Privacy Policy
Last updated May 2026
Keepsake is a private daily journal. We built it with one principle in mind: your entries are yours, and they stay that way. This policy explains exactly what data we collect, what we do with it, and what we don't do.
What we collect
- Account data — your email address, display name, and timezone preference.
- Journal entries — the text and emotion you log each day, stored securely in our database.
- Authentication data — if you sign in with Google, we receive your email and name from Google. We do not store your Google password.
- Usage data — basic, anonymised analytics (e.g. which features are used). No personal identifiers attached.
What we never do
- We never read your journal entries for any purpose.
- We never use your entries to train AI models.
- We never sell your data to third parties.
- We never show you ads — on any plan.
- We never track you across other websites.
How we use your data
- To provide Keepsake — storing and displaying your entries to you.
- To send transactional emails (password resets, account confirmations). No marketing emails unless you opt in.
- To improve the product using anonymised, aggregated usage patterns only.
Data storage and security
Your data is stored on Supabase (hosted on AWS infrastructure). All data is encrypted at rest and in transit (TLS). Row-level security is enforced at the database level — your entries are only accessible by your account. Passwords are hashed by Supabase Auth and never stored in plaintext.
Data retention
Your data is retained for as long as your account is active. If you delete your account, all entries and profile data are permanently deleted within 30 days. You can export your data at any time before deletion.
Third-party services
- Supabase — database and authentication hosting.
- Vercel — web hosting and edge functions.
- Stripe — payment processing (paid plan). We never see or store your full card details.
- Google — optional OAuth sign-in.
- Apple / Google Play — in-app purchases on mobile.
Your rights
You have the right to access, correct, and delete your data at any time. You can export your entries from Settings, and delete your account entirely from Settings → Danger Zone. To exercise any other right, email us at privacy@keepsake.day.
Cookies
We use only essential cookies — specifically, the session token that keeps you logged in. No tracking or advertising cookies. You can disable cookies in your browser, but the app will not function without the session cookie.
Children's privacy
Keepsake is not directed at children under 13. We do not knowingly collect data from children.
Changes to this policy
We'll notify users by email and update the "Last updated" date at the top before any material changes take effect.
Contact
Questions about privacy? privacy@keepsake.day