Privacy Policy

Effective date: August 31, 2026 Version: 2026-09-07

1. Introduction

This Privacy Policy explains how kept, operated by Kept AI Inc., a Delaware corporation (kept, we, us, or our), handles information when you use the kept product and related services (the Service). kept is an evidence engine with a conversation layer: it captures your work into evidence-backed memory, and it retrieves only what the asker is permitted to see. We wrote this policy to be read, not skimmed.

The kept Privacy Commitments are not marketing language. They are the constraints the product is built to enforce. Where a detail below adds nuance, the Commitments still govern: capture is opt-in, your record is visible to you and you can correct it, deletion follows your plan (on a personal plan you delete your own record outright; in a business workspace, where captured work product belongs to the workspace, you hold a deletion request, described in Business-Workspace Participants), your employer sees a red, amber, or green band for how much you have contributed and nothing else about you, and every answer is cited or marked unknown.

2. Which kept you are on

kept is sold two ways, and parts of this policy read differently depending on which one covers you. Kept for You is the personal product: you are our customer, the workspace is yours alone, and everything captured belongs to you outright. Kept for Business covers business and enterprise workspaces: an organization is our customer, it purchases seats and invites its people in, and the knowledge captured for the workspace is the workspace's intellectual property, while your rights as a person in that workspace are the ones this policy describes and they do not depend on the organization's goodwill.

Every plan-dependent rule in this policy is stated in the section where it applies, and the two that matter most are named here so you cannot miss them: on Kept for You, deletion is self-service and real, and nothing purges by default (Your Rights and Choices, Data Retention); on Kept for Business, deleting knowledge you captured for the workspace is a request the workspace decides (Business-Workspace Participants), and raw session material carries a retention ceiling (Data Retention). If you hold both a personal account and a workspace membership, each side follows its own rules: your personal knowledge is never governed by an employer's plan.

3. Our Role and Your Workspace

kept is a workplace product. In most deployments your employer or another organization (your workspace) is our customer: it purchases seats, decides which features are enabled, and is responsible for having a lawful basis to offer kept to its people. Where data protection law distinguishes a controller from a processor, your workspace is ordinarily the controller of workspace content and we process it on documented instructions under our agreement with the workspace.

Two things do not change with that structure. First, capture from you is opt-in with you personally: your workspace cannot consent on your behalf, and the record of your own consent, including every grant, pause, and withdrawal, is kept in an append-only ledger. Second, the Privacy Commitments run to you as a person: whatever the commercial arrangement, the only thing kept reports about you to your employer is how much you have contributed, as a red, amber, or green band, and the internal working model kept uses to run a good interview never surfaces to any organization-facing view.

4. Information We Collect

We collect only what the Service needs to work, and we separate the categories deliberately:

  • Account information: your name, work email, workspace membership, role, and preferences, so we can sign you in, associate you with the right tenant, and keep your settings.
  • Workspace content: the documents, messages, and materials you or your workspace choose to bring into kept for a session.
  • Captured knowledge with provenance: the evidence-backed memory kept builds from your sessions, always stored with a citation to its source so every later answer can point back to where it came from.
  • Consent and audit records: the append-only record of your consent transitions and of sensitive actions taken on your account, kept so that what happened is provable later.
  • Usage and diagnostics: technical logs such as device and browser type, timestamps, feature interactions, and error reports, used to keep the Service reliable and secure.

We do not ask for credentials, passwords, or personal information such as government identifiers, financial account numbers, or health details: the interviewer is built never to solicit them, and kept has no use for them. If such information surfaces in a session or in content you bring in anyway, it is yours to remove from your record at once, and we do not promise that an automatic filter catches it first.

5. Live Voice Processing and Transcripts

A capture session is a live conversation with a voice AI interviewer, presented as one before you join. Nothing is captured without your own recorded consent, asked for separately from your acceptance of these documents and enforced at the database floor: a session cannot begin for someone who has not consented, and consent is re-checked during the session, not only at its start. Each session opens with a spoken notice that everything in it is being captured, that the record stays yours to see, and that you can skip anything or stop whenever you want, and a visible end control stops the session at any time.

During a session, your live audio is transmitted to our voice provider, ElevenLabs, where it is processed and transcribed in real time. The transcript, not the audio, is what kept keeps and works from: kept's own systems store no audio after live processing. On the provider's side, audio handling is governed by our agreement with the provider.

Dictation in the chat composer is a separate thing from a capture session, and it uses a different provider. When you press the microphone to dictate a message, that audio is transmitted to OpenAI, where it is transcribed and returned as text. It is input, not capture: nothing is recorded to your knowledge, no transcript is kept, and the words become part of kept only if you send the message they land in. kept's own systems store no dictation audio at any point.

kept does not use your voice to identify you, does not verify identity by voice, and does not create a voiceprint or other biometric identifier.

The Voice Capture and Consent notice, published at kept.solutions/recording-and-consent, describes the session flow, the consent requirements, and the rule that no one may be added to a session without their own notice and consent.

6. How We Use Information

We use the information we collect to:

  • Provide the Service: run your sessions, build your evidence-backed memory, and return answers that are cited or marked unknown.
  • Keep the Service secure and reliable: detect and prevent abuse, debug errors, and maintain availability.
  • Enforce access rules: resolve which tenant, role, and grants apply so that retrieval only ever returns what the asker is permitted to see.
  • Improve the Service: understand which features are used, in aggregate, without turning your record into a profile for your employer.
  • Communicate with you: send service, security, and account messages you cannot reasonably opt out of, and product updates you can.

We report one thing about you to your employer: a red, amber, or green band for how much you have contributed so far, counted from the pieces of knowledge you have captured. We do not evaluate the quality of your work, we do not rank you against your colleagues, and we do not give your employer the underlying number. Beyond that band, we do not use your captured knowledge to monitor, score, or evaluate you on behalf of your employer. We do not sell your information. We do not use your workspace content or your captured knowledge to train generalized AI models.

8. Your Rights and Choices

You hold direct control over your record. At any time you can:

  • Access: see everything kept holds about your work, with its provenance.
  • Export: request a complete, portable copy of your account data.
  • Correction: remove anything that is wrong from your record at once, restore anything removed by mistake, and retract things in the session itself, where the interviewer confirms what you want gone before applying it.
  • Deletion: on a personal plan, delete or retract any part of your captured knowledge, or your whole account, yourself. In a business workspace, deleting knowledge you captured for the workspace is a request the workspace decides, described in Business-Workspace Participants; your personal account and anything outside the workspace remain yours to delete.
  • Pause: pause capture so nothing new is kept, while keeping what you already have.
  • Objection: object to a given use, or withdraw consent to capture entirely, which stops capture going forward.

We honor these controls for everyone who uses kept, not only where a statute requires them. Depending on where you live, for example in the European Economic Area, the United Kingdom, or a United States state with a comprehensive privacy law such as California, you may also have statutory rights to access, correct, delete, port, or restrict the processing of your personal information, and the right not to be discriminated against for exercising them. You can exercise any of these through the controls in the product or by contacting admin@kept.solutions, and you may also complain to your local supervisory authority. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no such sale or sharing to opt out of.

Withdrawing consent or pausing capture does not remove what you have already chosen to keep, unless you also delete it. Exercising any of these rights never degrades the parts of the Service that do not depend on capture.

9. Business-Workspace Participants

If you use kept as a participant in a business workspace, the business customer that administers the workspace controls the workspace content, and kept processes it on that customer's behalf.

This means that for requests about workspace content, such as access to or deletion of knowledge captured for your employer's workspace, we may need to route your request to your organization, and your organization is responsible for responding under its own policies and legal obligations. We will tell you when we do this, and we will assist your organization as our contract with it requires.

Who in your workspace can see your captured knowledge, exactly: the workspace's owner and its administrators can view the knowledge you captured for the workspace. A manager sees it only inside their own department's roll-up, never as your individual record, and only for the department they manage. Other members do not see it unless a specific grant shares it. Your capture level (the red, amber, or green read of how much you have contributed) is visible to the owner, to administrators, and to your own department's manager, and you see your own. No role, in any workspace, on any plan, ever sees the internal working model kept builds to run a good interview, a per-person usage number, or any score, rating, or ranking of you as a person.

On a business or enterprise plan, the knowledge you capture for the workspace is the workspace's intellectual property. You keep full visibility of it, you can have anything that is wrong removed from view at once, and you can retract something you said during a live session: the companion confirms what you want removed and applies it the moment you confirm, ahead of everything else. Deleting it is a request. The workspace's owner and administrators are notified in the dashboard and by email. They may approve an audited erasure, disapprove a request with no erasure deadline by giving a recorded reason, or leave it open without a deadline. Disapproval does not change your account, access or knowledge. You can see the decision and reason, withdraw an open request, or submit a new request after disapproval. Requests and decisions stay on record, including after your membership ends. The workspace sees your request and stated reason, not additional information about you.

One exception, and it is not the workspace's to waive: where the law of your workspace's jurisdiction gives you a legal right to erasure, kept provisions that workspace with a deletion window. There, you are told the window when you make the request, the workspace gets no say, and the erasure runs automatically when the window closes.

For information kept controls directly, such as your account registration, security records, or a support request you sent us, you can contact us at support@kept.solutions and we will handle the request ourselves.

If you leave the workspace, the administrator ending your membership chooses, at that moment, one of two outcomes for the knowledge you captured. Either the workspace keeps it, or you take it. There is no standing workspace policy set in advance, so the outcome is not knowable before your departure. The Departing Members section of the Terms of Service governs that choice.

We email you either way, at the address we hold for you, which may be a personal recovery address you have given us. The email tells you which outcome the administrator chose.

10. Data Retention

We keep account information for as long as your account is active. Captured knowledge persists across sessions by design: on a personal plan it is kept until you remove it or close your account, and in a business workspace it is kept under the workspace's ownership until it is deleted under the rules described here and in Business-Workspace Participants. Consent and audit records are retained for as long as the law and our accountability obligations require, because they exist to prove what happened. Diagnostic logs are kept for a limited period sufficient for security and reliability, then deleted or aggregated. When an account is closed, it is recoverable for 30 days, and after that we delete the covered content from active systems, except where we must keep a limited record to meet a legal obligation or a lawful hold. Deleted content is not returned to service from our infrastructure provider's disaster-recovery copies, which expire on that provider's own schedule.

Raw capture material is retained differently from distilled knowledge. On business and enterprise plans, raw material (session transcripts, original uploaded documents, chat threads, and call audio where we hold it) is retained for 30 days by default and then deleted. A workspace may contract for a longer window, up to 365 days; the window is provisioned by kept with effective dates, and when a contracted term lapses the window returns to 30 days. Distilled knowledge units, the evidence-backed memory the product exists for, are not subject to this ceiling. On a personal plan there is no default purge at all: your data lives until you delete it.

Removing a single item behaves differently by plan. On a personal plan, and in a workspace provisioned with a jurisdiction deletion window, a removed item leaves your knowledge at once and stops being used to answer anyone's questions, including your own; for 30 days we can restore it if you ask us at support@kept.solutions (in a business workspace with a window, the workspace may also ask within those same 30 days, by email only, with no administrator control in the product); after 30 days it is permanently deleted and no one can recover it through kept, including us, subject to a lawful hold, which keeps an item until the hold is released. In a business or enterprise workspace without a provisioned window, a removed item is suppressed rather than destroyed: it leaves your knowledge and every view at once and is no longer used to answer questions, but because the captured work product belongs to the workspace, your removal alone does not permanently delete it. There, you or the workspace can ask us by email to restore a removed item at any time, for as long as the item still exists. Permanent deletion there happens through an approved deletion request, the workspace's own deletion, or the raw-material retention schedule where it applies.

The 30 day permanent-deletion clock applies to items removed on or after the effective date of this policy, on the plans where that clock runs. Anything you removed before that date is not on the clock: it stays out of your knowledge and out of answers, it has no deletion date, and it can still be restored on request.

11. Security

We protect information with encryption in transit and at rest, strict tenant isolation enforced at the database floor, deny-by-default access controls, least-privilege access for our team, audit logging of sensitive actions, and routine review of our controls. Session transcripts are immutable by design once recorded. No system is perfectly secure, and we do not promise otherwise, but security is a first-class part of how kept is built rather than an afterthought: access to your record is denied by default until an authorized path allows it, and we will notify you and your workspace of a breach as the law requires.

12. Sharing and Sub-processors

We do not sell your information, we do not share it for cross-context behavioral advertising, and beyond the contribution band described above we do not hand it to your employer as a score, ranking, or profile of you. We use a small set of vetted sub-processors strictly to run the Service, each bound by contract to protect your data and to use it only on our instructions:

  • Hosting and infrastructure: cloud providers that store and run the Service.
  • AI model providers: model gateways used to generate answers, which receive only the minimized, authorized content needed for a given request and are contractually barred from training on your data. An enterprise workspace may arrange for its model calls to be routed to an AI endpoint the workspace itself operates; that endpoint receives only that workspace's requests, is the workspace's own infrastructure rather than a kept sub-processor, and every call through it is recorded like any other.
  • Payments: a payment processor that handles billing details, which we never store ourselves.
  • Email and communications: providers used to send account, security, and service messages.

A current list of sub-processors is available on request to admin@kept.solutions. We may also disclose information if required by law, to protect the rights and safety of people and the Service, or in connection with a corporate transaction such as a merger or acquisition, in which case we will require the recipient to honor this policy.

13. International Transfers

We are a United States company and process information in the United States, and we may also process and store information in other countries where we or our sub-processors operate. Where we transfer personal information out of a jurisdiction that restricts such transfers, we use appropriate safeguards, such as standard contractual clauses or an equivalent lawful mechanism, so that your information keeps a comparable level of protection wherever it is handled.

14. Geographic Availability

kept is offered only to users in the United States at launch and is not offered to users outside the United States.

15. Cookies and Similar Technologies

We use a minimal set of cookies and similar technologies that are necessary to sign you in, keep your session secure, and remember your preferences (such as light or dark theme). We do not use advertising cookies or cross-site tracking. Where the law requires consent for non-essential cookies, we ask for it, and you can manage cookies through your browser settings. Our pages also load fonts from Google Fonts, which means your browser makes a request to Google's font servers when a page loads; that request serves the font and is not used by us to track you. Our marketing site measures page visits with Plausible, a cookieless analytics service that sets no identifier and does not follow you across sites. The product can report application errors to a monitoring service; those reports are built to carry no personal information and exist only so defects get fixed.

16. Children

kept is a workplace product intended for use by adults in a professional setting. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

17. Changes to this Policy

We may update this policy as the Service evolves or the law changes. When we make a material change, three things happen, every time: the document gets a new version and, where the substance changes, a new effective date with reasonable advance notice; we email every account at its registered address describing what changed and when it takes effect; and the product asks you to review and accept the updated documents the next time you sign in, before you continue. Silence is not acceptance, no one accepts on your behalf, and a change never weakens the kept Privacy Commitments.

18. Contact

For any privacy question, request, or complaint, contact us at admin@kept.solutions, or write to Kept AI Inc., Attn: Privacy, c/o our registered agent, 131 Continental Drive, Suite 305, Newark, DE 19713. We will respond within the timeframe the applicable law requires, and sooner where we can.