Privacy Policy
Last updated 12 September 2026
Contents
- Who this policy is from
- The short version
- What we collect
- How your saves reach us
- What we do to a save
- AI processing
- Search
- Playing and opening saves
- Notifications
- Usage measurement
- Why we are allowed to do this
- Who else touches your data
- Where your data goes
- How long we keep it
- Your rights
- If you are in the EEA or UK
- If you are in the United States
- If you are in India
- Children
- If your post is in someone's library
- Security
- Deleting everything
- Changes to this policy
- Contact
1. Who this policy is from
Allkept is a mobile app that gathers the things you save on other platforms into one private library you can search. This policy covers the Allkept iOS and Android apps, the Allkept Instagram account @allkeptapp, the Allkept backend, and the pages on allkept.app.
The controller of your personal data — the "Data Fiduciary" under India's DPDP Act and the "controller" under the GDPR — is MECA Engineering Solutions (OPC) Private Limited, 4th Floor, No. 19, Urban Vault, 18th Cross Road, Sector 7, HSR Layout, Bengaluru, Bengaluru Urban District, Karnataka 560102, India, operating from India. You can reach us at hi@allkept.app.
"We", "us" and "our" mean that entity. "You" means the person using the app.
2. The short version
- Your library is private to your account. Nobody else, including other Allkept users, can read it.
- We do not sell your data and we do not share it for advertising. There is no ad network, no tracking SDK and no third-party analytics SDK in the app.
- To sort and search your saves we send the text of each save, and the words you type into the search box, to OpenAI. Nothing else is sent to an AI provider, and you can turn the sorting off in Settings.
- Notifications are off until you turn them on, and we store nothing about your device until you do.
- We fetch the public preview of each link you save — title, description, author, thumbnail — from our own servers, not from your phone.
- Raw Instagram message events are deleted automatically after 30 days. Everything else stays until you delete your account.
- You can delete your account and everything in it from Settings inside the app. It is immediate and permanent.
3. What we collect
This is the complete list, taken from the database itself. There is nothing else.
3.1 Account and sign-in
| What | Where it comes from |
|---|---|
| An account identifier (a random UUID) | Created by us when you first sign in |
| Your email address | Your Google Account or your Apple ID, depending on which you signed in with |
| The basic identity record from that provider — the provider name, your user id there, and the basic profile fields it returns | Google or Apple, through our authentication provider |
| When you created the account and when you last signed in | Recorded by us |
You sign in with Google or with Apple. Either way we ask only for basic identity, profile and email. We never receive your password, and we have no access to Gmail, iCloud, Drive, Contacts or any other service of theirs.
If you sign in with Apple and choose Hide My Email, we receive Apple's private relay address rather than your real one. That address is all we have and all we will ever write to. It still reaches you, and you can switch it off at any time in your Apple ID settings.
Some early test-phase installs hold a "guest" library that was created on the device without any sign-in. If your phone still has one, the app can restore it and then attach it to a Google or Apple account. That stored session lives in your phone's secure keychain, not on our servers.
3.2 Your profile
After signing in, the app asks for a display name and nothing else before you can use the library.
| Field | Required? | Notes |
|---|---|---|
| Display name | Required | Up to 80 characters. Whatever you choose to type. |
| Profile photo | Optional | Added from Settings if you want one. A JPEG you pick from your photo library, cropped square and reduced to at most 512 × 512 pixels on your phone before it is uploaded. Kept in a private bucket only your account can read. |
We do not ask for a phone number. Early test builds did, as an optional field; those numbers were deleted on 11 September 2026 and nothing accepts one any more.
The app asks permission to open your photo library only at the moment you choose a profile photo. It never uses your camera or microphone, and it never reads your photo library in the background.
3.3 The doors you connect
| Door | What we store |
|---|---|
| Your Instagram-scoped user id — an identifier Meta issues that is specific to your conversation with us and cannot be used to look you up elsewhere — your Instagram username, when the connection was made, when we last heard from it, and whether you want confirmation replies in the thread. | |
| YouTube | The playlist id you gave us, the playlist's title, its channel title, how many videos it holds, and when we last checked it. We never ask for or hold a Google or YouTube login for this: a public or unlisted playlist is readable with our own API key. |
| Linking codes | The six-character code the app shows you, when it expires (ten minutes) and when it was used. |
3.4 Your saves
| What | Detail |
|---|---|
| The link itself | Platform, the kind of thing it is, the URL you sent, the tidied ("canonical") URL, and the platform's own id for it |
| Public details about it | Title, caption or description, author name and author handle, taken from the platform's public preview |
| A thumbnail | Copied into a private storage bucket only your account can read — up to 4 MB, JPEG, PNG, WebP or HEIC. We also keep the remote address it came from. |
| Technical details about the media | The preview provider and type, the thumbnail's dimensions, a YouTube video's aspect ratio, the publishing site's name, and the reason a fetch failed when one did |
| Your own words | Any note you type onto the card, and any text you sent alongside a link |
| Timing | When you saved it, when you last saved it, how many times, and its processing status |
| A record of the capture | The exact instruction the door handed to us: the URL, caption, title or media id. Free text you sent is replaced by a marker here and kept in the save's own text and note fields instead, so it is not stored twice. |
3.5 What the sorting produced
For each save we store the category it was filed under (one of fourteen), up to five tags, a one-sentence summary, the named entities found in it (places, products, recipes, tools, people, brands), a language code, an "actionability" label (watch, try, buy, go, read, reference, none), a confidence score, the model that produced it, the prompt version, and the token count and cost of the call. If you correct the category, your correction is stored separately and is never overwritten by the model. If sorting fails, the failure message is stored.
3.6 The search index
For each save we build one combined text document out of its platform, title, text, your note, author name and handle, its URLs, its category, tags, summary and entity names — and a 512-number vector ("embedding") of that document, which is what lets you search by meaning rather than by exact words. Both belong to your account and are readable only by you.
3.7 Instagram message events
When you message @allkeptapp, Meta sends us a webhook. We store the whole message event as Meta sent it, plus up to 20,000 characters of the raw request body, the sending and receiving Instagram-scoped ids, and the timestamps. This is the working record that lets us recover a save that failed to process. These rows are deleted automatically 30 days after they arrive, by a job that runs every day.
We also store each confirmation message we send back into the thread: its text, the recipient's Instagram-scoped id, when it was due, when it went out, and any send error.
3.8 Bringing in older Instagram saves
If you use the import feature, you upload the "saved posts" export that Meta gives you. The file goes into a private folder only your account can write to and read. Our server downloads it, reads the Instagram post links out of it, and deletes the file immediately afterwards. We keep only a record of the run: how many saved posts were found, how many were added, how many were already there, any error, and the timestamps. We do not read, keep or index any other part of your Meta export.
3.9 Your switches
Four settings are stored on your profile: whether to send notifications at all, whether to tell you when a save lands, whether to tell you when a save needs you, and whether saves may be sorted automatically. Every one starts in the position the app already behaved in, so nothing changes for you until you move one.
3.10 Notification devices
If you turn notifications on, we store a push token for each device — see section 9. Nothing is stored while notifications are off.
3.11 Feedback you send us
If you use Send feedback in Settings, we store the message you wrote (up to 4,000 characters), the app version and platform it was sent from, when you sent it, and your account, so we can reply. Nobody can read feedback back through the app — not even the person who wrote it.
One exception to deletion. If you later delete your account, we keep the message but detach it from you: your account link is cleared, and the address we could have replied to disappears with it. We keep it because it is a report about the product, not a record about a person. If you want a message you sent removed entirely as well, ask us at hi@allkept.app and we will delete it.
3.12 Usage measurement
See section 10. It is a short fixed list, and it never contains anything you typed.
3.13 The launch waitlist on allkept.app
If you join the waitlist on allkept.app we keep the email address you give us, which of the two sign-up boxes you used, when you gave it, your browser's name, and a hashed form of your network address to stop abuse. We use it to send you one email when Allkept opens, and to nothing else. You can ask us to remove it at hi@allkept.app.
3.14 What we do not collect
- No advertising identifier (IDFA or GAID), no device fingerprint, no ad network, no attribution SDK.
- No third-party analytics or crash-reporting SDK. There is no Firebase, Sentry, Amplitude, Mixpanel, PostHog or Segment in the app.
- No location of any kind, precise or coarse.
- No contacts, calendar, health, camera or microphone access.
- No payment or card details. Allkept is free and takes no payments.
- No passwords. Sign-in is handled by Google and we never see one.
- No browsing history, and no reading of your other apps.
4. How your saves reach us
Instagram direct messages
You link your Instagram account by sending a six-character code to @allkeptapp.
From then on, anything you send to that account — a reel, a post, a link, or a line of text — becomes a
save. We only ever see the messages you send to us. We cannot see your Instagram feed, your
followers, your other conversations, your stories or your own saved-posts collection, and we never post
or message on your behalf. We reply only in the thread you started, and only to confirm a save; you can
turn those replies off by sending stop replies, or from Settings in the app.
Some Instagram post shares arrive without the original link, because Instagram does not include one. Those become a card with no link until you supply one.
A YouTube playlist
You give us the link to a playlist of your own. We check it on a schedule — every fifteen minutes while it is active, backing off to once a day when nothing changes — and anything new in it becomes a save. We read it with our own YouTube API key. We never ask for your Google or YouTube account, and we cannot see anything but that one playlist. YouTube does not let anyone read Watch Later or Liked videos, including us.
Links you paste or share
You can paste a link into the app, or share one into Allkept from another app's share sheet. That link, and any text you sent with it, becomes a save.
5. What we do to a save
- We fetch the public preview. Our server — not your phone — asks the platform's
public oEmbed endpoint, or reads the public Open Graph tags on the page, for the title, description,
author and thumbnail. The request identifies itself as
AllkeptBot/0.1. Because this happens on our server, the site you saved from never sees your IP address or your device. If a post is private or the platform refuses, the card simply has no preview. - We store the thumbnail in private storage, so your library still shows a picture after the platform's temporary image link expires.
- We ask YouTube for a video's shape — its width and height only — so a vertical video is not drawn inside black bars.
- We sort it. See section 6.
- We index it for search. See section 7.
6. AI processing
To put a save into a category, we send a single request to OpenAI containing:
- the platform and the kind of thing it is,
- its link,
- its author,
- its title, up to 300 characters,
- its caption or text, up to 1,500 characters, and
- your own note on it, up to 300 characters.
We do not send your name, your email, your photo, your account identifier, your other saves, or anything else about you. The model returns a category, tags, a summary, entities, a language code, an actionability label and a confidence score, and that is what we store.
The model in use today is from OpenAI's GPT-5.6 family; a cheaper tier of the same family is used
when someone imports a large back catalogue at once. We send these requests with OpenAI's
store option switched off, which asks OpenAI not to retain the request. We do not control
OpenAI's own handling of API data — see
OpenAI's privacy policy.
You can switch the sorting off. In Settings, turn Sort saves automatically off. From that moment no save of yours is sent to the AI provider to be categorised: the check happens on our server, immediately before the call would be made, so it is a promise about what leaves our systems rather than about what the app chooses to ask for. Saves still arrive and still appear in your library; they simply arrive uncategorised. Categories worked out before you switched it off are kept, and deleting a save removes them.
Be aware of what that switch does not cover. Building the search index is a separate step, and it is not affected: the text of a save is still sent to OpenAI to produce its search vector, so that meaning-based search keeps working. If you want nothing at all about a save to reach OpenAI, do not save it — or delete it, which removes its vector with it. the switch also stops search indexing
If we ever change AI provider, we will update this policy before the change goes live.
Sorting is automated, and it is not a decision about you. It produces a label on a saved link. It has no legal or similarly significant effect on you, and you can overrule any category by tapping a different one.
7. Search
Search works two ways at once. Keyword matching happens entirely inside our database. Meaning-based matching needs a numeric vector of what you typed, so the words you type into the search box are sent to OpenAI's embeddings API to produce that vector.
We do not store your search terms. The vector is held in memory on the server for at most five minutes, so that paging through results and live refreshes do not repeat the call, and then it is gone. If OpenAI is unavailable, search quietly falls back to keyword matching and nothing leaves our servers at all.
Every search runs as you, against your own library only. A search cannot return another person's saves.
Building the search index is separate from sorting, and the Sort saves automatically switch does not turn it off: a save's text is still sent to OpenAI to produce its search vector. See the note in section 6.
8. Playing and opening saves
When you open a save, Allkept shows the platform's own embed inside the app — Instagram's embed
page, or YouTube's privacy-enhanced youtube-nocookie.com player. That page is loaded
by your phone, directly from Instagram or YouTube. Those companies therefore see your
IP address, your device's user agent and the fact that the embed was requested, and they may store
data inside the app's web view, exactly as they would if you had opened the post in a browser. That is
their processing, under their own privacy policies, not ours.
The same applies when you tap through to the original: Instagram and YouTube links open in their own apps, and everything else opens in an in-app browser.
9. Notifications
Allkept can send you a push notification when a save has finished sorting, or when a save needs something from you. Notifications are off until you turn them on.
The app asks your phone for permission at the moment you turn the switch on in Settings, and never before — not on first launch, and not anywhere else. If you refuse, Allkept cannot ask again; only your phone's own settings can undo that.
What we store
When you turn notifications on, we store one row per device: the push token your phone's operating system issued for this app install, whether the device is iOS or Android, when it was registered, when it was last seen, and — if the push service later refuses the token — when and why. A push token identifies an app installation, not you, and it cannot be used to read anything on your phone.
The row is keyed on the token, so a phone that signs out and signs in as somebody else moves to the new account rather than continuing to announce the previous owner's saves. Turning the switch off, and signing out, both delete the row.
We also store your four switches on your profile: notifications on or off overall, whether to be told when a save lands, whether to be told when a save needs you, and whether saves may be sorted automatically at all (see section 6).
What a notification contains, and who sees it on the way
A notification carries a short line of text and the identifier of the save it is about, so tapping it opens that save. The text names the save — for example, "<the save's title> is in Food & recipes" — which means the title and category of something you saved can appear on your lock screen, and passes through the push infrastructure on the way to you:
- Expo's push service, which we send to;
- Apple's Push Notification service on an iPhone, or Google's Firebase Cloud Messaging on an Android phone, which Expo forwards to.
On Android, notifications are delivered on a channel set to hide their contents on a locked screen. On iPhone, whether a locked screen shows previews is your own iOS setting. If you would rather none of this leave your device, leave notifications off — nothing is sent, and no token is stored.
10. Usage measurement
The app records a short, fixed list of things you did, so we can tell whether Allkept is worth building. It is stored in our own database against your account — there is no third-party analytics service anywhere in the app — and only you and our administrators can read it.
This is the entire list of events, and everything recorded alongside each one:
| Event | What is recorded with it |
|---|---|
| App opened; library viewed; save opened | Nothing but the time |
| Search | How many characters you typed and how many results came back — never the words themselves |
| Note saved | How many characters the note was — never the note |
| Category changed | The category it was, and the category you chose |
| Original opened | Which platform |
| Save shared out | Whether it had a link |
| Save deleted | Its processing status |
| Link pasted onto a card | The resulting status |
| Instagram linking started, and completed | Nothing but the time |
| Import opened, started, finished or failed | The size of the file in bytes; how many posts were found, added and skipped; or which step failed |
This log is append-only: once a row is written, not even we can edit it. It is deleted when you delete your account.
11. Why we are allowed to do this
If the GDPR applies to you, these are the lawful bases we rely on. If you are in India, see section 18, where consent is the basis for everything.
| Purpose | Lawful basis |
|---|---|
| Creating and running your account; storing your saves; showing and searching your library; fetching public previews; sorting saves into categories; building the search index | Performance of a contract — Article 6(1)(b). This is the service. |
| Keeping raw Instagram message events for 30 days so a failed save can be recovered, and keeping a record of the replies we sent | Legitimate interests — Article 6(1)(f): running the service reliably and being able to explain what happened to a save |
| Usage measurement (section 9) | Legitimate interests — Article 6(1)(f): understanding whether the product works, on the minimum possible data and with no third-party trackers our legitimate interests in understanding how Allkept is used and keeping it working |
| Profile fields — name, and a photo if you add one | Performance of a contract — Article 6(1)(b): a name is how the app addresses you and how your library is shown as yours. The photo is yours to add or remove, and nothing depends on it. |
| Sending push notifications, and storing the device token that makes them possible | Consent — Article 6(1)(a). Notifications are off until you switch them on, and switching them off withdraws it. |
| Feedback you choose to send us, and keeping it after your account goes | Legitimate interests — Article 6(1)(f): improving the product. The message is detached from you at deletion, and we will delete it outright on request. |
| Security, preventing abuse of the Instagram door, and administering the service | Legitimate interests — Article 6(1)(f) |
| Complying with a legal obligation, when one applies | Article 6(1)(c) |
Where we rely on legitimate interests, you have the right to object — see section 15.
12. Who else touches your data
We do not sell your personal data and we do not share it for advertising. We do use the following service providers, who process data on our instructions:
| Who | What they do | What reaches them |
|---|---|---|
| Supabase | Our database, authentication, file storage, background jobs and server functions — the entire backend | Everything described in section 3 |
| OpenAI | Sorts saves into categories, and turns saves and search terms into vectors for search | The content of a save (section 6), the text of its search document, and the words you type into search |
| Meta (Instagram) | Delivers the messages you send to @allkeptapp, tells us your Instagram username, delivers our replies, and serves public post previews and embeds | Your Instagram-scoped id, the text of our replies, and the post links we ask for previews of |
| Google (YouTube Data API) | Tells us what is in the playlist you connected, and a video's dimensions | The playlist id and video ids — not your identity |
| Google (Sign in with Google) and Apple (Sign in with Apple) | Sign you in | Whatever they show you on their own consent screen; we receive your basic identity and an email address — Apple's private relay address if you chose Hide My Email |
| Expo (EAS) | Builds the app, delivers over-the-air updates, and — only if you turn notifications on — delivers push notifications | Your device asks Expo whether a newer version exists. If notifications are on, Expo also receives your push token and the text of each notification. |
| Apple Push Notification service and Google Firebase Cloud Messaging | Carry a notification the last step to your phone — only if you turn notifications on | Your push token and the text of the notification, which names the save |
| Apple and Google Play | Distribute the app | Whatever their own store terms cover. We receive no personal data from them beyond aggregate figures. |
| The sites you save from | Serve the public preview of the link | Our server's request for that public page — never your IP or your device. (Embeds are different: see section 8.) |
| Vercel Inc. (static hosting for allkept.app) | Serves this page and the other pages on allkept.app | Ordinary web server logs for visits to these pages |
We may also disclose data where we are legally required to, or to establish or defend legal claims. If Allkept is ever sold or transferred, your data would move with it, and we would tell you before it did.
13. Where your data goes
We operate from India. Our providers are based outside India and outside the EEA, principally in the United States. Using Allkept therefore involves transferring your personal data internationally.
Our backend is hosted in Mumbai, India (ap-south-1). For transfers out of the EEA or the UK we rely on the Standard Contractual Clauses, and the UK Addendum where applicable, as incorporated in each provider's data processing agreement. India's DPDP Act permits transfer to any country the Government has not restricted; we will update this section if that changes.
14. How long we keep it
| What | How long |
|---|---|
| Raw Instagram message events | 30 days, then deleted automatically by a job that runs daily |
| An uploaded Instagram export file | Deleted as soon as it has been read, normally within seconds. A file left behind by an interrupted run is removed within an hour. |
| Instagram linking codes | Valid for ten minutes, and replaced whenever you ask for a new one |
| Your library, profile, switches, connections, categories, notes, thumbnails, search index and usage log | Until you delete your account, which removes them immediately |
| Confirmation replies we sent into your Instagram thread | Until you delete your account |
| Notification device tokens | Until you turn notifications off, sign out, or delete your account. A token the push service permanently refuses is marked dead and stops being used, and is removed with your account. |
| Feedback you sent us | Kept after your account goes, with your account link and reply address removed — see 3.11. Ask us and we will delete it outright. 24 months |
| Administrative audit records — which administrator queued which save for another attempt, and when | Kept for accountability. They hold the identifier of the save, not your name, email or account id; once your account is deleted, the save it points to no longer exists. 12 months |
| Server logs and provider backups | Governed by our providers' own retention backups and server logs are retained by Supabase for up to 7 days |
15. Your rights
Wherever you live, you can ask us to:
- Show you what we hold about you;
- Correct anything wrong — your name and photo are editable in the app at any time, and any category can be changed by tapping a different one;
- Delete everything — see section 22;
- Restrict or object to processing we base on legitimate interests;
- Receive a copy of the data you gave us, in a portable form;
- Withdraw a consent you gave, without affecting what happened before you withdrew it;
- Complain to your data protection authority.
Please note: Allkept does not yet have a self-service export button. Until it does, email hi@allkept.app from the address you signed in with and we will assemble a copy by hand. We will respond within 30 days.
We verify a request by checking that it comes from the email address on the account. We will not act on a request we cannot tie to an account.
16. If you are in the EEA or UK
You have the rights in Articles 15 to 22 of the GDPR, as set out above, and the right to lodge a complaint with your national supervisory authority. Allkept is not offered to users in the European Economic Area or the United Kingdom: we do not make the app available in those App Store or Google Play territories, and we do not target or market it there. Because we do not offer goods or services to people in the EEA or UK, we have not appointed a representative under Article 27 of the GDPR or its UK equivalent. The rights described above are honoured for anyone who asks, wherever they are — if you believe we hold your data, write to us and we will act on your request. We have not appointed a Data Protection Officer under Article 37 no Data Protection Officer is required.
We do not carry out profiling that produces legal or similarly significant effects. Category sorting is automated, but has no such effect — see section 6.
17. If you are in the United States
In the last twelve months we have collected the following categories of personal information under the CCPA as amended by the CPRA, for the purposes and from the sources described above:
| CCPA category | Collected? | Examples in Allkept |
|---|---|---|
| Identifiers | Yes | Account id, email, name, Instagram-scoped id, and a push token if you turn notifications on |
| Customer records information (Civ. Code § 1798.80(e)) | Yes | Name |
| Protected classification characteristics | No | — |
| Commercial information | No | — |
| Biometric information | No | — |
| Internet or other network activity | Yes | The in-app events listed in section 9, and the links you save |
| Geolocation data | No | — |
| Audio, visual or similar information | Yes | Your profile photo if you added one, and thumbnails of the things you saved |
| Professional or employment information | No | — |
| Education information | No | — |
| Inferences | Yes | The category, tags, summary and search vector produced for each save |
| Sensitive personal information | Limited | The contents of the messages you send to @allkeptapp. We use them only to provide the service you asked for, never to infer anything about you and never for advertising, so no right to limit under § 1798.121 arises. |
We do not sell personal information, we have never sold it, and we do not share it for cross-context behavioural advertising. We do not knowingly sell or share the personal information of anyone under 16.
You have the right to know, to delete, to correct, and to be free from discrimination for exercising those rights. Delete your account in Settings, or email hi@allkept.app. An authorised agent may act for you with written permission we can verify. We offer no financial incentives.
Residents of other US states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah and Texas — have equivalent rights, including the right to appeal a refusal. To appeal, reply to our decision at hi@allkept.app with the word "appeal".
18. If you are in India
We are the Data Fiduciary for your personal data and you are the Data Principal. This policy is the notice required by section 5 of the Digital Personal Data Protection Act, 2023: it says what personal data we process, for what purposes, how to exercise your rights, and how to complain.
We process your personal data on the basis of the consent you give when you create an account, connect a door and complete your profile. You may withdraw that consent at any time — by disconnecting a door in Settings, or by deleting your account, which withdraws it entirely. Withdrawing consent does not make what we did beforehand unlawful; after you withdraw it we stop processing and erase, except where a law requires us to keep something.
Under the DPDP Act you have the right to a summary of your personal data and of our processing of it, the right to correction, completion, updating and erasure, the right to nominate someone to exercise your rights if you die or become incapacitated, and the right to grievance redressal.
Grievance Officer
The DPDP Act requires us to publish the contact details of the person who answers your grievances:
Grievance Officer: Pranav Aditya
Designation: Grievance Officer
Address: 4th Floor, No. 19, Urban Vault, 18th Cross Road, Sector 7, HSR Layout, Bengaluru, Bengaluru Urban District, Karnataka 560102, India
Email: hi@allkept.app
We will acknowledge a grievance within 30 days. You should use this route first; if you are not satisfied, you may then approach the Data Protection Board of India.
Your duties as a Data Principal. The DPDP Act asks you not to impersonate anyone else, not to suppress material information, and not to raise false or frivolous grievances.
19. Children
Allkept is not for children. You must be at least 18 years years old to have an Allkept account, and older where your country requires it.
We do not knowingly collect personal data from anyone below that age. India's DPDP Act requires verifiable parental consent for anyone under 18 and prohibits tracking, behavioural monitoring and targeted advertising directed at children — we do none of those things for anyone, at any age. The GDPR sets a floor of 16, which member states may lower to 13. In the United States, COPPA applies below 13.
The app has no age-verification step today 18 years. If we learn that we hold data about a child below the applicable age, we will delete it. A parent or guardian who believes their child has an account should write to hi@allkept.app and we will remove it.
20. If your post is in someone's library
Everything in an Allkept library came from a public post that an Allkept user chose to save. If you posted something and it now sits in someone's private library, we hold its public link, its public title or caption, your public display name and handle, and a copy of the public thumbnail.
We fetched all of that from the platform's own public preview. We do not build creator profiles, we do not aggregate anything across creators, and no Allkept user can see another user's library.
If you want your content removed, write to hi@allkept.app with the link. We will remove the stored preview text and thumbnail from our systems. How we handle the underlying saved link is described in the takedown section of the Terms.
21. Security
- Every table in the database enforces row-level security: a signed-in client can read and write only its own rows. The database enforces this, not the app code.
- Thumbnails, profile photos and uploaded exports live in private buckets, reachable only through short-lived signed links issued to their owner.
- Your sign-in session is held in your phone's secure keychain, split into pieces so that a partial write can never be read back as a whole session.
- Instagram webhook requests are rejected unless they carry a valid Meta signature.
- Internal background jobs require a shared secret held in the database vault.
- Administrator access is an explicit, server-held membership list, re-checked on every single read, with an audit record for every action taken.
- All traffic is over HTTPS.
A small number of Allkept administrators can see operational data, in order to keep the service working. To be precise about what that means, they can see: the email address and profile fields on an account; how many saves it holds and which platforms they came from; the connected Instagram handle and YouTube playlist; import runs; the in-app event log; any feedback you sent, with the address to reply to; and, for a save that failed to process, its title and the error, next to the email of the account it belongs to. There is no screen that browses a working library, administrators cannot read your notes or your categories, and the only action they can take on a save is to queue it for another attempt. Every such action is recorded in an audit log.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant authorities as the law requires: within 72 hours under the GDPR, and to the Data Protection Board of India as the DPDP Act requires.
22. Deleting everything
Open Allkept, go to Settings, and tap Delete account and everything in it. There is no waiting period and no soft-delete stage. It removes:
- every save, category, tag, summary, note and search vector;
- every stored thumbnail, and every profile photo you ever uploaded, including replaced ones;
- your profile, your switches, your connected Instagram and YouTube doors, and any unused linking codes;
- every raw Instagram message event and every reply tied to your Instagram-scoped id, including ones still inside the 30-day window;
- every notification device token registered to you, so no phone can go on ringing;
- your usage log and your import records; and
- your login itself.
The one thing that is kept is any feedback you sent us, and it is kept without you: your account link and the address we could have replied to are removed with everything else. Ask us and we will delete the message too. See section 3.11.
If you cannot open the app, email hi@allkept.app from the address you signed in with and we will do it for you. There are fuller instructions on the data deletion page.
Deleting your Allkept account does not delete anything on Instagram, YouTube or any other platform. Copies may persist briefly in our provider's routine backups before they age out backups and server logs are retained by Supabase for up to 7 days.
23. Changes to this policy
We will change this page when the system changes, and the date at the top will change with it. If a change materially affects how we handle your data — a new AI provider, a new category of data, a new purpose — we will tell you in the app before it takes effect, and where the law requires consent, we will ask for it.
24. Contact
Write to hi@allkept.app about anything in this policy: a question, a request to see or delete your data, or a complaint.
Allkept is not affiliated with, endorsed by or sponsored by Meta, Instagram, YouTube, Google, OpenAI, Apple or any other platform named here.