Connect your Stripe and see today which paying accounts stopped showing up.

Join

Legal

Effective September 23, 2026

Privacy
Policy

What Keep stores, what it reads and writes in the tools you connect, who it is shared with, and what you can do about it. Written from what the product actually does, in line with Brazil's data protection law (LGPD, Law 13,709/2018) and the European GDPR.

Back to home
  1. 1. Who we are

    Keep is a product operated by Vinicius Aguiar, who is the controller of your account data. Keep reads billing and product-usage data you already have, crosses the two, and warns you when one of your customers looks about to cancel.

    Contact for any privacy matter, including as data protection officer: vinicius@usekeep.dev.

  2. 2. Your account data

    Sign-in is through Google or GitHub. We receive your name, email, and profile picture from the provider you choose. There is no password sign-in: we never have or see any password.

    We also store the preferences on the Settings screen, a record of alerts already sent (so the same message is not repeated), and, if you subscribe to Keep, the identifiers of your Stripe subscription — plan, billing cycle, status, and renewal date. Card details stay with Stripe; they never pass through us.

  3. 3. What we access from your tools

    Stripe: we read subscriptions, customers (name and email), plan changes, and declined charges from the account you authorize. Stripe only grants the connection with read and write permission, but Keep does not use the write side: it never creates, changes, or cancels any charge. No Stripe token is stored.

    AbacatePay and Asaas: we read subscriptions and customers with the API key you paste. In Asaas, Keep creates a webhook named "Keep" in your account to receive billing events; in AbacatePay, you set up the webhook yourself.

    PostHog: we read usage counts per person — how many actions in the period and when each was last seen — along with the person's email, for the match. We do not read the content of the events.

    HubSpot: we read companies (name, domain, owner, stage, last contact), owners (name and email), and contact emails, to show who looks after each account. Read-only.

    Intercom: we read open conversations and the email of the contacts involved. When an account becomes at risk, Keep adds an internal note to the Intercom contact with the reason and the revenue at stake.

    Slack: we store the webhook URL for the channel you chose and the workspace and channel names. It only allows posting to that channel — we cannot read messages. When someone answers an alert with its buttons, we store the Slack identifier of who answered.

    API keys, tokens, and webhook URLs are encrypted with AES-256-GCM before they touch the database.

  4. 4. Your customers' data

    To cross revenue with usage, we process the name, email, and subscription value of the customers in your billing accounts, plus the usage and support data described above. In this processing, you are the controller and Keep is the processor: we act on your instruction, given when you connect the tools, and for no other purpose.

    We do not sell, rent, or hand this data to anyone.

  5. 5. Activity you send through the API

    If you generate an API key and send activity from your own product, Keep receives the account identifier — the Stripe customer id or an email —, the moment of the activity, and, optionally, the name of the feature used. You choose what to send: the Stripe id alone is enough for the match, and in that case no end-user personal data reaches us.

    We do not store the event. What arrives is summed into counters per account, per day, and per feature. We do not receive content, screens visited, IP address, or any browser identifier — the call comes from your server. Events dated more than 90 days in the past are rejected.

    The key is stored only as a hash, never in readable text, and revoking it stops ingestion immediately.

  6. 6. The agent and OpenAI

    Keep's agent answers questions about your operation using OpenAI models. To do so, we send OpenAI your question and the data needed to answer it: account names, emails, and MRR, risk status and reason, feature usage, open support conversations, and the HubSpot owner.

    If you use voice dictation, the audio is sent to OpenAI for transcription and is not stored by us.

    Conversations with the agent are saved in your account until you delete them. The agent also extracts facts from your messages ("learned memory") to use in later answers; you can see and delete each fact on the agent screen.

    Under OpenAI's API terms, data sent through the API is not used to train its models.

  7. 7. Emails, support chat, and newsletter

    Alert emails are sent through Resend to your account email, and only if you turn that channel on.

    When you join the newsletter, your email, language, and sign-up date are sent through Resend to the founder's inbox. They are not stored in Keep's database. To leave, just ask.

    Support chat is run by Crisp and only loads when you click to open it. What you write there stays with Crisp.

  8. 8. Audience measurement and cookies

    We use Umami to count visits in aggregate — page, referrer, browser, country. Umami uses no cookies and collects no personally identifiable data. We do not use Google Analytics, Meta Pixel, or advertising trackers.

    The cookies and local storage we use are listed, one by one, in the Cookie Policy.

  9. 9. Legal basis

    We process your data to perform our contract with you (LGPD art. 7, V) — your account, the integrations, the alerts, and billing; on legitimate interest (art. 7, IX) for security, abuse prevention, and aggregate audience measurement; on consent (art. 7, I) for the newsletter; and to meet legal and tax obligations (art. 7, II).

  10. 10. Who we share it with

    Only the processors the product needs to work: Supabase (database and authentication), Vercel (hosting), OpenAI (agent), Resend (email), Stripe (billing for your Keep subscription), Crisp (support chat, only after you open it), and Umami (aggregate measurement). Stripe, AbacatePay, Asaas, PostHog, HubSpot, Intercom, and Slack receive or provide data only when you connect each one.

    Several of these processors handle data outside Brazil, mainly in the United States. These international transfers rely on each processor's contractual safeguards, as provided by LGPD art. 33. The full list, with what each one does and where it is, is on the subprocessors page (usekeep.dev/en/subprocessors).

  11. 11. If you are in the European Union or the UK (GDPR)

    The GDPR applies to the processing of data of people in the EU and the UK. The roles are the same as described above: for your account data, Keep is the controller; for your customers' data, you are the controller and Keep is the processor.

    Legal bases (GDPR art. 6): performance of a contract (6(1)(b)) for your account, the integrations, the alerts, and billing; legitimate interest (6(1)(f)) for security, abuse prevention, and aggregate audience measurement; consent (6(1)(a)) for the newsletter; and legal obligation (6(1)(c)) for tax records.

    Your rights: access, rectification, erasure, restriction of processing, portability, objection, and withdrawal of consent at any time, as well as lodging a complaint with the data protection authority in your country.

    Keep's database is in Canada (AWS, ca-central-1 region), a country with a European Commission adequacy decision. The other processors are mainly in the United States; those transfers rely on the Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework, depending on the processor. The full list, with what each one does, is on the subprocessors page.

    We offer a Data Processing Agreement (DPA) for anyone using Keep with customer data from the EU or the UK. Ask at vinicius@usekeep.dev.

  12. 12. How we protect it

    Connections always over HTTPS, third-party credentials encrypted with AES-256-GCM, and row-level isolation in the database, so an account can only reach its own records.

    No protection is absolute. If an incident poses a relevant risk to your data, we will notify you and Brazil's data protection authority (ANPD), as LGPD art. 48 requires.

  13. 13. How long we keep it

    Everything tied to your account stays for as long as the account exists: connections, subscription change history, alerts, activity counters, agent conversations, and facts. The subscription history is kept even if you disconnect Stripe — disconnecting hides the history, it does not destroy it, and reconnecting the same account finds it again.

    When you delete the account, your Keep subscription is canceled and this data is removed from our database immediately. What remains is only what lives outside our database: Stripe's records of your subscription, emails already delivered, Crisp conversations, and caches of up to 15 minutes. The access granted to your tools stops being used, but revoking it in the tool itself is how to guarantee the cut.

  14. 14. Your rights

    The LGPD (art. 18) guarantees confirmation of processing, access, correction, anonymization, blocking or deletion, portability, information about sharing, and withdrawal of consent.

    In Settings → Account you can download, in JSON, everything we hold about you — account, settings, connections, subscription history, alerts, agent conversations and facts, activity counters — and delete the account, without talking to anyone. Only credentials to other systems (tokens, API keys, the Slack webhook URL) are left out, and the file says which.

    For any other right, write to vinicius@usekeep.dev. We answer within 15 days, at no cost.

  15. 15. Minors

    Keep is a product for businesses and is not directed at anyone under 18. If we find data from minors collected by mistake, it will be deleted.

  16. 16. Changes and contact

    If anything material changes, we will notify you by email before the change takes effect. The effective date at the top always reflects the current version.

    Questions: vinicius@usekeep.dev. You can also contact Brazil's National Data Protection Authority (ANPD) at gov.br/anpd.

This document is the current version. Changes are published here with a new effective date.