Kept

Kept Privacy Policy

Effective date: 2026-09-23 Version: 2026-09-23 (replaces 2026-09-22; what changed: photo metadata, including any location, is now removed on your phone before upload — section 1)

Kept is a mobile app in which you set a goal, put money behind it, and prove each check-in with a photo. If you miss a check-in without a valid proof, the stake you chose is charged to the card you saved. To do that, Kept has to handle personal information: your email address, your photos, and the details of a payment card. This policy says what we collect, why, who else touches it, how long we keep it, and what you can ask us to do. It is written to be read, not skimmed. It is short because the app is small.

Kept is operated by Moritz Rechtalski, a sole proprietorship established in Germany, for customers in the United States. Contact: info@keptgoals.com or by post at Weidenweg 11, 17498 Dargelin, Germany. Because the operator is established in Germany, both United States law and the European Union's General Data Protection Regulation (GDPR) apply to how we handle your information; section 12 covers the GDPR specifically.

Kept is for adults. You must be at least 18 years old to create an account (section 10).

1. What we collect

We collect only what the app needs to work. Nothing on this list is bought from anyone or inferred about you from other sources.

InformationWhere it comes fromWhy we need it
Email address and passwordYou, at sign-up. The password is stored only as a one-way hash by our authentication provider; we never see it.Your login; account emails such as confirmation, password reset, and email-change links.
Display name (optional)You, in Settings.To address you in the app.
Time zoneYour phone at sign-up, and you in Settings.Every deadline is set in this zone. A wrong zone would be a wrong deadline.
Goals: title, proof requirement, schedule, stake amount, statusYou, when creating a goal.The service itself: what you committed to, when, and for how much.
Consent record: the mandate text you saw, your drawn signature image, the time, your IP address and device typeYou, on the confirmation step of each goal.Evidence that you agreed to the charge, as card networks require for saved-card payments (section 5).
Terms and Privacy Policy acceptance: which version you accepted and when, your IP address and device typeYou, at sign-up and when a version changes.Evidence of the agreement.
Proof photos and screenshotsYou, at each check-in. Photos come from the live camera; screenshots from your gallery, only for goals that ask for one.To check whether the required situation or object is visible. Before an image leaves your phone, Kept removes the metadata your camera or another app wrote into the file — including any location — and keeps only the picture's orientation. Separately, Kept records when you took the photo and the camera make, model and image size the camera reported, to detect reused or edited images. Kept never asks for your location, and no location is stored with a photo.
Challenge code and image fingerprintGenerated by us for some check-ins.A short code you write into some photos, and a numerical fingerprint of each image, both used only to detect reused images among your own proofs.
Verdicts and review notesGenerated by our image check and by the person who reviews it.To decide whether a check-in counts, and to explain the decision to you.
AppealsYou, when you appeal a decision.To review the decision.
Payment card display data: card brand, last four digits, expiry month and year, and an identifier for the card at our payment processorStripe, after you save a card. The full card number, the security code, and your billing details never reach us; Stripe collects them directly on its own form.To show you which card is on file and to charge it when a check-in is missed.
Charge and refund records: amount, time, outcome, the payment identifier at StripeGenerated when a stake is charged or refunded.Your account history, your receipts, and the records the law requires us to keep.
Push notification tokenYour phone, when you allow notifications.To send reminders, warnings, results, and charge notices to your phone.
Notification historyGenerated by us.The Activity tab in the app.
Server logs and audit trail: which action happened when, from which IP addressGenerated by us.Security, fraud prevention, and accountability for every decision that touches money.
Crash and error reports: device model, operating system version, app version, what went wrong (when error reporting is enabled in a release)Your phone, when the app fails.To find and fix defects.

We do not collect your contacts, your calendar, your precise location (a location your camera writes into a photo is removed on your phone before the photo is uploaded), your health data, your browsing history, or advertising identifiers. We do not use advertising SDKs or analytics that profile you across apps.

2. No face recognition, no biometric data

Kept never uses face recognition or any other biometric identification. We do not create, collect, store, or share biometric identifiers or biometric information: no scans or templates of face geometry, hand geometry, fingerprints, voiceprints, retinas, or irises, and nothing derived from your photos that could identify who is in them.

Proof photos are checked for one thing only: whether the situation or object your goal requires is visible (for example, a gym, an open book, a running track, or the challenge code). The check does not identify people, does not compare people between photos, and does not ask who is in the photo. Our image-check provider's own usage rules prohibit facial recognition, and it receives the image without its metadata (section 1). If you appear in your own photo, that is incidental; we do not analyze you.

This is a design rule of the product, not just a policy statement, and it is not going to change without a new version of this policy.

3. How we use your information

We use your information to:

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use your information for marketing to you unless you ask us to, and there is currently no marketing at all.

Automated decisions. An image-check model produces a first verdict on each proof: pass, fail, or uncertain. An uncertain result always counts as a pass. A high-confidence fail never charges you by itself: it goes to a person who reviews the image and decides. You can appeal any rejection within 24 hours in the app, and a person reads every appeal. In short, money never moves on a machine's decision alone.

4. Who else touches your information

We use a small number of service providers. Each one processes your information only to provide its service to us, under a written contract, and may not use it for its own purposes. None of them is allowed to sell it.

ProviderWhat it does for KeptWhat it receivesWhere
Supabase, Inc.Hosts our database, logins, and file storageEverything in section 1 except full card detailsUnited States (AWS us-east-1)
Stripe, Inc.Saves your card and processes charges and refundsYour card details (entered on Stripe's own form), email address, the charge amounts; Stripe also acts on its own behalf for fraud prevention and its legal dutiesUnited States; Stripe's own privacy policy applies to what it collects directly
Anthropic, PBCChecks proof images for the required situation or objectThe proof image — already without its metadata, section 1 — and the goal's requirement, without your name or email. Anthropic does not use this content to train its models, and deletes API inputs and outputs from its systems within 30 daysUnited States
Expo (650 Industries, Inc.) and Google (Firebase Cloud Messaging)Deliver push notifications to your phoneYour push token and the text of each notification while it is being delivered; Expo does not store the text longer than delivery takesUnited States
Resend, Inc. (when enabled)Sends account emailsYour email address and the email's content, kept for 30 days in delivery logsUnited States
Sentry (Functional Software, Inc.) (when enabled)Collects crash and error reportsDevice and app details and the error; not your email address unless we turn that on, which we have notUnited States
Google PlayDistributes the app and, if a subscription is introduced, handles subscription billingWhat Google Play collects is governed by Google's own terms

We also disclose information when the law requires it, to respond to a valid legal request, to protect the rights and safety of users or the public, or in a dispute about a charge (to Stripe, the card network, or your bank, section 5). If Kept is ever sold or merged, your information would pass to the new operator under this policy, and you would be told before that happens.

5. Payments, saved cards, and disputes

When you create a goal with a stake, Stripe collects your card details on its own screen and saves the card to a customer record for you. We store only what is needed to show you the card and to ask Stripe to charge it: brand, last four digits, expiry, and Stripe's identifiers. We never see or store your full card number.

Charges happen only as described in the Terms of Service: when a check-in is missed without a valid proof, after a person has confirmed it. Each charge is recorded with the consent you gave for that goal.

If you dispute a charge with your bank, we may provide the bank and the card network with the evidence of your agreement and of the missed check-in: the mandate text you saw, your signature image, the time and device of your consent, the goal's schedule, the proof timeline and the review decision, and any appeal. That is what the records in section 7 are for.

You can change or remove your saved card in Settings. Removal is possible when no goal has an open check-in and no charge is being settled; the app tells you which of these still holds it.

6. Notifications

Push notifications are sent through Expo and Google. In Settings you can turn off reminders, missed-check-in warnings, and charge notices individually; results and decisions about your money are always sent, because you need to know them. You can also turn off all notifications in your phone's settings. Turning notifications off does not change any deadline.

7. How long we keep your information

InformationKept for
Account information (email, name, time zone, settings)While your account exists. Deleted with it.
Proof photos and screenshots, and the camera details kept with them (time taken, make, model, image size)While your account exists. Deleted with it. The verdict on each proof is kept as part of the check-in record.
Push tokens and notification historyWhile your account exists, or until the token stops working. Deleted with the account.
Appeal textsWhile your account exists. Deleted with it; the decision is kept.
Saved cardUntil you remove it or delete your account, when it is removed from Stripe as well.
Goals, consent records (mandate text, signature image, time, IP, device), acceptance records, check-in outcomes, charges and refundsAfter deletion these stay without your name or email address, tied to an internal account number, for the period German commercial and tax law sets for business records (currently eight to ten years, depending on the type of record) and for as long as a card dispute can still be raised. They are financial records; the law does not let us delete them on request.
Server logs and audit trailUp to 12 months, then deleted or anonymized; entries that document a charge or refund are kept with the financial records.
Data at our providersStripe keeps transaction records under its own legal duties. Anthropic deletes API inputs within 30 days. Resend keeps delivery logs 30 days. Sentry keeps error reports up to 90 days.

8. Your rights and choices

You can, at any time:

We do not sell or share your personal information, so there is nothing to opt out of in that respect, and we do not process sensitive personal information for any purpose beyond providing the service you asked for. We will never treat you differently for exercising a right.

Residents of California and other U.S. states with privacy laws. Kept is a very small service and does not currently meet the revenue or volume thresholds at which the California Consumer Privacy Act (CCPA/CPRA) or the comparable laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Kentucky, Indiana, and Rhode Island apply to a business. We grant the rights those laws describe anyway: to know, to access, to correct, to delete, to obtain a portable copy, to opt out of sale or sharing (we do none), to limit the use of sensitive information (we do not use it beyond the service), and to be free from discrimination for exercising them. To exercise a right, use the app or write to info@keptgoals.com from your account's email address. We will confirm the request is yours, answer within 45 days, and tell you if we need more time. If we refuse a request, we will say why, and you can ask us to review the refusal by replying to our answer. You may use an authorized agent; we will ask for proof of the authorization and may ask you to confirm it directly.

9. Security

Your information is encrypted in transit and at rest. Photos and signature images are stored in private storage that is never public; the app reads them only through short-lived signed links. Every database table restricts each user to their own rows. Card details are handled by Stripe and never by our servers. Decisions that move money are made on the server, never in the app on your phone, and every one of them is written to an audit trail. No system is perfectly secure; if a breach ever affects your information, we will tell you and the authorities as the law requires.

10. Children

Kept is for adults. You must be 18 or older to create an account, because the service involves a payment card and money at stake. Kept is not directed to children under 13, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we delete it and close the account. If you believe a minor has an account, write to info@keptgoals.com.

11. Where your information is processed

Kept is operated from Germany, and its servers and providers are in the United States. Your information is therefore stored and processed in the United States, and accessed from Germany by the operator. Where the GDPR requires a legal basis for moving information between the European Union and the United States, we rely on the EU–U.S. Data Privacy Framework for providers certified under it and on the European Commission's standard contractual clauses otherwise (section 12).

12. For everyone: your rights under the GDPR

Because the operator is established in Germany, the GDPR applies to Kept's processing of your information even though you are in the United States. This section states what the GDPR requires us to tell you.

Controller. Moritz Rechtalski, Weidenweg 11, 17498 Dargelin, Germany, info@keptgoals.com. Kept has no data protection officer, because it is not required to have one for a service of this size; questions go to the same address.

Purposes and legal bases.

Recipients. The providers in section 4, and public authorities when the law requires it.

Transfers. The providers are in the United States. Transfers rely on the EU–U.S. Data Privacy Framework where a provider is certified under it, and otherwise on the European Commission's standard contractual clauses in our contracts with them. You can ask us for a copy of the relevant clauses.

Retention. Section 7.

Your rights. Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection to processing based on legitimate interests (Art. 21), and withdrawal of consent at any time without affecting earlier processing (Art. 7(3)). Erasure does not extend to the financial records we are legally required to keep (Art. 17(3)(b)). You also have the right to lodge a complaint with a supervisory authority, in particular the data protection authority of the German state where the operator is established: [Name of the competent state data protection authority].

Automated decision-making. The image check described in section 3 produces a first verdict, but no decision with a legal or financial effect on you is taken without a person: a rejection is reviewed by a person before anything is charged, and you can appeal every rejection. If you believe a decision was wrong, use the appeal in the app or write to us.

Is providing information required? Your email address, a password, a time zone, a card, and a signed consent are required to use the service; without them a goal with a stake cannot be created. A display name is optional.

13. Changes to this policy

When this policy changes, the new version gets a new date at the top, and the app asks you to read and accept it before you continue. We keep every earlier version and can tell you which version you accepted and when. If a change would let us use your information in a new way that you would not expect, we will explain the change when we ask for your acceptance.

Version history. 2026-09-23: photo metadata, including any location, is removed on your phone before upload; only the time taken and the camera make, model and image size are kept with a photo (section 1). 2026-09-22: first version.

14. Contact

Moritz Rechtalski Weidenweg 11, 17498 Dargelin, Germany info@keptgoals.com

The operator's details are also published at keptgoals.com/imprint.