Document
Privacy policy
This policy explains what personal data Keepino processes, why it is needed, where it is stored, and who may receive it. It reflects the service as it operates on 28 July 2026.
At a glance
The public website uses no cookies, analytics scripts, advertising pixels, or profiling. If you join the waiting list, we store your email address, signup time, and signup source for up to 12 months. If you use the app, we store your account email, submitted links and notes, and the Markdown pages created from them on a server in Poland. The connection is encrypted, but the active Markdown files are not separately encrypted at rest, so the data controller has technical access to them. Relevant content is processed by an external generative-AI service to create summaries and connections. Encrypted off-site backups are retained on a rotating schedule. You may request a copy of your data or ask us to delete it at any time.
Data controller
The data controller is Krzysztof Gołatowski, who operates Keepino (“Keepino”, “we”, “us”). For any privacy request or question, contact kgolatowski.prv (at) gmail.com.
Waiting list
- Data and purpose: we store your email address, the time you joined, and a record that the signup came from the landing page. We use this data only to manage the waiting list and send an invitation.
- Legal basis: your consent under Article 6(1)(a) GDPR. You may withdraw it at any time without affecting processing carried out before withdrawal.
- Retention: the entry expires automatically after 12 months. We delete it earlier if you withdraw consent or ask us to do so.
- Storage: the entry is stored in Cloudflare Workers KV, a globally distributed database. It may therefore be processed outside the European Economic Area.
- Request metadata: Keepino does not add your IP address or browser information to the waiting-list record. Cloudflare nevertheless processes standard request data, including IP addresses, to deliver and protect the site.
- No marketing: we do not use the waiting list for newsletters, advertising, or profiling, and we do not sell the data.
Keepino app
- Account and access: Cloudflare Access verifies the email address associated with your invitation. That address determines which vault you may access. User vaults are isolated from one another.
- Content: we process the links and notes you submit and the pages, summaries, connections, search indexes, and briefs created from them. This is necessary to provide the service you requested (Article 6(1)(b) GDPR).
- Active storage: your content is stored as Markdown files in a directory assigned to your account on the controller’s server in Poland. The server is reached through a Cloudflare tunnel and is not exposed directly to the public internet.
- Encryption and access: traffic to the app is encrypted with HTTPS. Active Markdown files are stored in plain text and are not encrypted with a separate per-vault key. The data controller therefore has technical access to them.
- Generative AI services: relevant submissions and vault pages are sent to an external generative-AI service currently provided by Anthropic PBC in the United States. The service processes them to create summaries, connections, and briefs. Anthropic receives both the input and the generated output.
- AI provider retention: Anthropic states that content processed through the account currently used by Keepino is normally retained for 30 days. If the account’s model-improvement setting is enabled, de-identified session data may be retained for up to five years; material flagged for safety review or retained for legal reasons may be kept longer. See Anthropic’s current retention notice.
- Semantic search: the search index is calculated on our server with a local model. Content is not sent to another provider for this purpose.
- Images from cited pages: our server, rather than your device, retrieves preview images. This prevents the publisher from receiving your IP address when you open a card. The image is cached in a directory assigned to your vault.
- On your device: the app stores interface preferences, recently opened items, downloaded content for offline use, and unsent items in an offline queue. Unsent items leave the device only when they are submitted. Logging out clears cached vault content, recent items, and the offline queue. The native iOS app stores its submission key in the system Keychain.
- Security: we process limited technical data where necessary to secure the service and prevent abuse, based on our legitimate interest under Article 6(1)(f) GDPR.
Backups and retention
We keep active app data for as long as your account remains active or until you ask us to delete it. User vaults are included in a daily, encrypted off-site backup stored in Cloudflare R2. The backup schedule retains up to seven daily, eight weekly, and twelve monthly snapshots. As a result, data removed from the active server may remain in an encrypted backup for up to 12 months. Backups are used only for disaster recovery and are not used for routine access. If a backup is restored, we will reapply completed deletion requests.
Service providers and transfers
- Cloudflare, Inc. — hosts the public website, provides the waiting-list database, login gateway, network protection, tunnel to the app server, and R2 backup storage. Cloudflare processes standard request data, including IP addresses, and may process data outside the EEA.
- Anthropic PBC — receives relevant vault content and generated output through its generative-AI service as described above. The service is provided from the United States and data is processed under the terms and privacy settings applicable to the controller’s Anthropic account.
- Apple Inc. — if you use the native iOS version, Apple distributes it through TestFlight and processes tester information under its own terms as a separate data controller.
Cookies and analytics
The public website sets no cookies and uses no client-side analytics, advertising pixels, or profiling. Cloudflare still processes HTTP request data to deliver and secure the site and provides aggregate network statistics, such as visit counts and countries. Keepino does not build visitor-level behavioural profiles from those statistics.
Your rights
Depending on the circumstances and legal basis, you may request access to and a copy of your data, rectification, erasure, restriction of processing, data portability, or object to processing based on legitimate interests. You may withdraw waiting-list consent at any time. Keepino does not make decisions based solely on automated processing that produce legal or similarly significant effects.
Send requests to kgolatowski.prv (at) gmail.com. We may ask for information needed to verify your identity. We respond without undue delay and normally within one month; the GDPR permits an extension of up to two additional months for complex or numerous requests, in which case we will explain the delay.
Deletion
To delete a waiting-list entry or app account, write to kgolatowski.prv (at) gmail.com. After verifying the request, we will remove the waiting-list entry and, where applicable, the account record, active vault, generated indexes, snapshots, and cached preview images without undue delay and no later than 30 days. You may request a copy of your data before deletion. Encrypted backup copies expire under the rotation schedule described above; third-party providers apply their own retention periods.
Children
Keepino is not intended for anyone under 16, and we do not knowingly collect their data. If you believe that a person under 16 has an account, contact us so that we can investigate and remove it.
Changes to this policy
We will publish updates at this address and change the effective date above. If a change materially affects how we process existing user data, we will also notify affected users by email where we have a current address.