Privacy Policy
Kept ("we", "us") is operated by Fergus Richards trading as Kept, a sole trader based in the United Kingdom. ICO registration number: ZC242499. The quickest way to reach us about anything in this policy is by email: [email protected].
Last updated: 9 September 2026 (v4)
1. What Kept does
Kept monitors whether automated workflows ran when they were supposed to. Your workflows send us a short "ping" when they run. We compare pings against the schedule you set or confirm, and alert you when something is late, missing or failed.
2. What we store, and what we deliberately don't
We store only metadata about your workflows:
- Client names and promise (task) names you enter
- Ping timestamps, status (ok / fail / start), and an optional short message
- Before saving any of these we remove anything that looks like an email address, phone number or access token — from client names, promise names, descriptions and messages alike — and truncate messages to 300 characters
- Alerts we sent you and when
- Schedules, time zones and settings
We never accept or store the data your workflows process — no emails, documents, customer records, invoices or payloads. Pings over 2 KB are rejected.
Your account: email address, sign-in tokens, plan and billing status, API keys (stored as hashes only), and alert channel settings such as a Slack webhook URL (webhook URLs and bot tokens are stored encrypted).
Technical: server logs with IP address, request path and timing, kept for security and debugging — typically no more than 30 days, depending on our hosting providers. Ping URLs carry their token in the path, so those tokens appear in these logs; we treat them as credentials, and you can regenerate a token from the dashboard at any time.
3. Who is responsible for what
For your account details we are the controller.
For the client names, promise names and ping messages you send us, you are the controller and we are your processor. We process that data only to provide the service and on your instructions, as set out in our Data Processing Agreement. Please avoid putting personal details into names and messages unless you need to.
4. Why we process data (lawful bases)
- Providing the service you signed up for — contract
- Sending alerts and account emails — contract
- Security, abuse prevention, rate limiting — legitimate interests
- Billing and tax records — legal obligation
- Product emails about Kept itself (rare) — legitimate interests; unsubscribe any time. We do not send marketing on behalf of anyone else.
5. Who we share it with (sub-processors)
| Provider | Purpose | Location |
|---|---|---|
| Neon | database hosting | EU |
| Railway | application hosting | EU |
| Resend | sending email | EU/US (see Resend's DPA) |
| Stripe | payments, invoices | EU/US, with standard safeguards |
| Cloudflare | DNS, DDoS protection, edge caching | global network; EU data handling under its DPA |
Alerts you configure (email, Slack, Discord, Telegram) are delivered to channels you control. By default an alert contains the client name, promise name, what happened and when, and a link back to Kept — not error details. Once delivered, that content is stored in your own tool under its retention settings, not ours.
We do not sell data or share it with advertisers. If we add a sub-processor we will update this page at least 14 days before it starts handling data.
6. Where data lives
Our application and database run in the EU. Where a provider handles data outside the UK/EU, it does so under the UK International Data Transfer Addendum or EU Standard Contractual Clauses.
7. How long we keep it
- Pings: 90 days, then deleted automatically
- Alerts: 180 days
- Server logs: typically no more than 30 days, depending on our hosting providers
- Account, client and promise data: while your account exists
- Billing records: invoices and payment records are held by Stripe for 6 years for tax purposes, and remain there after you delete your account
- Deleting your account removes Kept's own records — clients, promises, pings, alerts, channels and API keys — immediately. Database backups and restore points are retained for a short period — currently up to 6 hours — and roll off thereafter.
8. Cookies
We set only strictly necessary cookies:
| Cookie | Purpose | Lifetime |
|---|---|---|
authjs.session-token (__Secure- prefixed on https) |
keeps you signed in | 30 days |
authjs.csrf-token, authjs.callback-url |
protect the sign-in form and return you to the right page | session / sign-in |
kept_first_key |
shows your first API key on the first-run card | 7 days |
kept_terms |
records that you ticked the Terms/DPA box at sign-in until it is saved to your account | 30 days |
In production our edge provider, Cloudflare, may set its own strictly necessary security cookie (such as __cf_bm) to tell people from bots. No analytics or advertising cookies, so we don't show a cookie banner. If that changes, we'll ask first.
9. Your rights
You can access, correct, export or delete your data, object to or restrict processing, and complain to the ICO (ico.org.uk). Most of this you can do yourself from the app — Download my data on the Billing page exports your clients, promises, pings, alerts and channels as JSON, and Delete my account removes them; for anything else email [email protected] and we'll respond within one month. If you are a client of one of our customers, please contact them first — they control your data and we act on their instructions.
10. Security
Encryption in transit (TLS) and at rest, hashed API keys, least-privilege access, two-factor authentication on all provider accounts, rate limiting, and automated deletion on schedule. If a breach affects you, we'll tell you without undue delay.
11. Children
Kept is a business tool and not intended for anyone under 18.
12. Changes
We'll post changes here and, for material changes, email account holders.