Skip to content
Privacy

Privacy Policy

Last updated 1 August 2026. Written to be read, not to be survived.

The short version

  • Your photos are never used to train any model, ours or anyone else's.
  • We never sell or rent your personal data, and we do not run advertising.
  • Cloud libraries are connected read-only. We never modify or delete anything in them.
  • You can export everything or delete everything at any time, and deletion is real.
  • Data is encrypted in transit (TLS 1.3) and at rest (AES-256).

Everything below is the detail behind those five lines. Where the two ever appear to disagree, the detail governs, and please tell us through the contact form so we can fix the summary.

1. Who we are

keepsi.ai ("keepsi", "we", "us") provides software that turns personal photo libraries into printed and digital photo books. For users in the EU and UK we act as the data controller for account data, and as a processor for the photo content you upload. Contact us through the contact form, choosing the privacy topic.

2. What we collect

Photos and media

The images you upload or connect, plus the metadata already inside them: capture time, camera settings, and location if your camera recorded it. You can strip location before upload in settings.

Account data

Email address, name if you give one, password hash, and your language and region. We use a third-party authentication provider and never see your password in plain text.

Order data

Shipping address, order history and delivery status. Card details go directly to our payment processor; we store only the last four digits and the brand.

Product usage

Which features you use, error reports, and performance timings. Aggregated wherever it can be. We do not use third-party advertising or cross-site tracking cookies.

3. What we do with it

We process your photos to do the thing you asked for: select images, group them into chapters, generate captions, apply the enhancements you approve, lay out pages, and produce a print file. We process account and order data to run your account, take payment, and get a book to your door. We process usage data to fix bugs and decide what to build next.

What we never do: use your photos or captions to train machine learning models; share your photos with anyone outside the processors listed in section 5; sell, rent or trade any personal data; use your content in marketing without separate, specific, written permission you can withdraw.

4. Legal bases (EU and UK)

Contract: processing photos, running your account and fulfilling orders. Legitimate interests: security, fraud prevention, and aggregate product analytics, balanced against your rights. Consent: optional marketing email, and any use of your content as an example. Legal obligation: tax and accounting records.

5. Who we share with

Only the processors we need to deliver the product, each under a data processing agreement and each limited to what their job requires:

  • Cloud hosting and storage — to store your library and run processing.
  • Print partners — receive only the finished print file and the shipping label, never your library.
  • Payment processor — handles card data directly; we never receive full card numbers.
  • Email and support tooling — for transactional email and your support conversations.
  • Error and performance monitoring — receives technical diagnostics, not photo content.

We may also disclose data if legally compelled. Where the law allows, we will tell you before we do, and we publish a transparency count annually.

6. Where your data lives

Accounts created in the EU or UK are stored in EU data centres and printed by EU partners. Accounts elsewhere default to US storage. Where data crosses borders we rely on Standard Contractual Clauses and the UK International Data Transfer Addendum. You can request EU-only processing at any time.

7. How long we keep it

DataKept forThen
Photos in an active projectUntil you delete the projectRemoved from live systems immediately
Deleted projects and photosUp to 30 days in backupsPermanently purged
Print files90 days after deliveryDeleted (so reprints stay possible)
Account recordUntil you close the accountDeleted within 30 days
Order and tax records7 yearsLegally required retention

8. Your rights

You can access, correct, export, restrict, object to, or delete your data. Export and deletion are self-service in account settings and take effect immediately. Anything else, use the contact form and we will respond within 30 days, and usually within two business days. You may also complain to your local supervisory authority, though we would rather you told us first.

9. Children

keepsi.ai is not for people under 16. We do not knowingly create accounts for them. Photos of children uploaded by an adult account holder are treated exactly like any other photo: never used for training, never shared, never used to identify anyone outside your own account.

10. Security

TLS 1.3 in transit, AES-256 at rest, least-privilege internal access with audit logging, annual third-party penetration testing, and a security contact reachable through the contact form. If we ever suffer a breach affecting your data, we will notify you and the relevant regulator within 72 hours of becoming aware.

11. Cookies

We use strictly necessary cookies for sign-in and security, and first-party analytics cookies you can decline without losing any functionality. No third-party advertising or cross-site tracking cookies are set, ever.

12. Changes

If we change this policy in a way that materially affects you, we will email you at least 30 days before it takes effect and keep the previous version available for comparison. Silence is not consent; you can close your account instead.

Questions about any of this?

Privacy questions get answered by a person who works on the product, not a form.

Contact us