KeptBack to Kept ↗

Last updated 10 September 2026

Privacy

Kept was built so that as little as possible leaves your phone. This is the specific, unglamorous account of what does.

Who you are dealing with

Kept is made by Akintade Oluwaseun, trading as Kept, an individual developer based in the United Kingdom. For data protection purposes that means I am the data controller for the small amount of information described here. You can reach me at hello@getkept.xyz.

This policy covers the Kept iPhone app and this website. It does not cover Apple's own services, which are governed by Apple's privacy policy.

What stays on your phone

Most of Kept never touches a server. The following is created and stored on your device, and nothing about it is transmitted to me:

  • Receipt photographs. The image you capture is saved on the device and is never uploaded.
  • Text recognition. Kept reads receipts using Apple's Vision framework, which runs entirely on the device.
  • Your records. Purchases, merchants, totals, coverage dates, return windows, and any notes or edits you make are held in the app's local database.
  • Reminders. Expiry notifications are scheduled locally by iOS. No server knows when your cover ends.

What leaves your phone, and why

Three things need to leave the device for the app to work. Each is limited to what the task actually requires.

Receipt text, so it can be structured

After Vision reads a receipt on your device, Kept sends the recognised lines of text and their positions on the page to its extraction service, which runs on Cloudflare Workers. That service passes the text through Cloudflare AI Gateway to a large language model provider, which returns the structured fields you then confirm: merchant, item, date, total, and a suggested coverage length.

The photograph itself is never sent. Only the text recognised from it travels, and only for as long as the request takes.

Request bodies are not logged at the gateway, and the extraction service writes nothing to storage — the text is held in memory for the length of the request and then discarded. Under the model provider's API terms, requests sent through it are not used to train their models, though the provider may retain a request briefly for its own abuse monitoring.

Receipts can contain more than the thing you bought. If a receipt shows something you would rather not send, you can edit the record by hand instead of running extraction on it.

Wallet pass details, so the pass can be signed

Apple requires that the private key used to sign a Wallet pass never sit inside an app. When you add a purchase to Wallet, Kept sends the merchant, item name, total, currency, purchase date, coverage end date, and a serial number identifying the pass to its signing service, which returns a signed pass. Those fields are processed in memory and are not stored.

Subscription state, so Kept Pro works

Kept Pro is handled by RevenueCat, Inc., which records your purchase and entitlement status against an app user identifier derived from your iCloud account. Apple processes the payment itself — your card details never reach RevenueCat or me. If you turn on iCloud sync as a Pro subscriber, your records sync through your own iCloud private database, which Apple encrypts and which I cannot read.

One technical detail

The extraction and signing services see the IP address your request comes from, because that is how requests are rate limited to thirty per minute. Addresses are used for that check and are not stored, logged against your records, or used to build any profile.

What Kept never does

  • No advertising, and no advertising identifiers.
  • No analytics or telemetry SDKs. Kept does not measure how you use it.
  • No tracking across apps or websites, and no data shared for anyone else's marketing.
  • No selling of personal information, in any form, to anyone.
  • No account. Kept does not ask for your name, email address, or a password.

RevenueCat is the app's only third-party SDK, and it exists solely to handle subscriptions.

The legal basis for processing

Under the UK GDPR, processing needs a lawful basis. Two apply here:

  • Performance of a contract (Article 6(1)(b)) — structuring your receipts, signing Wallet passes, and running your subscription are the service you asked for.
  • Legitimate interests (Article 6(1)(f)) — checking an IP address against a rate limit keeps the service available and resistant to abuse, which is a narrow interest that does not override your rights.

Where your data is processed

Cloudflare and the model provider operate outside the United Kingdom, including in the United States, so receipt text may be processed abroad. Those transfers rely on the safeguards in each provider's data processing agreement, which incorporates the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses. RevenueCat processes subscription data on the same basis.

How long anything is held

  • On your device — until you delete it. Nothing expires on its own.
  • Extraction and pass signing — for the duration of a single request, in memory. Nothing is written to storage.
  • Subscription records — held by RevenueCat while your subscription and its history are relevant, under their retention terms.

To remove everything the app holds, open Settings → Data → Delete all data in Kept. Deleting the app also removes its local database.

Your rights

Under UK data protection law you have the right to access your personal data, to have it corrected or erased, to restrict or object to how it is processed, and to receive it in a portable form.

In practice most of these you can exercise yourself and instantly, because the data is on your device and I hold no copy of it. Kept keeps no account and no identifier that would let me look you up, so for anything held by a processor I may need details from you to locate it. Write to hello@getkept.xyz and I will respond within one month.

If you think your data has been handled improperly you can complain to the Information Commissioner's Office at ico.org.uk. I would rather you raised it with me first, but the route is yours.

Children

Kept is not directed at children under 13 and I do not knowingly collect information from them. If you believe a child has provided personal information through the app, contact me and I will remove what I can.

Changes to this policy

When this policy changes, the date at the top of the page changes with it. If a change materially affects what leaves your device, Kept will tell you inside the app rather than relying on you to re-read this page.

Contact

Questions, corrections, or requests about any of the above go to hello@getkept.xyz.

Kept
PrivacyTermsContact

© 2026 Kept