Last updated: 4 August 2026
Nothing you write is ever stored by us, so most of this page is about how little there is to hold.
Your board is plain text files in a private GitHub repository you own. When you use the board here, your browser reads and writes it by talking directly to GitHub, so it does not pass through Kept's servers at all. We have no database and we keep no copies.
Kept can be connected to an AI assistant so it can read your board for you. That is the one case where your board does travel through Kept: we fetch it from GitHub and pass it straight on to the assistant that asked. It is held in memory only for the seconds that takes, it is never written to disk, never put in a database, and never kept afterwards. If you never connect an assistant, this never happens.
When you sign in, GitHub sends a one-time code to Kept's sign-in endpoint, which exchanges it for an access token and hands that token straight to your browser. The token lives in your browser only. We do not store it and we do not log it. When it expires, your browser trades its refresh token for a new one through the same endpoint, which likewise stores nothing.
One. A ten-minute security cookie during sign-in that protects you against forged logins. It applies only to the sign-in endpoints and is cleared the moment sign-in completes. No tracking cookies, no ad pixels, nothing that follows you around.
Anonymous counts of page views, through Cloudflare Web Analytics, which sets no cookie and does not follow you between sites. It never includes the contents of your board. Nothing else is measured.
If you connect an AI, we store one timestamp: when that connector was last used. No board content, and nothing about what was read. It exists so the setup screen can tell you the connection is working instead of leaving you to guess, and it is discarded after thirty days of no use.
Pressing "Tell me when it opens" stores one record: your GitHub username and the date you pressed it. Nothing else, and only if you press it. It exists so we can tell you when the paid tier opens, and for no other purpose.
gokept.app is served by Cloudflare. Like any host, Cloudflare processes requests in order to answer them and keeps its own operational logs, covered by Cloudflare's privacy policy. Kept itself writes no logs of your board activity.
Your board lives in your GitHub account and your sign-in happens on GitHub, under GitHub's privacy statement. Kept's GitHub App can reach only the repositories you grant it. You can see and revoke that access any time in your GitHub settings.
If you ever pay for Kept, we keep exactly one record: your GitHub id, which tier you are on, and until when. Stripe holds your card and your invoices; we never see the card. Cancel any time from the billing portal, and the record simply says free again. If you never pay, there is no record of you at all.
If you write to hello@gokept.app, we will have your email address and whatever you wrote. We use it to reply, nothing else.
Uninstall the Kept app from your GitHub settings and, if you want, delete your board repository. That is the whole process. Nothing remains with us, because nothing was with us.
If this policy changes in a way that matters, we will say so on the site rather than quietly edit this page.
hello@gokept.app