Keepsake Privacy Policy

Keepsake stores encrypted content for app functionality, not advertising or tracking.

What We Collect

We collect Sign in with Apple account identifiers, optional Apple email, display name, pairing state, subscription status, device push tokens, support messages, reports, and structural metadata such as dates, object sizes, vault membership, and storage usage.

We also collect user content such as photos, videos, voice notes, messages, timeline entries, and capsules because Keepsake must store and sync them for you and your paired partner.

End-To-End Encryption

Vault content is encrypted on your device before it reaches Keepsake. The server accepts and stores ciphertext blobs, ciphertext text fields, wrapped keys, and the metadata required to sync them. It never receives the plaintext vault content or an unwrapped vault key.

We cannot read your photos, messages, voice notes, letters, captions, or notes. Operational metadata remains visible, including account and vault membership, object dates and sizes, subscription state, device records, storage usage, and report reason metadata.

Use And Sharing

We use data for app functionality, security, support, subscription management, abuse handling, deletion, and export.

We do not sell your data, run ads, share data for tracking, or run AI processing over your content.

Retention And Deletion

Your encrypted content is kept until you delete it or delete your account. A normal item deletion is a recoverable encrypted soft deletion and can remain in your vault export until a later hard-purge policy applies.

Account deletion starts a 24-hour purge workflow for active-system rows and encrypted media objects. Exact completion can take longer when retries or shared blob references are required.

Provider-managed backups age out on their own schedule. Deletion tombstones are retained so that if a backup is restored, deleted data is purged again instead of silently reappearing.

Contact

Email megan@twohearth.com.