agents, we store its HTTPS address, reported server identity and protocol version, the tool names, descriptions, schemas, and effect hints you select, inspection and availability state, and an encrypted bearer credential if one is required. For an agent call, we store the exact proposed parameters and parameter-bound approval, execution state, bounded response data while the run continues, response digests and sizes, and the resulting action receipt. After you approve a call, Kept sends the approved parameters and, where needed, the bearer credential to that server. The server is a third-party service whose own terms and privacy practices also apply.
- Mac meeting-note import (optional). On Mac, you can choose a folder that Kept watches for new text, Markdown, VTT, and SRT transcript files. macOS grants Kept read-only access to that folder, and the security-scoped bookmark that remembers your choice stays on that Mac. Kept reads newly added supported files and saves their text as notes in your synced account. Turning the watcher off or clearing the folder stops future imports; it does not delete notes you already imported.
3.5 Cloud Agents organizations and company workspaces
If you use Kept Cloud Agents with a company or other organization, we store the organization profile its administrators provide (such as name, description, website, industry, size, timezone, and administrative contact), membership and invitation records (including invited email addresses, roles, access status, and acceptance times), organization policy, connected-service identities and scopes, delegated jobs, run history, approvals, artifacts, and tamper-evident audit events. Raw connector secrets are encrypted in our server-side vault and are not shown again after they are saved. Organization members can see organization information according to their role; owners and administrators can manage profiles, invitations, roles, policy, and connectors, while auditors can access governance evidence and exports.
3.6 Usage, diagnostics, and device information
- First-party analytics. Product events (for example, opening the app or completing a task) with small, non-sensitive properties. These events do not include the raw text of your captures. Assistant quality records contain fixed categories, outcome labels, counts, and identifiers of selected Skills, not the text of your message or the assistant response. We may also retain content-free category signals for up to 90 days to assess whether a repeated workflow could become a useful personal Skill.
- AI feedback you provide. If you rate an AI result — for example, a thumbs-up or thumbs-down on a suggested classification, an insight, a briefing, or a coaching reply — we record that rating and an optional short reason so we can measure and improve the quality of our AI.
- AI operations telemetry. For each AI request, we record technical metadata about the model call — which model ran, token counts, latency, estimated cost, and whether it succeeded — so we can monitor quality, performance, and cost. This operational telemetry does notinclude the content of your captures, messages, or the model’s responses.
- Aggregated product metrics. We combine the usage and diagnostic signals above into aggregate, de-identified metrics — counts, rates, percentiles, and averages — to understand product health on our internal dashboards. These aggregates do not contain your notes, capture text, or other personal content.
- Performance and crash diagnostics. Aggregated crash and performance metadata such as operating system version, app version, and error type, via Apple MetricKit.
- Website analytics. On our website only, our first-party analytics records named page and interaction events, the page path, campaign parameters, an A/B variant, and a pseudonymous session ID. A session cookie lasts 30 minutes; a first-touch attribution cookie (which may include the referring page) lasts up to 90 days; and the A/B variant cookie lasts up to 180 days. If you later submit a waitlist or application form, its email record can be associated with the same session and campaign history so we can understand which outreach worked. We do not load third-party advertising or session-replay scripts on the website at this time.
- Waitlist and campaign signups. If you join the waitlist on one of our signup pages, we collect your email address and basic campaign attribution (such as the page and link you arrived from). If you opt in to our brand-ambassador or creator program, we also collect the Instagram handle and follower range you provide and any optional details you choose to share when applying (such as what you make, where you post, your goals, the tools you use today, and a link to your work), and we use them only to select and contact participants for that program.
- Call bookings. If you book a call with us on one of our scheduling pages (for example an onboarding call), we collect the name and email address you enter, the time you pick, your timezone, and any optional note you add. We use them only to create and run that call: the details become a calendar invitation delivered through Google Calendar, which emails you the invite (and a Google Meet link when one is attached). Booking a call does not add you to marketing lists. The invite includes a private link you can use to cancel, which removes the event and frees the time.
- Bug reports you choose to send. You can report a problem from a shake gesture, Settings, or an in-app button. A report includes the description you write, the category and screen you pick, and technical context needed to investigate the issue — such as app/OS version, device model, network state, locale, your current layout configuration, and which feature flags were on. Attaching an image is optional and always your choice (you can remove it before sending): on iPhone, Kept can include an automatic screenshot of the app screen or a short screen recording; on Mac, you pick an image file, drag one in, or paste one — Kept does not capture your screen automatically. Any image you attach is re-encoded before it uploads, which removes hidden data such as location and device details. Including a recent on-device activity trail (event names and times only — not your notes or captures) is a separate opt-in and stays off unless you turn it on for that report. We use bug reports only to investigate and fix problems.
- Founding Practice (invited members). If you accept the invite-only Founding Practice program, we record your enrollment, the terms and consent versions you accepted, and the campaign facts that qualify benefits: references to your own tasks, events, notes, and captures by identifier and category only, with timestamps. We do not store the titles or contents of those items in campaign, benefit, or messaging records, and we never place them in push notifications, emails, analytics, or logs. Progress and benefit grants are computed from your real product activity, not from analytics events. Optional practice coaching email is a separate opt-in you can turn off at any time; benefit and account receipts are sent as service messages. You can leave the program without losing your base or earned benefits, and you can ask us to review any progress that looks wrong.
4. How we use information
- Provide, maintain, secure, and improve the Service.
- Run the features you request, including routing captures and generating insights.
- Personalize plans, coaching, nutrition, and recommendations.
- Send service messages and, if enabled, reminders and nudges.
- Prevent fraud and abuse and enforce our terms.
- Comply with legal obligations.
5. Artificial intelligence processing
Cloud AI is off when you create an account, and setting up Kept never turns it on. Kept does not send your personal data to a third-party AI provider until you open Settings, review the in-app disclosure, and explicitly choose Allow Cloud AI. If you allow it, Kept may send the information needed for the cloud feature you choose through our server to OpenAI and/or Anthropic, depending on the feature. That information can include capture text; the relevant portions of notes, tasks, goals, calendar context, saved memories, or coaching messages; meal photos and meal descriptions when you ask Kept to analyze food; and health or fitness summaries when you ask for a related plan, briefing, or coaching result. It can also include the assistant context statement you set, relevant saved contact details, and personal Skill instructions or test examples when Kept drafts, evaluates, or runs that Skill for you. If you use Cloud Agents, we also send the selected model provider the objective and operating instructions for a Cloud Agent, the reviewed schemas of tools granted to it, proposed tool-call parameters, and bounded text or structured results returned by an approved MCP call so the agent can continue. A Cloud Agent job may also draw on the context you have given it access to: the notes, saved memories, and calendar entries that its context scope selects are retrieved before the job runs and are included in what we send to the model. Kept records which items were used and why, and you can see that list on the job and exclude items from future runs. Kept executes the MCP request itself; the connected server address and bearer credential are not sent to the AI provider in this execution path. When you grant a Cloud Agent built-in web research or code workspace capabilities, the search queries it issues and the code and data it runs execute inside the model provider's hosted environment, subject to the same processing-only contract.
We do not authorize OpenAI or Anthropic to use your content to train their general models, and we contract for limited, processing-only use. Provider security and abuse-monitoring retention may still apply under their service terms. Some features also use on-device processing. You can turn Cloud AI off at any time in Settings on iPhone or Mac. Turning it off stops future third-party model requests and background AI processing for your account. Account sign-in, synchronization of your Kept items, deterministic features, and basic non-content product analytics continue to use our servers. Capture-text retention is controlled by a separate setting that remains off until you enable it.
We keep operational records of each AI request — such as the provider and model used, token counts, latency, estimated cost, and outcome — to monitor quality, reliability, and cost; these records do not include your content. AI output can be inaccurate; you are responsible for reviewing it.
Connected Google account (Cloud Agents).If you connect a Google account to Cloud Agents, Kept requests read access to Gmail only. Kept does not request the ability to send email, and it does not request the ability to create drafts either: in Google’s authorization model the scope that permits draft creation also permits sending, so Kept declines it rather than hold an ability it does not need. The practical effect is that Google itself refuses a send attempt from this connection, so the limit does not depend on Kept behaving correctly. Anything Kept drafts for you is held in Kept and never placed in your Gmail account. Kept fetches messages at the moment an agent works on them and does not store message bodies: our database schema has no column for them, and what we keep is derived, non-content structure such as message identifiers, participant addresses, subjects, timestamps, content digests (hashes), and short redacted previews. OAuth tokens are stored encrypted in our credential vault. Kept’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Mail you receive necessarily includes content written by your correspondents; Kept processes it solely to provide the Service to you, applies the same non-possession handling to it, and never uses it to train foundation models.
Calibration against your own history (the harvest).To measure how well a Cloud Agent would have handled your past decisions, Kept can replay decisions you already made (for example, how you scheduled events or handled messages) and score the agent’s agreement with what you actually did. The stored record of each replayed decision contains references, timestamps, difficulty labels, and content digests, never the underlying content, which is re-fetched from its source only while the comparison runs. These scores calibrate your own agent’s permissions and are deleted with your account. Agreement measured this way is published to you as a lower bound and is never described as accuracy.
6. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:
- Service providers (sub-processors) who process data on our behalf under contract, including:
- Supabase · database, authentication, and file storage.
- Vercel · application hosting and our API.
- OpenAI and Anthropic · optional AI processing of the content described above, only after you explicitly allow Cloud AI.
- Apple · sign-in and push notification delivery (APNs).
- Google · sign-in and Google Calendar synchronization, if you connect them.
- Resend · delivery of sign-in and account emails.
- USDA FoodData Central and Open Food Facts · food and nutrition lookups (search terms only; no account identifiers).
- Legal and safety. When we believe disclosure is required by law or necessary to protect rights, safety, or the integrity of the Service.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
- With your direction. When you choose to share or connect a third-party service.
7. Your choices and controls
- Turn capture-text storage on or off in Settings.
- Allow or turn off Cloud AI in Settings, under Privacy. Turning it off stops future OpenAI and Anthropic processing and background AI reflection. Your account, synced Kept items, deterministic features, and basic non-content product events still use our servers.
- Manage or disable push notifications in the app and iOS Settings.
- Connect or disconnect Apple Health and Google Calendar at any time.
- Revoke a customer-configured MCP connection to disable its credential and dependent agent tools. You can inspect and repair a connection before granting changed tools again.
- Ask Kept to “forget” saved memories.
- Edit or clear your assistant context, remove saved assistant contacts, and pause, edit, or delete personal Skills from the controls available in the Kept app. A Skill edit remains pending until the revised version passes its required review.
- Delete your account in Settings in the Kept iOS or Mac app. Deletion is permanent and removes your account and associated personal data from our active systems as described in Section 9. You can also email privacy@thesis.do to request access, correction, or deletion if you cannot use the in-app control.
8. Your privacy rights
8.1 California residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to request access to and deletion or correction of your personal information, and to not be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising, and we do not knowingly process the personal information of minors for such purposes. To delete your account and associated personal information, use Delete account in Settings in the Kept app, or contact us at privacy@thesis.do. For other requests, contact the same address. We will verify your request using information associated with your account, and you may use an authorized agent.
8.2 EEA, UK, and Switzerland (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, Thesis Labs, LLC is the controller of your personal data. We process it on the legal bases of performance of our contract with you, your consent (which you may withdraw at any time), our legitimate interests in operating and improving the Service, and compliance with legal obligations. You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. Where we transfer data outside your region, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses. To erase your account data, use Delete account in Settings in the Kept app, or contact privacy@thesis.do. For other rights, contact the same address.
9. Data retention
We keep personal information for as long as your account is active or as needed to provide the Service, and afterward only as required to comply with legal obligations, resolve disputes, enforce our agreements, or support the limited deletion-safety and recordkeeping purposes described below. When you delete your account in the app or we complete a verified deletion request, we delete or de-identify your personal information from our active systems within a commercially reasonable period, typically within 30 days, except where retention is required by law or for the limited records below. Backups are purged on a rolling schedule.
Account deletion removes your Auth identity, profile, notes, tasks, events, habits, meals and meal photos, health summaries we store, memories, captures, imported meeting notes, push device tokens, connected Google Calendar tokens and synced events, MCP agent connections, assistant context, saved assistant contacts, personal Skills and their revisions, test examples, review receipts and content-free candidate signals, bug-report records, and related owner-scoped data. We also remove waitlist rows, beta-access application rows, and creator-program application rows that use the same email address as your account. Operational model-call logs may retain non-identifying metadata after the user id is cleared.
Cloud Agents keep durable, content-free operating records so that agent behavior stays auditable: run events, policy decisions, activity receipts and notification-delivery state, action receipts, the evidence ledger that underlies an agent’s published standing, and replayed-decision records (references and digests, described above). These records are the audit trail itself; they contain identifiers, verdicts, timestamps, and digests rather than your words, and they are deleted with your account. Replayed-decision records also expire on their own retention schedule without account deletion.
On your device, Kept may temporarily keep a content-free deletion recovery receipt containing the account ID and deletion time until local removal is verified. That receipt is removed after cleanup succeeds. A separate content-free deletion-safety marker associated with the account ID may remain on the device so stale app extensions or background work cannot recreate deleted-account data.
On our servers, we retain a one-way hash of the deleted account ID as a deletion-safety marker so requests using credentials issued before deletion cannot recreate account data. The device and server safety markers contain no name, email address, notes, captures, tokens, or other account content and are used only to enforce deletion.
After deletion we may retain a de-identified record of redeemed or applied financial benefits (for example Founding Practice complimentary months or discounts), including amounts, benefit type, status, and store transaction identifiers, without your email, name, or account id. We keep these records only as needed for fraud prevention, tax, accounting, and dispute handling. Deleting your Kept account does not cancel an App Store subscription; manage or cancel subscriptions in your Apple ID settings.
Company workspace records are controlled and retained at the organization level under its configured policy and any applicable legal hold. Deleting an individual account removes that person’s access and personal account data, but does not automatically delete shared organization jobs, artifacts, approvals, or audit history that other members rely on. Where practical, the departing person’s identifier is removed or retained only as needed for security, audit integrity, disputes, or legal obligations.
10. Security
We use technical and organizational measures designed to protect your information, including encryption in transit, encryption at rest, and row-level access controls so users can access only their own data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Staff access. Authorized Kept personnel may access your content when reasonably necessary for support you request, bug triage, incident response, abuse review, or legal process. Direct database access exists as a break-glass procedure limited to named people; it is procedural rather than architectural.
11. International data transfers
We and our service providers may process and store information in the United States and other countries that may have data protection laws different from those in your jurisdiction. Where required, we use appropriate safeguards for these transfers.
12. Children’s privacy
The Service is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact privacy@thesis.do and we will take appropriate steps to delete it.
13. Third-party links and services
The Service may link to or interoperate with third-party products and services. Their privacy practices are governed by their own policies, and we are not responsible for them.
14. Health and informational disclaimer
Kept’s nutrition, fitness, and coaching content is for informational and general wellness purposes only. It is not medical, nutritional, or professional adviceand is not a substitute for consultation with a qualified professional. Do not rely on the Service for medical decisions. The Service and all content are provided “as is” and “as available” without warranties of any kind, to the maximum extent permitted by law.
15. Limitation of liability and governing law
To the maximum extent permitted by applicable law, Thesis Labs, LLC and its officers, members, employees, and agents will not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, profits, or goodwill, arising out of or relating to your use of the Service. This Policy is governed by the laws of the State of California, without regard to its conflict-of-laws rules, and any dispute will be resolved in the state or federal courts located in California, unless applicable law requires otherwise. If any provision of this Policy is found unenforceable, the remaining provisions remain in full effect.
16. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
17. Contact us
Thesis Labs, LLC
Email: privacy@thesis.do
Web: thesis.do