Legal
Privacy Policy
Last updated: September 15, 2026
This Privacy Policy explains how Thesis Labs, LLC(“Thesis Labs,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with the Kept applications for iPhone and Mac, the related website at kept.do, and Kept Workplace, our company-workspace product for organizations at enterprise.kept.do (together, the “Service”). By creating an account or using the Service, you agree to this Policy. If you do not agree, do not use the Service.
1. Who we are
The Service is operated by Thesis Labs, LLC, the data controller responsible for your information. You can reach us about privacy at privacy@thesis.do. Kept is an identity-first productivity app available for iPhone and Mac.
2. Scope
This Policy applies to information we process when you use the Kept app and our website. It does not apply to third-party products, services, or websites that we do not control, even if you reach them through the Service. The Service is offered “as is” and “as available” (see Section 14).
3. Information we collect
We collect only what we need to provide the Service. The categories below describe what we may collect depending on the features you use.
3.1 Account and identity information
- Account identifiers.An email address and a unique account ID. You can sign in with an email one-time code, a one-click sign-in link emailed to that same address, Sign in with Apple, or Sign in with Google. A sign-in link and a sign-in code are the same one-time credential: whichever you use, it works once and expires, and using one retires the other. If you use Sign in with Apple, Apple may share a name and a relay email at your choice. If you use Google, Google’s sign-in software processes the account and device information needed to authenticate you, including a user identifier and an IP address that may be used to estimate general location for fraud prevention. The embedded Google SDK’s privacy declaration also covers linked phone-number and analytics identifiers; Kept requests only your basic profile and email address, does not request a phone number, and does not request Core Location.
- Profile and identity details you provide. Display name, an optional profile photo (stored in our private cloud storage), your identity statement and goals, life areas, preferences, time zone, and unit settings.
- Optional personal characteristics. Date of birth, biological sex, gender identity, height, body composition, and activity baseline, where you choose to provide them for health and nutrition features.
3.2 Content you create
If you attach a file to a task, we store the file and its name, type, size, task association, and upload date in private storage. Downloads use time-limited links. We also retain limited account identifiers, counts, and rejection reasons to enforce upload limits and investigate abuse; those operational records do not include file contents. Removing a file, its task, or your account queues the stored file for deletion.
When you create a note-sharing link, anyone holding that link can read the note and its published images. Commenting or editing also requires a signed-in account and the permission you choose. We create separate copies of included images for sharing. Shared pages and their image requests check whether the link is still active. Revoking the link blocks new requests and removes those published copies; it cannot recall copies someone already saved or images cached from older links.
- Captures and the items they create.Tasks, subtasks, comments, goals, notes (including images you embed), folders, labels, calendar events, habits, focus sessions, mood entries, and saved “memories.” To prevent loss if the app is interrupted while saving, Kept temporarily keeps an account-scoped recovery copy of a pending capture on your device. It is retired after the created item is confirmed and removed during journal cleanup. Separately, you may choose to share capture text, route proposals, and the fields you corrected or kept to help improve Kept’s capture routing, prompts, and evaluations. This is optional and off by default, is not turned on by Cloud AI, and uses the separate “Help improve Capture” control described below.
- Who asked, and who did it.When an agent or a connection you have granted access creates a task or a note in your account, or asks you to take one on, Kept stores that provenance on the item: whether a person, an agent, or a connection made it, that party’s identifier and the role you granted it, the display name carried by the grant, the date, and, on completion, which of you marked it done. An Ask also keeps its own owner-scoped record · the request, what done looks like, an estimate and a needed-by date where given, the notes and links offered with it, where it was placed in your list, and whether it is open, answered, sent back, or withdrawn. The display name comes from the connection or agent grant you approved, never from model text. Only you can read these records; they are deleted with the item or with your account.
- Requested note-tag corrections. If you request a correction to existing note tags, Kept keeps the prior and corrected tags, note identity, version checks, and correction and Undo dates. These records support a reversible repair without overwriting a later edit. They do not contain a copy of the note body and are deleted with the note or your account.
- Meal photos and nutrition data. Photos you take for meal logging, the foods we identify, and estimated macros. Photos are processed for analysis and, if you save the meal, stored in our private cloud storage.
- Assistant personalization and personal Skills. If you use these features, we store the assistant context statement you choose, contact names and email addresses you save or confirm through an invitation, personal Skill instructions, and a bounded set of evaluation examples derived from the request you choose to save as a Skill. We also keep immutable Skill revisions, activation and safety-review status, and content-bound evaluation receipts so an unreviewed edit cannot silently replace a reviewed version. A saved contact is used to help resolve recipients you name; Kept still shows an outward-action confirmation before sending.
- Cloud Agent responsibilities and supporting documents. If you use Commitments in Kept Cloud Agents, we store responsibilities you explicitly accept, including their title, intended outcome, responsible party, deadlines and wake times, proof requirements, answers, decisions, attestations, linked work, and immutable activity history. You may also provide already-extracted document context, including text blocks, page and extraction provenance, a content digest, and trust-review metadata. Kept treats that document material as untrusted context: it strips the source URL, does not treat instructions inside it as commands, and does not treat a document statement as completion proof merely because it appears in the document.
3.3 Health and fitness data (Apple Health)
If you connect Apple Health, we read selected categories you authorize, such as workouts, activity, steps, energy, heart rate, sleep, body mass, body composition, height, date of birth, and biological sex. We request read access only. We sync authorized workout records and daily summaries needed for your insights, not raw, continuous health streams. We never use Health data for advertising or share it for advertising purposes. You can disconnect at any time in the app and in iOS Settings.
A synced sleep summary can include the recording time zone supplied by Apple Health. This keeps its bed and wake times consistent after travel and does not collect a location trail.
When Apple Health reports a deleted workout, we remove its synced Kept record and keep the HealthKit identifier and removal time in your account to prevent an older sync retry from restoring it. This receipt contains no workout measurements and is deleted with your Kept account. An empty Health query alone does not remove records. Disconnecting stops Health reads and sync. An account-specific checkpoint with no workout measurements remains on your device so an explicit reconnect can resume unfinished changes. Permanent account deletion removes that checkpoint too.
When a recorded workout is linked to a planned session, we keep a private confirmation record with the record identifiers, revision checks, prior link, status, label and confidence values, the requested label and confidence, whether you confirmed it, and link and Undo dates. It contains no copy of workout measurements or session notes. This record can remain after either item is deleted to keep retries from silently recreating a link. It becomes eligible for bounded cleanup after 90 days and is deleted with your account.
If you separately enable an Apple Health check-in rule for a habit, we store your chosen sleep-duration or active-energy target, time zone, and schedule settings. We use recent measurements for that signal to compare against your target without asking an AI model to decide whether the habit is complete. We keep an explanation of an automatic check-in, including the measurement, target, and observation time. Undo records your decision so a later sync does not automatically check in that habit again for the same day. Turning off the rule stops new automatic check-ins; it does not erase saved explanations or other Health summaries. Recent rule observations are pruned during subsequent observation uploads once they are more than 15 days old. Rules, explanations, and Undo decisions are deleted with your account. They are not added to Workplace organization memory or shared through an agent’s ordinary habit permissions.
3.4 Integrations
- Google Calendar (optional).If you connect it, we store OAuth tokens and sync event details (including titles, times, locations, descriptions, and attendee information) so your calendar appears in Kept. Kept can also create, change, or remove an event on a calendar you marked writable when you ask it to. A Cloud Agent can do this only through a per-action approval that shows you the exact event first; after you approve, Kept sends those details to Google Calendar, reads the event back to confirm it matches, and keeps a receipt containing the operation’s identifiers, the outcome, and how to undo it · not the event’s own text, which stays in the approval you were shown. No one is invited by this path.
- Google user data and Limited Use.Kept’s use of information received from Google APIs · including Google Calendar data obtained through the calendar.readonly and calendar.events scopes, and Gmail data obtained through the read-only scope described in section 5 · adheres to the Google API Services User Data Policy, including its Limited Use requirements. Concretely: Kept uses Google user data only to provide and improve the user-facing features described in this Policy; Kept does not transfer or sell that data to third parties except as necessary to provide those features, for security purposes, or to comply with applicable law; Kept does not use it for advertising of any kind, including personalized, retargeted, or interest-based advertising; and Kept does not use it to train generalized or foundation AI models. No human reads your Google data except with your explicit consent, to resolve a specific support request you have initiated, for security purposes, or where required by law.
- Apple Calendar (optional). On iPhone and Mac, if you grant full access, Kept can read and display events and can add, update, or remove an event when you direct it to, where the calendar allows changes. Events read from Apple Calendar are not synced to or persisted as part of your Kept account. Events you create in Kept can sync to your account and may also be copied to Apple Calendar. If you invoke the cloud assistant on iPhone or Mac after allowing Cloud AI, Kept may transmit a bounded snapshot of relevant calendar names and events through our server to OpenAI or Anthropic for that request, subject to the AI processing terms below.
- Push notifications (optional).If you enable them, we store a device push token to deliver reminders and nudges. For Cloud Agents, Kept also creates a content-free activity receipt when a job needs an approval or clarification, or reaches an outcome. If external Cloud Agent alerts are enabled for your account and deployment, the lock-screen alert uses fixed generic copy and a closed link to the signed-in Work page; it does not contain a job title, objective, approval parameters, artifact content, or a customer-supplied URL. A new Kept Workplace Inbox row can also send a lock-screen push on iPhone. That alert uses fixed generic copy (“Kept Workplace” / “Something new is waiting for you in your workspace.”) and never includes the row’s title, who acted, or the object. Mac does not receive this Inbox push. Delivery status is operational metadata and is not treated as evidence that you read the update.
- Customer-configured MCP servers (optional). If you connect a Model Context Protocol server for Cloud Agents, we store its HTTPS address, reported server identity and protocol version, the tool names, descriptions, schemas, and effect hints you select, inspection and availability state, and an encrypted bearer credential if one is required. For an agent call, we store the exact proposed parameters and parameter-bound approval, execution state, bounded response data while the run continues, response digests and sizes, and the resulting action receipt. After you approve a call, Kept sends the approved parameters and, where needed, the bearer credential to that server. The server is a third-party service whose own terms and privacy practices also apply.
- Mac meeting-note import (optional). On Mac, you can choose a folder that Kept watches for new text, Markdown, VTT, and SRT transcript files. macOS grants Kept read-only access to that folder, and the security-scoped bookmark that remembers your choice stays on that Mac. Kept reads newly added supported files and saves their text as notes in your synced account. Turning the watcher off or clearing the folder stops future imports; it does not delete notes you already imported.
3.5 Cloud Agents organizations and company workspaces
If you use Kept Cloud Agents with a company or other organization, we store the organization profile its administrators provide (such as name, description, website, industry, size, timezone, and administrative contact), membership and invitation records (including invited email addresses, roles, access status, and acceptance times), organization policy, connected-service identities and scopes, delegated jobs, run history, approvals, artifacts, and tamper-evident audit events. Raw connector secrets are encrypted in our server-side vault and are not shown again after they are saved. Organization members can see organization information according to their role; owners and administrators can manage profiles, invitations, roles, policy, and connectors, while auditors can access governance evidence and exports.
3.6 Usage, diagnostics, and device information
- First-party analytics. Product events (for example, opening the app or completing a task) with small, non-sensitive properties. These events do not include the raw text of your captures. Assistant quality records contain fixed categories, outcome labels, counts, and identifiers of selected Skills, not the text of your message or the assistant response. We may also retain content-free category signals for up to 90 days to assess whether a repeated workflow could become a useful personal Skill. These account-linked signals expire within 90 days. After a same-day segment includes at least five accounts, we may convert it into identifier-free monthly counts that contain no account or event identifier and retain those coarse trend counts for up to 10 years.
- Optional Capture improvement samples.If you separately turn on “Help improve Capture,” Kept may retain the capture text, the on-device and cloud route proposals, and the fields you kept or corrected for up to 365 days. We use those samples only to evaluate and improve Kept’s capture routing, prompts, and evaluations. The permission is purpose-specific: it does not cover notes, assistant conversations, personal Skills, or other account content, and it does not authorize OpenAI, Anthropic, or another provider to train a general or foundation model. Turning it off stops future collection and removes retained samples for this purpose. Content-free permission and access records remain as described in Section 9.
- Habit Builder measurement (when enabled).To measure whether the dedicated Habit Builder entry is useful, Kept creates a random identifier for each opening. Our service associates that identifier with your account so it can enforce ownership, deletion, and safe retry, and keeps stage times, the closed doorway and app/platform version, a schedule snapshot (cadence, local start/end dates, and timezone), and scheduled/completed counts. To retry first-party stage delivery after an interruption, Kept also keeps an account-scoped journal on your device containing the random opening identifier, doorway, stage, and timestamp. A successfully acknowledged delivery removes its entry. Pending entries remain eligible for retry for 90 days and are pruned the next time the journal loads or is cleaned after that window; permanent account deletion clears that account’s entries. These records do not contain your prompt, assistant response, habit label, cue, actions, goal or habit identifiers, or other authored content. Client product analytics and product logs do not contain the random opening or account identifier; delivery logs record only the stage and a closed outcome. Internal dashboards may show overall aggregate counts and rates at any sample size, while platform and doorway rows are suppressed unless their segment has at least five journeys.
- AI feedback you provide. If you rate an AI result — for example, a thumbs-up or thumbs-down on a suggested classification, an insight, a briefing, or a coaching reply — we record that rating and an optional short reason so we can measure and improve the quality of our AI.
- AI operations telemetry. For each AI request, we record technical metadata about the model call — which model ran, token counts, latency, estimated cost, and whether it succeeded — so we can monitor quality, performance, and cost. This operational telemetry does notinclude the content of your captures, messages, or the model’s responses.
- Aggregated product metrics. We combine the usage and diagnostic signals above into aggregate, de-identified metrics — counts, rates, percentiles, and averages — to understand product health on our internal dashboards. These aggregates do not contain your notes, capture text, or other personal content.
- Performance and crash diagnostics. Kept collects technical diagnostics through Apple MetricKit and local crash handlers. On Mac, crash events can include the app and operating system versions, crash type, signal, uptime, active surface, error codes, and a bounded stack-frame symbol. These events are associated with your account when sent to Kept for reliability analysis. If you submit a Mac bug report after a recent crash, it can also include the retained crash record, including its signal and stack, for support.
- Website analytics. On our website only, our first-party analytics records named page and interaction events, the page path, campaign parameters, an A/B variant, and a pseudonymous session ID. A session cookie lasts 30 minutes; a first-touch attribution cookie (which may include the referring page) lasts up to 90 days; and the A/B variant cookie lasts up to 180 days. If you later submit a waitlist or application form, its email record can be associated with the same session and campaign history so we can understand which outreach worked. We do not load third-party advertising or session-replay scripts on the website at this time. Some short campaign links (including event links) are server-side redirects: for each request, we may record the timestamp, requested path, referring origin and path, allow-listed campaign parameters, and coarse browser, operating-system, and device class. When our host makes it available, we may also record its approximate country, region, and city classification. These redirect records do not store a raw IP address or raw user-agent string, do not use browser fingerprinting, and do not set cookies or other persistent identifiers.
- Waitlist and campaign signups. If you join the waitlist on one of our signup pages, we collect your email address and basic campaign attribution (such as the page and link you arrived from). If you opt in to our brand-ambassador or creator program, we also collect the Instagram handle and follower range you provide and any optional details you choose to share when applying (such as what you make, where you post, your goals, the tools you use today, and a link to your work), and we use them only to select and contact participants for that program.
- Call bookings. If you book a call with us on one of our scheduling pages (for example an onboarding call), we collect the name and email address you enter, the time you pick, your timezone, and any optional note you add. We use them only to create and run that call: the details become a calendar invitation delivered through Google Calendar, which emails you the invite (and a Google Meet link when one is attached). Booking a call does not add you to marketing lists. The invite includes a private link you can use to cancel, which removes the event and frees the time.
- Bug reports you choose to send. You can report a problem from a shake gesture, Settings, or an in-app button. A report includes the description you write, the category and screen you pick, and technical context needed to investigate the issue — such as app/OS version, device model, network state, locale, your current layout configuration, and which feature flags were on. Attaching an image is optional and always your choice (you can remove it before sending): on iPhone, Kept can include an automatic screenshot of the app screen or a short screen recording; on Mac, you pick an image file, drag one in, or paste one — Kept does not capture your screen automatically. Any image you attach is re-encoded before it uploads, which removes hidden data such as location and device details. Including a recent on-device activity trail (event names and times only — not your notes or captures) is a separate opt-in and stays off unless you turn it on for that report. We use bug reports only to investigate and fix problems.
- Founding Practice (invited members). If you accept the invite-only Founding Practice program, we record your enrollment, the terms and consent versions you accepted, and the campaign facts that qualify benefits: references to your own tasks, events, notes, and captures by identifier and category only, with timestamps. We do not store the titles or contents of those items in campaign, benefit, or messaging records, and we never place them in push notifications, emails, analytics, or logs. Progress and benefit grants are computed from your real product activity, not from analytics events. Optional practice coaching email is a separate opt-in you can turn off at any time; benefit and account receipts are sent as service messages. You can leave the program without losing your base or earned benefits, and you can ask us to review any progress that looks wrong.
- Optional lifecycle email. If you choose product guidance email, we use your account age, broad onboarding-survey categories, connected-product state, and content-free activity facts such as whether you completed a Kept Action or used Kept recently to decide whether a message is relevant. We do not put your task, note, goal, capture, calendar, meal, or Health content in these messages or their campaign records. We keep the campaign and step, delivery state, and unsubscribe choice. Our delivery provider may also report an email as delivered, opened, clicked, delayed, bounced, or marked as spam. Open data can be distorted by email privacy features and is used only as a delivery diagnostic, not as proof that you read a message or as a condition for another message.
3.7 Kept Workplace (organization workspaces)
Kept Workplace is offered separately from the consumer app described above, at enterprise.kept.do, and runs on its own database isolated from your personal Kept account. An organization that signs up for Kept Workplace holds its own workspace data there: todos, plans, docs, a ledger of completed and evidenced work (“ledger acts”), the identities and granted tool scopes of any connected agents, files members or connected agents add to the workspace, comments and mentions posted there, and any Markdown corpus the organization imports for those agents to reference. Membership, role, and audit records work the same way described for Cloud Agents organizations in Section 3.5, including that an invited or member email address is stored to send the invitation and identify who holds a seat, and is visible to other active members of the same workspace.
Workspace files.If a member or a connected agent uploads a file to a Kept Workplace workspace, we store the file itself, its name, type, size, a hash used to detect a duplicate upload, and, for supported file types, a short excerpt of its extracted text for search and previews. Files are held in a private storage bucket that no client reads or writes directly; a file is reached only through a time-limited link our server issues after confirming you are an active member of the workspace it belongs to. A file is visible to active members of the workspace it is filed in. Kept Workplace limits a single file to 50 MB and a workspace’s total stored files to 5 GB. Deleting a file removes it from view immediately; the underlying bytes are removed from storage within thirty days.
Comments and mentions.Comment text a member or a connected agent writes on a todo, doc, project, or file is stored with that item and shown to other active members of the workspace. Mentioning a member in a comment notifies that member that they were mentioned; the notification itself does not carry the comment text, which the mentioned member reads inside Kept Workplace. A new Inbox row can also send a lock-screen push on iPhone. That push says only that something is waiting in your workspace. It never includes the row’s title, who acted, or the object, and it uses the same Apple push path (APNs) already described in Section 6. Tapping it opens Inbox on that row. Mac does not receive this push.
An agent a customer connects to Kept Workplace acts on that customer’s own configured instructions, policy, and granted tool scopes · not on instructions from us. Within the scopes the customer grants it, a connected agent may list and read workspace files through a time-limited link, attach a file it produces, and read or post comments; each of those actions is written to the workspace’s ledger the same as other agent activity. We do not direct what a customer’s agents do; the customer is responsible for what it grants them, consistent with the Terms of Service.
Kept Workplace uses the sub-processors named in Section 6 for the consumer Service · Supabase for the database and file storage, Vercel for hosting, Resend for invitation and account email, and the model providers named there for agent model calls · and there is no separate sub-processor list for Workplace.
The ledger of completed work is append-only: entries are written once and are not edited or deleted, only added to, so it stays a reliable record of what an agent or person did. An organization admin can request export or deletion of that organization’s Kept Workplace data · including its files, comments, and member email addresses · today by contacting privacy@thesis.do; as of this writing that request is handled by us rather than through a self-service control in the product.
Workplace Daily Synthesis has a separate organization permission, off by default. An active workspace owner can save permission for future daily summaries. The feature is not yet available, and saving permission does not start model work. When available and permitted, Anthropic may process shared workspace tasks, completion evidence, notes, document excerpts, and shared memory to prepare cited summaries within the workspace model budget. Personal Kept notes and health data are excluded.
We record the owner’s permission choice, disclosure version, time zone, and change time for access control and audit. Turning permission off prevents new runs and pending work from publishing. It does not delete saved summaries or recall information already sent to a provider.
4. How we use information
- Provide, maintain, secure, and improve the Service.
- Run the features you request, including routing captures and generating insights.
- Personalize plans, coaching, nutrition, and recommendations.
- Send service messages and, if enabled, reminders and nudges.
- Prevent fraud and abuse and enforce our terms.
- Comply with legal obligations.
5. Artificial intelligence processing
Cloud AI and Help improve Capture are off when you create an account. Setup may offer an optional Cloud AI disclosure, but Cloud AI stays off unless you explicitly choose Allow Cloud AI. Help improve Capture can be enabled only through its separate Settings disclosure. Kept sends personal data to a third-party AI provider only after you review the applicable disclosure and explicitly allow the relevant permission. Cloud AI authorizes the information needed for the cloud feature you choose; Help improve Capture authorizes only the bounded correction-sample use described below. Depending on the feature, Cloud AI information sent through our server to OpenAI and/or Anthropiccan include capture text; the relevant portions of notes, tasks, goals, calendar context, saved memories, or coaching messages; meal photos and meal descriptions when you ask Kept to analyze food; and health or fitness summaries used for related plans, briefings, coaching, or background reflection after you allow Cloud AI. It can also include the assistant context statement you set, relevant saved contact details, personal Skill instructions, or bounded evaluation examples derived from the request you chose to save as a Skill when Kept drafts, evaluates, or runs that Skill for you. If you use Cloud Agents, we also send the selected model provider the objective and operating instructions for a Cloud Agent, the reviewed schemas of tools granted to it, proposed tool-call parameters, and bounded text or structured results returned by an approved MCP call so the agent can continue. A Cloud Agent job may also draw on the context you have given it access to: the notes, saved memories, and calendar entries that its context scope selects are retrieved before the job runs and are included in what we send to the model. Kept records which items were used and why, and you can see that list on the job and exclude items from future runs. Kept executes the MCP request itself; the connected server address and bearer credential are not sent to the AI provider in this execution path. When you grant a Cloud Agent built-in web research or code workspace capabilities, the search queries it issues and the code and data it runs execute inside the model provider's hosted environment, subject to the same processing-only contract.
Daily priorities and practice suggestions. With Cloud AI enabled, a daily plan can use current tasks, goals, standing guidance, available time, and up to six relevant notes with up to 280 characters of authored text each to suggest outcomes. Suggested associations are not verified relationships. Opening the Habit Builder from a goal can use that selected goal and up to six existing practices to prepare a draft for your review. Local suggestions do not themselves send model requests. You review the practice before saving it. Manual capture and local search remain available with Cloud AI off.
Background memory reflection. While Cloud AI is on, Kept may review saved activity, relevant existing memories, and portions of your authored notes in small batches to update personal memories and briefings. This can include older notes, not only items saved that day. Kept keeps private progress and source references so work can resume after interruption and affected AI memories can be retired when their source notes are corrected or deleted. These references do not certify an AI interpretation as true. Later manual edits to a memory are preserved. Turning Cloud AI off stops future background AI requests; existing saved memories remain subject to your memory and account deletion controls. Kept also keeps private revision counters, output hashes, and bounded refresh records to check whether a saved context summary still matches your activity, permissions, and local day. These records do not duplicate the source text and are deleted with your account. A same-day recalculation can refresh that context without making another model request. Morning and Now briefings also use private publication and completion records to prevent outdated work from replacing a newer result. These records contain identifiers, hashes and timestamps rather than copies of briefing text. Current publication records are deleted with your account; scheduled completion records also follow the existing 30-day schedule-record cleanup.
Today’s goal read (iPhone).After you allow Cloud AI, opening a goal on iPhone may send part of that goal through our server to OpenAI or Anthropic so Kept can write that day’s read. We send the goal’s title; its north star, why it matters, and target date, each one only if you have written it; today’s date in your profile time zone; and a bounded selection of work explicitly linked to that goal from the modules you have enabled. This can include up to twelve tasks with their titles, due dates and completion states; six active practices with their recorded marks from the past fourteen calendar days; six notes with titles, dates, authorship labels and up to 600 characters of authored text each, including linked daily notes and saved assistant notes; six upcoming events with their titles and dates; and six completed focus sessions from the past fourteen calendar days with labels, times and recorded minutes. References identify the linked items used as sources. Saved prose is context, not verification that an action happened.
If Body is enabled, this read can also include logged-food aggregates from up to four active food metrics explicitly linked to this goal. Each uses its existing day, week, month, seven-day or twenty-eight-day window. We send the metric title, field, window, counts and resulting value, not raw meal names, ingredients, photos or Health records. We do not infer meal membership from the goal's title or life area, or send unrelated notes, conversations or work filed under other goals. Older iPhone versions continue to send only the goal fields and linked tasks described above. Mac goal reads remain on-device.
With Body and Cloud AI enabled, newer iPhone goal reads can also include up to six recorded workouts from the past fourteen days in your profile time zone. Each must belong to your account and link to the goal through a completed session in a training plan. We send its label, recorded date and time, distance, duration and activity type when available. This may include workout records you authorized us to sync from Apple Health. Planned or skipped sessions and workouts without that explicit plan link are excluded. We do not send continuous sensor streams or infer that an activity belongs to a goal from its name or life area.
Reads are cached for their goal, profile day, enabled modules and consent revision. The account limit is twelve attempts in the past twenty-four hours, including attempts that fail after the provider may have processed them. A content-free attempt record retains the account and goal references, context identifiers and reservation time for this limit; deleting a goal does not immediately reset its used allowance. Account deletion removes those records. Kept stores the generated read, its cited source labels and availability receipts with the goal; goal deletion removes the read. Changing enabled modules or granting Cloud AI again can require a new read within the same limit. Turning Cloud AI off stops future reads, prevents late results from being saved under the old permission, and removes cached cloud reads from the device.
Rendered public-source checks (Cloud Agents). When Browser Research is enabled for your personal workspace and you run public-web research, Kept may send up to four public HTTPS source addresses from that report to Browserbase so a temporary, read-only managed browser can render those pages. Browserbase processes the public pages and their rendered text for that check. Kept uses the bounded rendered text only long enough to look for the cited excerpt; Kept does not use this feature to sign in, submit forms, or open private or authenticated pages. We keep the cited public source address, a content digest, bounded evidence metadata and counts, and whether the cited excerpt was confirmed. We do not store the rendered page body or a browser screenshot through this feature.
We do not authorize OpenAI or Anthropic to use your content to train their general models, and we contract for limited, processing-only use. Provider security and abuse-monitoring retention may still apply under their service terms. Some features also use on-device processing. You can turn Cloud AI off at any time in Settings on iPhone or Mac. Turning it off stops future third-party model requests and background AI processing authorized by the Cloud AI control. Account sign-in, synchronization of your Kept items, deterministic features, and basic non-content product analytics continue to use our servers. The optional “Help improve Capture” permission is separate from Cloud AI, remains off until you explicitly enable it, and independently controls the bounded improvement processing described next. Turn that separate permission off to stop future improvement processing and remove its retained source samples. If Kept enables an authorized weekly improvement run, it may send a redacted summary of shared correction samples to OpenAI or Anthropic to propose generalized changes to Kept’s capture prompt. Those providers would process that material for Kept under the limited-use terms above; we do not authorize foundation-model training. Within that authorized run, source text remains temporary and is not copied into durable evaluation fixtures or prompt text.
Answer quality review. This separate review is disabled under the current Cloud AI permission. If Kept offers it later, we will update the disclosure and require you to allow the updated processing before any review request. For an eligible text-only turn, that request may send the latest question and that answer to Anthropic in a separate, short-lived model request to evaluate answer quality. We would not run this review for multi-turn, tool-grounded, action-card, artifact-only, image, or ambient-context-grounded turns, because the reviewer would not have the evidence needed to judge them accurately. The content-free records Kept would store include account and turn coordinates plus fixed eligibility, outcome, category/failure, score, surface, turn/tool/image, selected Skill identifiers, model/rubric, token/cost, date, and timing fields — not your question or the answer. This processing would remain subject to the provider terms described above.
We keep operational records of each AI request — such as the provider and model used, token counts, latency, estimated cost, and outcome — to monitor quality, reliability, and cost; these records do not include your content. AI output can be inaccurate; you are responsible for reviewing it.
Connected Google account (Cloud Agents).If you connect a Google account to Cloud Agents, Kept requests read access to Gmail only. Kept does not request the ability to send email, and it does not request the ability to create drafts either: in Google’s authorization model the scope that permits draft creation also permits sending, so Kept declines it rather than hold an ability it does not need. The practical effect is that Google itself refuses a send attempt from this connection, so the limit does not depend on Kept behaving correctly. Anything Kept drafts for you is held in Kept and never placed in your Gmail account. Kept fetches messages at the moment an agent works on them and does not store message bodies: our database schema has no column for them, and what we keep is derived, non-content structure such as message identifiers, participant addresses, subjects, timestamps, content digests (hashes), and short redacted previews. OAuth tokens are stored encrypted in our credential vault. Kept’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Mail you receive necessarily includes content written by your correspondents; Kept processes it solely to provide the Service to you, applies the same non-possession handling to it, and never uses it to train foundation models.
Calibration against your own history (the harvest).To measure how well a Cloud Agent would have handled your past decisions, Kept can replay decisions you already made (for example, how you scheduled events or handled messages) and score the agent’s agreement with what you actually did. The stored record of each replayed decision contains references, timestamps, difficulty labels, and content digests, never the underlying content, which is re-fetched from its source only while the comparison runs. These scores calibrate your own agent’s permissions and are deleted with your account. Agreement measured this way is published to you as a lower bound and is never described as accuracy.
6. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:
- Service providers (sub-processors) who process data on our behalf under contract, including:
- Supabase · database, authentication, and file storage.
- Vercel · application hosting and our API.
- OpenAI and Anthropic · optional AI processing of the content described above, only after you explicitly allow the applicable Cloud AI or Help improve Capture permission.
- Browserbase · optional rendering of public source pages for read-only Cloud Agent research verification, only after you explicitly allow Cloud AI.
- Apple · sign-in and push notification delivery (APNs).
- Google · sign-in and Google Calendar synchronization, if you connect them.
- Resend · delivery of sign-in, account, and optional lifecycle email, including delivery and engagement events described above.
- USDA FoodData Central and Open Food Facts · food and nutrition lookups (search terms only; no account identifiers).
- Legal and safety. When we believe disclosure is required by law or necessary to protect rights, safety, or the integrity of the Service.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
- With your direction. When you choose to share or connect a third-party service.
7. Your choices and controls
- Turn “Help improve Capture” on or off in Settings. It is off by default, independent of Cloud AI, and turning it off deletes retained Capture improvement samples before the change is confirmed.
- Allow or turn off Cloud AI in Settings, under Privacy. Turning it off stops future OpenAI, Anthropic, and Browserbase processing authorized by the Cloud AI control, and stops background AI reflection. Help improve Capture is controlled separately. Your account, synced Kept items, deterministic features, and basic non-content product events still use our servers.
- Manage or disable push notifications in the app and iOS Settings.
- Choose whether to receive lifecycle product guidance at kept.do/email-preferences. Every lifecycle message also supports one-click unsubscribe in compatible mail apps, includes a visible unsubscribe link, and lets you reply with the word “unsubscribe.” Withdrawing this choice stops future lifecycle email and does not affect account or security messages.
- Connect or disconnect Apple Health and Google Calendar at any time.
- Revoke a customer-configured MCP connection to disable its credential and dependent agent tools. You can inspect and repair a connection before granting changed tools again.
- Ask Kept to “forget” saved memories.
- Edit or clear your assistant context, remove saved assistant contacts, and pause, edit, or delete personal Skills from the controls available in the Kept app. A Skill edit remains pending until the revised version passes its required review.
- Delete your account in Settings in the Kept iOS or Mac app. Deletion is permanent and removes your account and associated personal data from our active systems as described in Section 9. You can also email privacy@thesis.do to request access, correction, or deletion if you cannot use the in-app control.
8. Your privacy rights
8.1 California residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to request access to and deletion or correction of your personal information, and to not be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising, and we do not knowingly process the personal information of minors for such purposes. To delete your account and associated personal information, use Delete account in Settings in the Kept app, or contact us at privacy@thesis.do. For other requests, contact the same address. We will verify your request using information associated with your account, and you may use an authorized agent.
8.2 EEA, UK, and Switzerland (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, Thesis Labs, LLC is the controller of your personal data. We process it on the legal bases of performance of our contract with you, your consent for optional processing where this policy expressly asks for it, our legitimate interests in operating, securing, and improving content-free aspects of the Service, and compliance with legal obligations. Help improve Capture relies on consent, not legitimate interests. You may withdraw consent at any time. You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. Where we transfer data outside your region, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses. To erase your account data, use Delete account in Settings in the Kept app, or contact privacy@thesis.do. For other rights, contact the same address.
9. Data retention
We keep personal information for as long as your account is active or as needed to provide the Service, and afterward only as required to comply with legal obligations, resolve disputes, enforce our agreements, or support the limited deletion-safety and recordkeeping purposes described below. When you delete your account in the app or we complete a verified deletion request, we delete or de-identify your personal information from our active systems within a commercially reasonable period, typically within 30 days, except where retention is required by law or for the limited records below. Backups are purged on a rolling schedule.
Account deletion removes your Auth identity, profile, notes, tasks, events, habits, meals and meal photos, health summaries we store, memories, captures, imported meeting notes, push device tokens, connected Google Calendar tokens and synced events, MCP agent connections, assistant context, saved assistant contacts, personal Skills and their revisions and bounded evaluation examples, Cloud Agent responsibilities and their supporting document context, review receipts and content-free candidate signals, task and note provenance and the Ask records described above, cached cloud goal reads, bug-report records, and related owner-scoped data. We also remove waitlist rows, beta-access application rows, and creator-program application rows that use the same email address as your account, along with lifecycle email preferences, enrollments, and account-linked delivery records. Operational model-call logs may retain non-identifying metadata after the user id is cleared. Where an address is not linked to an account, we may retain a minimal suppression record as needed to honor an unsubscribe or comply with law, and do not use that record to send lifecycle email.
Personal Skills and their immutable revisions are kept while your account is active so the product can preserve the behavior you approved; you may delete a Skill sooner. Content-free, account-linked Skill discovery signals expire within 90 days. We retain only five-account-or-larger, identifier-free monthly Skill trend counts for up to 10 years. Because those trend rows contain no account, event, or authored content, they cannot be attributed back to an account or removed account-by-account.
Capture improvement samples shared under the separate permission expire within 365 days and are removed sooner when you turn that permission off or delete your account. We keep content-free grant and withdrawal evidence while the account exists, and narrow content-access audit records for up to two years, so we can enforce and demonstrate the permission boundary. Capture text stored under the prior “Store my capture text” setting remains linked to your account and subject to account deletion and verified privacy requests. The new “Help improve Capture” permission does not enroll that historical text, even if you turn it on later, and active mining and analytics do not use it. We will separately review and notify you before changing that treatment.
Habit Builder opening and schedule-opportunity detail is available only to the service, is deleted with its owner, and expires no later than 90 days after creation. The scheduled purge also clears only the optional random correlation pointers from an existing habit; it does not delete the habit itself. Any longer-lived Habit Builder reporting is aggregate-only and does not retain the random opening identifier or authored habit content. The account-scoped on-device delivery journal removes successfully acknowledged deliveries, keeps a pending entry eligible for retry for 90 days, prunes it the next time the journal loads or is cleaned after that window, and is cleared for that account on permanent account deletion.
Cloud Agents keep durable, content-free operating records so that agent behavior stays auditable: run events, policy decisions, activity receipts and notification-delivery state, action receipts, the evidence ledger that underlies an agent’s published standing, and replayed-decision records (references and digests, described above). These records are the audit trail itself; they contain identifiers, verdicts, timestamps, and digests rather than your words. A rendered public-source check also keeps its source address, content digest, and evidence counters, but not the rendered page body or a screenshot. These records are deleted with your account. Replayed-decision records also expire on their own retention schedule without account deletion.
A responsibility’s title and intended outcome, your answers and attestations, and supporting document context are user content, not content-free operating records. We keep that content while it remains in your account and delete it with your account.
On your device, Kept may temporarily keep a content-free deletion recovery receipt containing the account ID and deletion time until local removal is verified. That receipt is removed after cleanup succeeds. A separate content-free deletion-safety marker associated with the account ID may remain on the device so stale app extensions or background work cannot recreate deleted-account data.
On our servers, we retain a one-way hash of the deleted account ID as a deletion-safety marker so requests using credentials issued before deletion cannot recreate account data. The device and server safety markers contain no name, email address, notes, captures, tokens, or other account content and are used only to enforce deletion.
After deletion we may retain a de-identified record of redeemed or applied financial benefits (for example Founding Practice complimentary months or discounts), including amounts, benefit type, status, and store transaction identifiers, without your email, name, or account id. We keep these records only as needed for fraud prevention, tax, accounting, and dispute handling. Deleting your Kept account does not cancel an App Store subscription; manage or cancel subscriptions in your Apple ID settings.
Company workspace records are controlled and retained at the organization level under its configured policy and any applicable legal hold. Deleting an individual account removes that person’s access and personal account data, but does not automatically delete shared organization jobs, artifacts, approvals, or audit history that other members rely on. Where practical, the departing person’s identifier is removed or retained only as needed for security, audit integrity, disputes, or legal obligations.
For a Cloud Agents organization’s governance audit trail specifically, deleting your account clears your account identifier from the events you acted on and marks each of those events as actor-redacted, so the removal is recorded rather than silent. The events themselves are neither deleted nor rewritten: their event type, target, outcome, policy version, metadata, timestamps, and both recorded hashes stay exactly as written. This is not anonymization. Event metadata and the surrounding record can still identify who acted, and an audit export the organization downloaded before your deletion is unchanged and still contains your account identifier. Because an event’s recorded hash was computed over that identifier, a redacted event’s own hash can no longer be recomputed from the values that remain. The recorded links between neighboring events are unaffected, which is evidence of an intact sequence rather than proof against every possible alteration.
Kept Workplace records · todos, plans, docs, the append-only ledger, files, comments, and agent identities and scopes · are retained for as long as the organization’s workspace is active, the same as other company workspace records above; a deleted file’s bytes follow the thirty-day removal described in Section 3.7. An organization admin can request export or deletion of that workspace’s data by contacting privacy@thesis.do. We honor that request today; it is not yet a self-service control in the product.
10. Security
We use technical and organizational measures designed to protect your information, including encryption in transit, encryption at rest, and row-level access controls so users can access only their own data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Staff access. Authorized Kept personnel may access your content when reasonably necessary for support you request, bug triage, incident response, abuse review, or legal process. Direct database access exists as a break-glass procedure limited to named people; it is procedural rather than architectural.
11. International data transfers
We and our service providers may process and store information in the United States and other countries that may have data protection laws different from those in your jurisdiction. Where required, we use appropriate safeguards for these transfers.
12. Children’s privacy
The Service is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact privacy@thesis.do and we will take appropriate steps to delete it.
13. Third-party links and services
The Service may link to or interoperate with third-party products and services. Their privacy practices are governed by their own policies, and we are not responsible for them.
14. Health and informational disclaimer
Kept’s nutrition, fitness, and coaching content is for informational and general wellness purposes only. It is not medical, nutritional, or professional adviceand is not a substitute for consultation with a qualified professional. Do not rely on the Service for medical decisions. The Service and all content are provided “as is” and “as available” without warranties of any kind, to the maximum extent permitted by law.
15. Limitation of liability and governing law
To the maximum extent permitted by applicable law, Thesis Labs, LLC and its officers, members, employees, and agents will not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, profits, or goodwill, arising out of or relating to your use of the Service. This Policy is governed by the laws of the State of California, without regard to its conflict-of-laws rules, and any dispute will be resolved in the state or federal courts located in California, unless applicable law requires otherwise. If any provision of this Policy is found unenforceable, the remaining provisions remain in full effect.
16. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
17. Contact us
Thesis Labs, LLC
Email: privacy@thesis.do
Web: thesis.do