Kept Privacy Policy
Effective date: 2026-09-23 Version: 2026-09-23 (replaces 2026-09-22; what changed: photo metadata, including any location, is now removed on your phone before upload — section 1)
Kept is a mobile app in which you set a goal, put money behind it, and prove each check-in with a photo. If you miss a check-in without a valid proof, the stake you chose is charged to the card you saved. To do that, Kept has to handle personal information: your email address, your photos, and the details of a payment card. This policy says what we collect, why, who else touches it, how long we keep it, and what you can ask us to do. It is written to be read, not skimmed. It is short because the app is small.
Kept is operated by Moritz Rechtalski, a sole proprietorship established in Germany, for customers in the United States. Contact: info@keptgoals.com or by post at Weidenweg 11, 17498 Dargelin, Germany. Because the operator is established in Germany, both United States law and the European Union's General Data Protection Regulation (GDPR) apply to how we handle your information; section 12 covers the GDPR specifically.
Kept is for adults. You must be at least 18 years old to create an account (section 10).
1. What we collect
We collect only what the app needs to work. Nothing on this list is bought from anyone or inferred about you from other sources.
| Information | Where it comes from | Why we need it |
|---|---|---|
| Email address and password | You, at sign-up. The password is stored only as a one-way hash by our authentication provider; we never see it. | Your login; account emails such as confirmation, password reset, and email-change links. |
| Display name (optional) | You, in Settings. | To address you in the app. |
| Time zone | Your phone at sign-up, and you in Settings. | Every deadline is set in this zone. A wrong zone would be a wrong deadline. |
| Goals: title, proof requirement, schedule, stake amount, status | You, when creating a goal. | The service itself: what you committed to, when, and for how much. |
| Consent record: the mandate text you saw, your drawn signature image, the time, your IP address and device type | You, on the confirmation step of each goal. | Evidence that you agreed to the charge, as card networks require for saved-card payments (section 5). |
| Terms and Privacy Policy acceptance: which version you accepted and when, your IP address and device type | You, at sign-up and when a version changes. | Evidence of the agreement. |
| Proof photos and screenshots | You, at each check-in. Photos come from the live camera; screenshots from your gallery, only for goals that ask for one. | To check whether the required situation or object is visible. Before an image leaves your phone, Kept removes the metadata your camera or another app wrote into the file — including any location — and keeps only the picture's orientation. Separately, Kept records when you took the photo and the camera make, model and image size the camera reported, to detect reused or edited images. Kept never asks for your location, and no location is stored with a photo. |
| Challenge code and image fingerprint | Generated by us for some check-ins. | A short code you write into some photos, and a numerical fingerprint of each image, both used only to detect reused images among your own proofs. |
| Verdicts and review notes | Generated by our image check and by the person who reviews it. | To decide whether a check-in counts, and to explain the decision to you. |
| Appeals | You, when you appeal a decision. | To review the decision. |
| Payment card display data: card brand, last four digits, expiry month and year, and an identifier for the card at our payment processor | Stripe, after you save a card. The full card number, the security code, and your billing details never reach us; Stripe collects them directly on its own form. | To show you which card is on file and to charge it when a check-in is missed. |
| Charge and refund records: amount, time, outcome, the payment identifier at Stripe | Generated when a stake is charged or refunded. | Your account history, your receipts, and the records the law requires us to keep. |
| Push notification token | Your phone, when you allow notifications. | To send reminders, warnings, results, and charge notices to your phone. |
| Notification history | Generated by us. | The Activity tab in the app. |
| Server logs and audit trail: which action happened when, from which IP address | Generated by us. | Security, fraud prevention, and accountability for every decision that touches money. |
| Crash and error reports: device model, operating system version, app version, what went wrong (when error reporting is enabled in a release) | Your phone, when the app fails. | To find and fix defects. |
We do not collect your contacts, your calendar, your precise location (a location your camera writes into a photo is removed on your phone before the photo is uploaded), your health data, your browsing history, or advertising identifiers. We do not use advertising SDKs or analytics that profile you across apps.
2. No face recognition, no biometric data
Kept never uses face recognition or any other biometric identification. We do not create, collect, store, or share biometric identifiers or biometric information: no scans or templates of face geometry, hand geometry, fingerprints, voiceprints, retinas, or irises, and nothing derived from your photos that could identify who is in them.
Proof photos are checked for one thing only: whether the situation or object your goal requires is visible (for example, a gym, an open book, a running track, or the challenge code). The check does not identify people, does not compare people between photos, and does not ask who is in the photo. Our image-check provider's own usage rules prohibit facial recognition, and it receives the image without its metadata (section 1). If you appear in your own photo, that is incidental; we do not analyze you.
This is a design rule of the product, not just a policy statement, and it is not going to change without a new version of this policy.
3. How we use your information
We use your information to:
- run the service: create goals, send reminders, receive proofs, decide check-ins, charge and refund stakes, answer appeals;
- keep the service secure and detect fraud, including reused or edited proof images;
- keep the records the law and the card networks require (section 7);
- send you account emails (confirmation, password reset, email change, receipts) and, in a later version, receipts and account notices;
- find and fix defects.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use your information for marketing to you unless you ask us to, and there is currently no marketing at all.
Automated decisions. An image-check model produces a first verdict on each proof: pass, fail, or uncertain. An uncertain result always counts as a pass. A high-confidence fail never charges you by itself: it goes to a person who reviews the image and decides. You can appeal any rejection within 24 hours in the app, and a person reads every appeal. In short, money never moves on a machine's decision alone.
4. Who else touches your information
We use a small number of service providers. Each one processes your information only to provide its service to us, under a written contract, and may not use it for its own purposes. None of them is allowed to sell it.
| Provider | What it does for Kept | What it receives | Where |
|---|---|---|---|
| Supabase, Inc. | Hosts our database, logins, and file storage | Everything in section 1 except full card details | United States (AWS us-east-1) |
| Stripe, Inc. | Saves your card and processes charges and refunds | Your card details (entered on Stripe's own form), email address, the charge amounts; Stripe also acts on its own behalf for fraud prevention and its legal duties | United States; Stripe's own privacy policy applies to what it collects directly |
| Anthropic, PBC | Checks proof images for the required situation or object | The proof image — already without its metadata, section 1 — and the goal's requirement, without your name or email. Anthropic does not use this content to train its models, and deletes API inputs and outputs from its systems within 30 days | United States |
| Expo (650 Industries, Inc.) and Google (Firebase Cloud Messaging) | Deliver push notifications to your phone | Your push token and the text of each notification while it is being delivered; Expo does not store the text longer than delivery takes | United States |
| Resend, Inc. (when enabled) | Sends account emails | Your email address and the email's content, kept for 30 days in delivery logs | United States |
| Sentry (Functional Software, Inc.) (when enabled) | Collects crash and error reports | Device and app details and the error; not your email address unless we turn that on, which we have not | United States |
| Google Play | Distributes the app and, if a subscription is introduced, handles subscription billing | What Google Play collects is governed by Google's own terms | — |
We also disclose information when the law requires it, to respond to a valid legal request, to protect the rights and safety of users or the public, or in a dispute about a charge (to Stripe, the card network, or your bank, section 5). If Kept is ever sold or merged, your information would pass to the new operator under this policy, and you would be told before that happens.
5. Payments, saved cards, and disputes
When you create a goal with a stake, Stripe collects your card details on its own screen and saves the card to a customer record for you. We store only what is needed to show you the card and to ask Stripe to charge it: brand, last four digits, expiry, and Stripe's identifiers. We never see or store your full card number.
Charges happen only as described in the Terms of Service: when a check-in is missed without a valid proof, after a person has confirmed it. Each charge is recorded with the consent you gave for that goal.
If you dispute a charge with your bank, we may provide the bank and the card network with the evidence of your agreement and of the missed check-in: the mandate text you saw, your signature image, the time and device of your consent, the goal's schedule, the proof timeline and the review decision, and any appeal. That is what the records in section 7 are for.
You can change or remove your saved card in Settings. Removal is possible when no goal has an open check-in and no charge is being settled; the app tells you which of these still holds it.
6. Notifications
Push notifications are sent through Expo and Google. In Settings you can turn off reminders, missed-check-in warnings, and charge notices individually; results and decisions about your money are always sent, because you need to know them. You can also turn off all notifications in your phone's settings. Turning notifications off does not change any deadline.
7. How long we keep your information
| Information | Kept for |
|---|---|
| Account information (email, name, time zone, settings) | While your account exists. Deleted with it. |
| Proof photos and screenshots, and the camera details kept with them (time taken, make, model, image size) | While your account exists. Deleted with it. The verdict on each proof is kept as part of the check-in record. |
| Push tokens and notification history | While your account exists, or until the token stops working. Deleted with the account. |
| Appeal texts | While your account exists. Deleted with it; the decision is kept. |
| Saved card | Until you remove it or delete your account, when it is removed from Stripe as well. |
| Goals, consent records (mandate text, signature image, time, IP, device), acceptance records, check-in outcomes, charges and refunds | After deletion these stay without your name or email address, tied to an internal account number, for the period German commercial and tax law sets for business records (currently eight to ten years, depending on the type of record) and for as long as a card dispute can still be raised. They are financial records; the law does not let us delete them on request. |
| Server logs and audit trail | Up to 12 months, then deleted or anonymized; entries that document a charge or refund are kept with the financial records. |
| Data at our providers | Stripe keeps transaction records under its own legal duties. Anthropic deletes API inputs within 30 days. Resend keeps delivery logs 30 days. Sentry keeps error reports up to 90 days. |
8. Your rights and choices
You can, at any time:
- see and correct your information: your email, name, time zone, goals, check-ins, and card display data are all visible in the app, and most can be changed there;
- get a copy of your information: write to us and we will send you a copy of what we hold about you in a readable format;
- delete your account in Settings, or by email if you no longer have the app (see keptgoals.com/delete-account). Deletion removes everything in section 1 except the financial records described in section 7, which are kept without your name;
- withdraw the permission to charge your card by removing the card or cancelling your goals — check-ins already missed remain payable, as the Terms explain;
- turn notifications off in Settings or on your phone;
- object to a decision about a check-in by appealing it in the app within 24 hours.
We do not sell or share your personal information, so there is nothing to opt out of in that respect, and we do not process sensitive personal information for any purpose beyond providing the service you asked for. We will never treat you differently for exercising a right.
Residents of California and other U.S. states with privacy laws. Kept is a very small service and does not currently meet the revenue or volume thresholds at which the California Consumer Privacy Act (CCPA/CPRA) or the comparable laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Kentucky, Indiana, and Rhode Island apply to a business. We grant the rights those laws describe anyway: to know, to access, to correct, to delete, to obtain a portable copy, to opt out of sale or sharing (we do none), to limit the use of sensitive information (we do not use it beyond the service), and to be free from discrimination for exercising them. To exercise a right, use the app or write to info@keptgoals.com from your account's email address. We will confirm the request is yours, answer within 45 days, and tell you if we need more time. If we refuse a request, we will say why, and you can ask us to review the refusal by replying to our answer. You may use an authorized agent; we will ask for proof of the authorization and may ask you to confirm it directly.
9. Security
Your information is encrypted in transit and at rest. Photos and signature images are stored in private storage that is never public; the app reads them only through short-lived signed links. Every database table restricts each user to their own rows. Card details are handled by Stripe and never by our servers. Decisions that move money are made on the server, never in the app on your phone, and every one of them is written to an audit trail. No system is perfectly secure; if a breach ever affects your information, we will tell you and the authorities as the law requires.
10. Children
Kept is for adults. You must be 18 or older to create an account, because the service involves a payment card and money at stake. Kept is not directed to children under 13, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we delete it and close the account. If you believe a minor has an account, write to info@keptgoals.com.
11. Where your information is processed
Kept is operated from Germany, and its servers and providers are in the United States. Your information is therefore stored and processed in the United States, and accessed from Germany by the operator. Where the GDPR requires a legal basis for moving information between the European Union and the United States, we rely on the EU–U.S. Data Privacy Framework for providers certified under it and on the European Commission's standard contractual clauses otherwise (section 12).
12. For everyone: your rights under the GDPR
Because the operator is established in Germany, the GDPR applies to Kept's processing of your information even though you are in the United States. This section states what the GDPR requires us to tell you.
Controller. Moritz Rechtalski, Weidenweg 11, 17498 Dargelin, Germany, info@keptgoals.com. Kept has no data protection officer, because it is not required to have one for a service of this size; questions go to the same address.
Purposes and legal bases.
- Providing the service you signed up for, including charging and refunding stakes: performance of a contract (Art. 6(1)(b) GDPR).
- Keeping financial and consent records after deletion: compliance with legal obligations (Art. 6(1)(c)), namely German commercial and tax law (HGB § 257, AO § 147) and card-network rules on saved-card agreements.
- Security, fraud prevention, and the audit trail: our legitimate interest in running a service that handles money honestly (Art. 6(1)(f)).
- Crash reports: our legitimate interest in fixing defects (Art. 6(1)(f)).
- Push notifications: your consent, given on your phone (Art. 6(1)(a)); you can withdraw it at any time in Settings or on your phone.
Recipients. The providers in section 4, and public authorities when the law requires it.
Transfers. The providers are in the United States. Transfers rely on the EU–U.S. Data Privacy Framework where a provider is certified under it, and otherwise on the European Commission's standard contractual clauses in our contracts with them. You can ask us for a copy of the relevant clauses.
Retention. Section 7.
Your rights. Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection to processing based on legitimate interests (Art. 21), and withdrawal of consent at any time without affecting earlier processing (Art. 7(3)). Erasure does not extend to the financial records we are legally required to keep (Art. 17(3)(b)). You also have the right to lodge a complaint with a supervisory authority, in particular the data protection authority of the German state where the operator is established: [Name of the competent state data protection authority].
Automated decision-making. The image check described in section 3 produces a first verdict, but no decision with a legal or financial effect on you is taken without a person: a rejection is reviewed by a person before anything is charged, and you can appeal every rejection. If you believe a decision was wrong, use the appeal in the app or write to us.
Is providing information required? Your email address, a password, a time zone, a card, and a signed consent are required to use the service; without them a goal with a stake cannot be created. A display name is optional.
13. Changes to this policy
When this policy changes, the new version gets a new date at the top, and the app asks you to read and accept it before you continue. We keep every earlier version and can tell you which version you accepted and when. If a change would let us use your information in a new way that you would not expect, we will explain the change when we ask for your acceptance.
Version history. 2026-09-23: photo metadata, including any location, is removed on your phone before upload; only the time taken and the camera make, model and image size are kept with a photo (section 1). 2026-09-22: first version.
14. Contact
Moritz Rechtalski Weidenweg 11, 17498 Dargelin, Germany info@keptgoals.com
The operator's details are also published at keptgoals.com/imprint.