Privacy policy
Last updated: August 5, 2026
What Kept does
Kept connects to messaging accounts you explicitly authorize (Slack, and email when you connect it) and reads the conversations you choose in order to find commitments — promises made by you or to you. Access is read-only: Kept never posts, sends, edits, or marks anything read on its own. Messages that Kept drafts on your behalf are sent only after you explicitly approve each one.
What we collect and store
- Account basics — your name, email address, and avatar from the identity provider you sign in with.
- Extracted commitments — a short description, the people involved, dates, and the verbatim quote of the message the commitment came from, with a link to the original thread.
- OAuth tokens — stored encrypted at rest. We never see or store your passwords.
- Coverage settings — which conversations you've asked Kept to read or exclude.
Kept does not store your full message history. Conversations are read transiently to detect commitments; only the quotes that evidence a commitment are kept.
How message content is processed
To detect commitments, conversation excerpts are processed by large-language-model providers acting as our subprocessors (currently Anthropic, Google, and Groq). Excerpts are sent for inference only; we do not permit these providers to train on your content under our API agreements.
What we never do
- We never sell your data or share it with advertisers.
- We never send messages, invites, or notifications to your contacts without your explicit per-message approval.
- We never read conversations outside the coverage you configured.
Retention and deletion
Your data is retained while your account is active. You can export everything Kept holds about you at any time, and you can delete your account in one action — deletion removes your commitments, quotes, settings, and encrypted tokens immediately. Disconnecting a single workspace deletes its tokens while preserving your commitment history.
Security
All traffic is encrypted in transit (TLS). OAuth tokens are encrypted at rest with a key held separately from the database. Access to production systems is limited to the operator of the service.
Contact
Questions or requests (including data export or deletion): support@allkept.ai.