Keppt

Privacy Policy

Version v1 — Effective August 2, 2026

1. Who We Are

Keppt is operated by Fixonal PTE Ltd, a company incorporated in Singapore ("we", "our", "us"). This Privacy Policy describes how we collect, use, share, and protect your personal information when you use Keppt.

2. What We Collect

Account information. When you create an account we collect your email address (or the equivalent identifier from Google Sign-In or Sign In with Apple), your display name, and a profile photo if your sign-in provider supplies one. We also collect a country code for compliance and data-residency routing.

Documents you upload. Keppt stores the files you upload, including their text content and any structured fields extracted from them.

Extracted data. Our AI extraction generates structured representations of your documents (for example: vendor name, transaction date, total amount). This extracted data is stored alongside the original file.

Usage data. We log technical information necessary to operate the service, including IP address, device type, app version, and timestamps of significant events. We do not run third-party advertising trackers.

Agreement records. When you accept these terms or our Terms of Service, we record the version you accepted, the timestamp, your IP address, and your device user-agent. This record exists only to resolve disputes about whether and when you agreed.

3. How We Use Your Data

We use your data to provide the service: store and serve your documents, extract and search structured information, recommend categories, and operate the application. We use technical logs to detect abuse, fix bugs, and improve the service. We do not sell your personal information. We do not use your documents or extracted data to train general-purpose AI models.

4. Who We Share Your Data With

Google Cloud Platform. Our backend (Firestore, Cloud Functions, Cloud Storage, and Vertex AI for document extraction) runs on Google Cloud. Your documents and extracted data are stored and processed by Google on our behalf under their data-processing terms. Vertex AI is contractually prohibited from using your content to train its models.

Sentry. We use Sentry for error monitoring. Crash reports may include limited context about an error (such as the file path or function that raised it) but are configured to scrub user data. Document content is not sent to Sentry.

Apple and Google. If you sign in with Apple or Google, your authentication information passes through their identity services. We receive only the identifier (and email, if you allow) — not your sign-in credentials.

Legal requests. We will disclose data when compelled by valid legal process (court order, subpoena) and may disclose data when we reasonably believe disclosure is necessary to prevent fraud or protect the security of our users.

5. Where Your Data Lives

You can choose your data residency at signup (US, EU, or APAC). Once chosen, your documents and AI processing are pinned to that region. Some metadata (such as account information) is stored in our default region for operational reasons; this metadata does not include the contents of your documents.

6. How Long We Keep Your Data

We retain your account and documents until you delete them or your account, whichever happens first. Backups may persist for up to 30 days after deletion. Logs are retained for up to 90 days.

7. Your Rights

Depending on where you live you may have rights to access, correct, export, or delete your personal data. You can exercise the access and deletion rights from within Keppt (via the account settings). For other requests email privacy@fixonal.com. We respond to verified requests within 30 days.

Deleting your account. You can delete your Keppt account at any time from Settings → Privacy → Delete my account. This permanently removes your profile, your personal library and all the documents in it, your Keppt subscription record, your share links, and every record we hold that's tied to your account. It is not reversible. If you've contributed documents to shared libraries, those documents remain in those libraries — they're now part of the library's data and the library owner controls them. You'll be removed as a member, and other members continue to use the library normally. If you're the sole owner of any shared library, you'll be asked to either transfer ownership or delete the library entirely before account deletion proceeds. Deletion completes within minutes; you'll receive a confirmation email when it's done. Deleting your account also cancels any active subscription and removes your customer record from our payment processor (RevenueCat), where applicable.

8. Security

Documents are encrypted in transit (TLS) and at rest (Google Cloud's default encryption). Authentication uses Firebase Authentication. We do not store user passwords; password authentication is handled by Firebase. Access to production systems is restricted to authorized personnel.

9. Children

Keppt is not intended for children under the age of 18 and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at the email above and we will delete it.

10. Changes to This Policy

If we make material changes to this Policy we will require you to re-agree before continuing to use Keppt.

11. Contact

Privacy questions: privacy@fixonal.com. For help using Keppt, visit our Support page.