Last updated: March 3, 2026

Privacy Policy

1. Introduction

NostrCorp, Inc., a Delaware corporation (“we,” “us,” or “our”), operates the KeepAI platform available at https://getkeep.ai (the “Service”).

This Privacy Policy explains how we collect, use, process, retain, and safeguard information when you use the Service.

2. Information We Collect

2.1 Information You Provide

Account Information

When you sign up via Google authentication, we receive your name, email address, and profile image associated with your Google account.

Payment Information

Subscription payments are processed securely by Stripe. We do not store full credit card numbers on our servers.

Configuration Data

Policies, permission rules, and configuration settings you create within KeepAI.

Support Communications

Information you provide when contacting support.

2.2 Information Collected Automatically

Usage Data

Features used, interactions with the Service, timestamps, and system events.

Device Information

Browser type, operating system, device type, and technical environment details.

Log Data

IP address, access times, referring URLs, error logs.

Cookies and Similar Technologies

Used for session management, authentication, and analytics.

3. Connected Services and Private User Data

The Service may connect to third-party services, including but not limited to Gmail and other supported platforms.

3.1 Client-Side Encryption

Private user data (including Gmail data and other connected service data) is encrypted on user-controlled devices using user-generated cryptographic keys.

3.2 No Server-Side Decryption

We do not:

  • Store decryption keys
  • Have access to user-generated encryption keys
  • Maintain technical capability to decrypt private user content

Our infrastructure cannot access plaintext content of encrypted private user data.

All decryption and content-level processing occur exclusively on user-controlled devices.

4. How Data Flows Through the Service

To provide clarity regarding architecture:

  1. 1.You authorize access to a third-party service (e.g., Gmail).
  2. 2.Data retrieved from that service is encrypted on your device using user-generated keys.
  3. 3.Encrypted payloads may be transmitted through our relay infrastructure.
  4. 4.Our servers process encrypted data only and cannot access plaintext content.
  5. 5.Decryption occurs exclusively on user-controlled devices.

We do not store decrypted private user data on our servers.

5. Limited Metadata Storage

To operate the Service, we may store limited metadata, including:

  • Account identifiers
  • Policy configurations
  • Action logs (e.g., attempted or blocked actions)
  • Usage timestamps
  • Subscription status

We do not store the content of emails or other decrypted private user content.

6. How We Use Information

We use collected information to:

  • Provide and operate the Service
  • Manage subscriptions and billing
  • Enforce configured AI safety policies
  • Send service-related communications
  • Detect fraud, abuse, or technical issues
  • Improve system performance and reliability
  • Comply with legal obligations

7. No Sale of Data / No Model Training

We do not:

  • Sell personal information
  • Sell private user data
  • Use private user data to train machine learning models
  • Use private user content for advertising purposes

Encrypted payloads transmitted through our infrastructure are not accessed or repurposed.

8. Relay Data Retention

Encrypted relay data is retained for a maximum of 24 hours for routing, delivery, and synchronization purposes.

After this period, encrypted payloads are automatically deleted from our systems.

Account-level metadata is retained as long as your account remains active, unless earlier deletion is requested or required by law.

9. Third-Party Services

We use third-party providers for specific functions:

Payment Processing: Stripe
Authentication: Google OAuth
AI Providers: OpenAI, Anthropic, Google (if you connect AI agents)
Analytics Providers
Transactional Email Providers

Interactions with third-party AI providers are governed by their respective privacy policies.

We do not control how third-party services process information once transmitted to them.

10. Google API Services Compliance

Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

We only access and use Google user data to provide or improve user-facing features of the Service.

11. Data Retention

We retain:

  • Account metadata while your account is active
  • Billing information as required for financial compliance
  • Logs necessary for fraud prevention and security

If you delete your account, we will delete or anonymize personal data within 30 days, except where retention is legally required.

12. Data Security

We implement industry-standard safeguards, including:

  • Encryption in transit (TLS)
  • Access controls
  • Infrastructure security monitoring
  • Restricted administrative access

However, no system can guarantee absolute security.

13. International Data Transfers

Information may be processed in the United States or other jurisdictions where our service providers operate.

We implement appropriate safeguards where required by applicable law.

14. Your Rights

Depending on your jurisdiction, you may have rights to:

  • Access your personal information
  • Correct inaccurate data
  • Request deletion
  • Restrict processing
  • Request data portability
  • Withdraw consent
  • Opt out of non-essential communications

To exercise these rights, contact us at: support@getkeep.ai

15. Children's Privacy

The Service is not intended for individuals under 18.

We do not knowingly collect personal information from children.

16. Changes to This Policy

We may update this Privacy Policy periodically.

Material changes will be reflected by updating the “Last Updated” date.

17. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

support@getkeep.ai

KeepAI is operated by NostrCorp, Inc., a corporation organized under the laws of the State of Delaware. · All trademarks are the property of their respective owners. · Gmail, Google Calendar, and Google Drive are trademarks of Google LLC.