Privacy Policy

Privacy Policy

Kept keeps your meeting content on your Mac. This policy explains what we collect, what we don’t, and how you can manage it.

Effective · July 26, 2026

01Principles

  • Meeting content stays on your Mac. Recordings, transcripts, notes, voiceprints, and screen content live only on your device. We hold no copy.
  • Processing is local by default. Transcription and speaker ID run on-device. Without an AI provider configured, everything except note generation works offline.
  • We see very little. License and order records, device activations, and emails you choose to send us.
  • No tracking. The app has no analytics SDK and no crash reporter. This site uses no cookies and no tracking scripts.

02What we never collect

The following never leave your Mac for our servers, under any circumstances:

  • Recorded audio (system audio and microphone tracks)
  • Transcripts and meeting notes
  • Voiceprints (speaker vectors stored only in the local database)
  • Screen content and meeting-window information (used only to detect which meeting app is open, then discarded)
  • Usage analytics
  • Crash reports (no crash service is integrated; diagnostic logs are created only when you export them, and sending them is optional)

03Purchase and licensing

Checkout is handled by a third-party payment provider, which acts as the seller for the transaction. Your card details go only to them — we never see or store them.

The license service is ours (hosted on Cloudflare). For each license, the database stores:

  • A SHA-256 hash of the license key (the plaintext key is never stored; it is hashed as soon as the webhook arrives)
  • Your email address and order ID
  • Product line, seat limit, updates-until date, refund-revocation status, and creation time

Each activation adds a row: instance ID, device name (as shown in “About This Mac”), and activation time. That is how seat limits and deactivation work.

04Update checks

About once every 24 hours, Kept requests appcast.xml from dl.keptmac.com to check for a new version. That request leaves your IP address, a timestamp, and the update framework’s User-Agent (including the Kept and macOS versions) in access logs.

We have not enabled Sparkle’s system profile reporting (SUSendProfileInfo), so hardware details, model identifiers, and language preferences are not sent.

05Speech model downloads

On first launch, Kept downloads roughly 1 GB of speech models (the English pack is optional). Downloads go straight to HuggingFace or a China mirror, not through our servers. They see your IP; we neither proxy the traffic nor know which packs you fetch.

06Your AI provider

Note generation needs a language model. Kept does not broker that for you: you enter your own API key in settings, and the app talks to the provider you choose.

  • Only text is sent (transcript and prompt) — never audio
  • Each send requires your explicit approval
  • The API key is stored in your system Keychain and is never uploaded to us
  • Once the text reaches the provider, their privacy policy applies; the request does not pass through our servers

Without an AI provider, everything except note generation works fully offline.

07This website

keptmac.com uses no cookies, analytics scripts, or third-party tracking pixels. Local storage holds a single item, theme (light/dark preference). It contains no identifying information and is never sent to a server.

The site is hosted on Cloudflare Workers. Cloudflare keeps standard access logs (IP, User-Agent, timestamp, request path) for security and troubleshooting.

08Third parties

WhoPurposeWhat they may receive
Payment providerCheckout, invoicing, refundsPayment and billing details, email
CloudflareSite, license service, update and download deliveryAccess logs (IP, User-Agent, timestamp)
HuggingFace / China mirrorSpeech model downloadsIP address of the download request
AI provider you chooseMeeting notesText you approved for sending

We do not share data about you with anyone else.

09How long we keep things

  • License records: kept for the life of the license for validation, deactivation, and update eligibility. After a refund, we retain the revocation marker so the same key cannot be reused.
  • Access logs: handled by Cloudflare under its default retention.
  • Emails you send us: may remain in the mailbox after the issue is resolved for follow-up; you can ask us to delete them.
  • Data on your Mac: entirely under your control. We hold no copy and cannot delete it for you.

10Your rights

You can ask to access, correct, or delete the records we hold about you (the license and order information above), and you can ask us to deactivate a device or export those records. Write to support@keptmac.com; we respond within 30 days.

If you are in the EU or UK (GDPR), California (CCPA/CPRA), or mainland China (PIPL), you also have the rights your local law provides, including restriction of processing, data portability, and lodging a complaint with a supervisory authority. We will not treat you differently for exercising them.

Data on your Mac is yours to manage. In Settings › Privacy & Data you can export everything as a JSON backup (meetings, transcripts, and notes; audio files not included), or use “Delete all data” to remove every meeting, audio file, database record, and personal dictionary. Deletion asks for confirmation twice and cannot be undone; model packs and your license remain.

11Children

Kept is not directed at children under 13, and we do not knowingly collect their personal information.

12Changes to this policy

If this policy changes, we update the effective date at the top of the page. Material changes are also noted in the changelog.

13Contact

Privacy questions: support@keptmac.com. This site and Kept are operated by an independent developer (an individual).

This policy covers Kept (the macOS app) and keptmac.com.