Legal
Effective September 23, 2026
Our
subprocessors
The vendors that process data on Keep's behalf: what each one does, what data it receives, and where it is. This page changes before a new vendor is added, and anyone who asks is notified by email.
Back to home1. Supabase — database and authentication
Stores all of your account data and handles sign-in with Google and GitHub.
Where: Supabase, Inc. (USA); Keep's database runs on AWS, ca-central-1 region, in Canada.
2. Vercel — hosting
Serves the site and the product and runs the server code, which the requests and the data they carry pass through.
Where: Vercel Inc. (USA).
3. OpenAI — agent and transcription
Receives the question you ask the agent and the account data needed to answer it (names, emails, MRR, risk, usage), and the audio from voice dictation. Under its API terms, it does not use this data to train models.
Where: OpenAI, L.L.C. (USA).
4. Resend — email
Sends alert emails, when you turn that channel on, and waitlist and newsletter sign-ups to the founder's inbox.
Where: Resend (USA).
5. Stripe — billing for your Keep subscription
Processes the payment for your Keep subscription. Receives your email and payment details, which never pass through us.
Where: Stripe, Inc. (USA), and Stripe Payments Europe, Ltd. (Ireland) for customers in Europe.
6. Crisp — support chat
Runs the support chat. It only loads when you click to open it, and stores what you write in the conversation.
Where: Crisp IM SAS (France).
7. Umami — audience measurement
Counts visits in aggregate, without cookies and without personally identifiable data.
Where: Umami Software, Inc. (USA).
8. Tools you connect
Stripe (your account, via Stripe Connect), AbacatePay, Asaas, PostHog, HubSpot, Intercom, and Slack are not Keep subprocessors: they are your tools, which Keep reads from or writes to only when you connect them, as described in the Privacy Policy.
9. Transfers and DPA
Transfers outside the European Economic Area rely on Canada's adequacy decision, the EU-US Data Privacy Framework, or the Standard Contractual Clauses (SCCs), depending on the vendor.
To receive Keep's Data Processing Agreement (DPA), or to be notified of changes to this list, write to vinicius@usekeep.dev.
This document is the current version. Changes are published here with a new effective date.