Privacy Policy
Last updated 30 August 2026
Keep has no server. There is no account to make, nothing to sign in to, and no copy of your library anywhere but your phone. Your photographs, and the decisions you make about them, stay on the device. Two things leave it — a coordinate for a place name, and whether this phone has paid — and both are named below.
Who we are
Keep is an iPhone app published by [legal entity name] (“Keep”, “we”, “us”), [registered address]. For anything in this policy, write to hello@keep.gallery. Where the UK GDPR or EU GDPR applies, we are the data controller for the small amount of information described here.
What Keep reads
With your permission, Keep reads your photo library through Apple's Photos framework: each photo's image data, the date it was taken, whether it is a video or a screenshot, whether it is already a favourite, and — where the photo carries one — the location stored in the photo itself. All of this is read on the device, to build the months, trips, places and duplicate sets you see in the app. None of it is transmitted to us or to anyone else.
Keep asks for full library access rather than a limited selection, because sorting a library is the job: under limited access you would have to hand-pick the photos to grant, and those are the photos you came here to find. You can change or withdraw that access at any time in Settings › Privacy & Security › Photos › Keep.
Keep never requests location permission. The only location it ever sees is the one already written into a photograph by the camera that took it.
What Keep stores, and where
On your device only: your verdicts (kept, favourite, skipped, thrown), the albums you made, the suggestions you dismissed, your settings, and caches of decoded thumbnails so the app draws quickly. None of it is backed up to us, because there is no us to back it up to. Deleting the app removes all of it. What Keep wrote into the Photos app — your albums and your favourites — belongs to Photos and stays behind.
What Keep writes
Photos you keep are added to an album in your Photos library. Photos you favourite are marked as favourites there. Photos are deleted only when you empty the Thrown pile and confirm twice, once in Keep and once in the system's own prompt; iOS then holds them in Recently Deleted for thirty days, where you can still get them back.
What leaves the device
Two things, and neither is a photograph.
- Place names. When the “Place names” setting is on — it is on by default — the centre coordinate of a suggested trip is sent to Apple's geocoding service to be turned into a name like “Zermatt”. One coordinate per suggestion, no photograph, no identifier of you, and no location permission is requested. Turn the setting off in the app and nothing is sent. Apple's handling of that request is covered by Apple's privacy policy.
- Your purchase. Payments are handled by the App Store; we never see your card, your name or your email address. Keep uses RevenueCat to ask whether this device has an active purchase and to restore one you have already made. The SDK is configured anonymously: the identifier it sends is one it generated on this phone at first launch, tied to no name, email or Apple ID, and meaningless anywhere else. What it carries is your purchase and receipt state and basic device and app information (model, OS version, app version, country, locale).
The App Store's privacy labels, in plain words
Keep's App Store listing declares two data types, both not linked to your identity and neither used for tracking:
- Purchase history — whether this device has an active subscription or lifetime purchase. Used to unlock deleting, and for nothing else.
- Device ID — the anonymous identifier described above, used to attach a purchase to a device so it can be restored.
There is no third data type, because there is no third thing being sent.
Notifications
If you start a free trial, Keep asks — after the purchase, never before — whether it may send you one notification two days before the trial turns into a paid plan. It is a local notification scheduled on your phone by your phone: nothing is sent to a server, and no push token is registered or transmitted. Refusing costs you nothing but the reminder, and you can turn notifications off at any time in Settings.
What Keep does not do
- No analytics, no crash reporting to third parties, no advertising identifiers, no trackers, no SDKs beyond the purchase check described above.
- No upload, backup or sync of photographs, thumbnails, verdicts or albums.
- No selling or sharing of personal information, for any purpose, ever. We have never sold personal information and have no plans to.
- No profiling, no automated decision-making, no marketing emails — there is no email address of yours for us to send one to.
- No location permission requested at any point.
Why we are allowed to do this (GDPR)
Where the GDPR applies, our lawful basis for the two outbound connections is contract — checking your purchase is how the app you bought knows you bought it — and, for place names, legitimate interests in naming a suggested trip, which you can switch off in one tap. Photo library access rests on the permission you grant in iOS, which you can withdraw at any time.
How long anything is kept
On your device, until you delete it or delete the app. At RevenueCat, purchase records are kept for as long as the purchase is relevant to providing the app, in line with their own policy. We keep no records at all, because we receive none.
Where it goes
RevenueCat processes purchase state on servers in the United States. Where an international transfer of personal data occurs, it relies on the European Commission's Standard Contractual Clauses. Apple's geocoding of a coordinate is covered by Apple's own policy.
Your rights
Because Keep holds no personal data of yours off your device, there is usually nothing for us to export, correct or erase on request — everything Keep knows about you is on your phone and under your control. Uninstalling the app deletes it, and photo access can be withdrawn at any time in Settings.
You still have the rights the law gives you — access, correction, erasure, restriction, objection, portability, and the right to complain to your data protection authority (in the UK, the ICO). If you are in California, you have the right to know, delete, correct and opt out of sale or sharing; there is no sale or sharing to opt out of, and we will not discriminate against you for asking. Write to hello@keep.gallery and we will answer within 30 days. To identify a purchase without an account, the anonymous identifier is the only handle that exists — the app's Subscription screen can show it to you.
Security
Your photographs never leave the device, which removes most of the risk this section usually addresses. What does leave travels over HTTPS. The data on your phone is protected by iOS itself and the passcode or biometric lock you have set on it.
Children
Keep is not directed at children under 13 and collects no personal information from anyone, of any age. If you believe a child has provided personal information, there is nothing for us to hold — but write to us and we will confirm that in writing.
Changes
If this policy changes, the updated version is posted here with a new date. Material changes will also be noted in the app's release notes. Continuing to use Keep after a change means you accept the updated policy.
Contact
hello@keep.gallery — a person reads it.