KEPT Privacy Notice
1. Scope
This Privacy Notice is provided by Kept AI Inc. ("KEPT," "we," "us," "our"). It explains what information we handle, why we handle it, who we share it with, how long we keep it, and the choices and rights available to you.
This notice covers:
- The public marketing website at kept.solutions, including the waitlist and enterprise contact forms.
- The KEPT product: a web-based voice AI interview and knowledge continuity platform, including voice capture sessions, captured knowledge, AI-assisted chat, and document uploads.
- Account administration, billing, security, and support for the website and product.
It applies to website visitors, individual account holders, business buyers and workspace administrators, invited participants in business workspaces, coworkers authorized to query knowledge, waitlist subscribers, enterprise prospects, and people who contact support.
2. KEPT's role for individual and business accounts
KEPT plays different roles depending on how you interact with us:
- Business workspaces. When a business customer creates a workspace and its people participate in capture sessions, upload documents, or use chat, KEPT processes that workspace content on the business customer's behalf, as a processor or service provider. The business customer decides whose knowledge is captured and who may access it, and our Data Processing Addendum governs that processing.
- Individual accounts. When you use KEPT through a personal account, KEPT is your service provider. Your captured knowledge belongs to your account, and you decide what to capture and what to delete, subject to this notice.
- KEPT's own operations. For account administration, billing, security, support, and marketing, KEPT decides how and why the information is processed and acts as an independent controller. This includes account registration records, subscription and payment records, security and audit logs, support requests, and waitlist and enterprise-contact submissions.
Section 12 explains what this distinction means for privacy requests from participants in a business workspace.
3. Information collected
We collect information directly from you, from your use of the website and product, from your organization when it invites you into a workspace, and from our service providers such as our payment processor. The categories are:
Identity and account information
Name, email address, authentication-provider identifier, workspace and organization membership, role and department, invitation and signup records, login session identifiers, IP address, browser and device user-agent string, session timing, and authentication metadata held by our authentication provider, including multi-factor authentication settings.
Voice capture and conversation information
Live microphone audio transmitted to our voice provider during a session, full transcript turns from both the AI interviewer and the participant, turn order and timestamps, session identifiers and status, the interview plan and configuration, and voice usage totals used for metering and billing. Section 4 describes how audio is handled.
Workplace knowledge and business-confidential content
Descriptions of tasks, workflows, decisions, judgment, exceptions, relationships, and role-specific expertise; knowledge claims extracted from conversations and the verbatim quotes that support them; role maps, coverage and gap reports, and session summaries; embeddings used for knowledge retrieval; and any business names, customer names, project details, or other confidential information that users state or upload.
AI-derived information and interview steering
Internal signals the interview system creates to guide the conversation, described in Section 5.
Chat and attachment information
Your questions, AI-generated answers and their citations, chat-thread titles, the AI model selected, the knowledge selected for the chat, and uploaded PDF, text, Markdown, and image files along with their file name, type, size, hash, private storage key, status, and extracted text and page numbers. Images used in chat may be sent to an AI model for analysis.
Billing and usage information
Payment-processor customer and subscription identifiers, plan and subscription status, name, email, and billing address held through our payment processor, invoice links, payment-attempt records, dunning and account-recovery state, AI token usage, voice-minute usage, and usage charges and entitlements. KEPT does not store full payment-card numbers; card details are handled by our payment processor, Stripe.
Security, audit, and operational information
Audit and security events, request identifiers, account and workspace attribution, authorization decisions, records of which AI model processed a request along with token counts, cost estimates, latency, and validation outcomes, and support-request text with the verified support email and account identifier.
Marketing and prospect information
Waitlist email address, the source page and campaign attribution of a signup, enterprise-contact name, work email, organization, the free-text description you provide about your knowledge-loss problem, submission time, and email delivery and unsubscribe status. The website stores your theme preference in local browser storage and campaign attribution in session storage. The website does not use advertising pixels.
4. Live voice processing and transcripts
A capture session is a live conversation with a voice AI interviewer. Before your first session, you are shown a separate consent notice, and a session cannot begin unless you have consented. Each session begins with an audible notice, and you can stop the session at any time.
During a session, your live audio is transmitted to our voice provider, ElevenLabs, where it is processed and transcribed in real time. The transcript, not the audio, is what KEPT keeps and works from. KEPT is designed not to store raw audio after live processing.
KEPT does not use your voice to identify you, does not verify identity by voice, and does not create a voiceprint or other biometric identifier.
The Voice Recording and Consent notice describes the session flow, the consent requirements, and the rule that no one may add another person to a session without that person's consent.
5. AI processing and derived information
KEPT uses AI models to conduct interviews, extract knowledge from what you say, and answer questions in chat. Transcripts, extracted knowledge, chat context, and uploaded content may be sent to our AI providers, Anthropic and, when selected, OpenAI, to generate these results. KEPT does not use your content to train a generalized AI model.
From your conversations, KEPT derives information for you and your authorized viewers: knowledge claims, the quotes that support them, role and coverage maps, gap reports, and summaries.
KEPT also creates internal signals that guide the interview, such as where knowledge appears incomplete; these are not shown to employers as profiles or scores. Depending on the session, these signals may include the shape of your role and areas of expertise, communication patterns, where you seem open or guarded, interview direction, and interaction signals such as pace or energy. They exist to help the interviewer decide what to ask next and where to go deeper. They are not employee evaluations, they are not provided to workspace administrators, and they are retained internally. Some of this internal steering information is currently excluded from the standard user export; how it is treated in access requests is under review with counsel and this notice will be updated with the outcome.
6. How information is used
We use information to:
- Provide the product: run capture sessions, transcribe conversations, extract and cite knowledge, answer chat questions, process uploads, and enforce workspace permissions.
- Operate accounts: create and administer accounts and workspaces, authenticate users, and manage invitations, roles, and departments.
- Bill and meter: process subscriptions and payments, track voice-minute and chat usage against plan allowances, and handle usage resets.
- Secure the service: authenticate requests, authorize access, detect and investigate abuse or security incidents, and maintain audit records.
- Support you: respond to support requests, privacy requests, and reported problems.
- Improve the contracted service: diagnose errors, measure performance, and improve reliability and quality within the commitments in this notice, without training a generalized model on your content.
- Communicate: send transactional messages about your account, and send product and launch updates to people who joined the waitlist or opted in, with the ability to unsubscribe at any time.
- Meet legal obligations: keep records of consent and acceptance, respond to lawful requests, and comply with tax, accounting, and other legal requirements.
7. How information is disclosed
We disclose information only in these circumstances:
- Service providers. The vendors listed in Section 8 process information for us to host, operate, and support the service, under contracts that restrict their use of the information.
- Within your workspace. In a business workspace, captured knowledge is visible to the people your workspace authorizes under its access settings. Workspace administrators control those settings. Internal interview-steering signals are not disclosed to administrators or employers as profiles or scores.
- Your organization. For business workspaces, the business customer controls the workspace content, and we act on its instructions as described in Section 2.
- Legal requirements. We may disclose information when required by law, subpoena, or legal process, or to protect the rights, safety, or property of KEPT, our users, or others. Where the law allows, we will notify the affected customer before disclosing their content.
- Corporate transactions. If KEPT is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this notice's commitments.
KEPT does not sell personal information. KEPT does not share personal information for cross-context behavioral advertising, does not use personal information for targeted advertising, and does not use advertising pixels on the website.
8. Subprocessors
These service providers process information to operate KEPT. The provider used can depend on the feature and the AI model selected. The current list is also maintained on the Subprocessors page.
| Provider | Function |
|---|---|
| Vercel | Web application and marketing-site hosting |
| Render | Application control plane, AI services, and background workers |
| Supabase | Database, authentication, and private file storage |
| ElevenLabs | Live voice conversation, audio transport, and transcription |
| Anthropic | AI inference |
| OpenAI | Optional AI inference when selected |
| Stripe | Checkout, subscriptions, invoices, and payments |
| Resend | Transactional, support, and optional marketing email |
| Pipedrive | Waitlist and enterprise customer relationship management |
Business customers may subscribe to subprocessor updates by emailing support@kept.solutions.
9. Retention
We keep information only as long as needed for the purposes described in this notice, and apply the following retention policy:
- Raw voice audio. KEPT is designed not to store raw audio after live processing. What remains from a session is the transcript and what is derived from it.
- Transcripts, captured knowledge, citations, chat, attachments, and extracted attachment text. Retained while your account or workspace is active, because these records are the service you purchased. You can delete individual items, and deleted items are removed from active product systems within 30 days, subject to legal holds and limited records we are legally required to retain.
- Internal interview-steering information. Retained internally while the account is active. It is not exposed to your employer as a profile or score.
- Account or workspace deletion. Recoverable for 30 days. After the recovery period, covered content is deleted from active systems and is not recoverable through KEPT.
- Consent, Terms acceptance, and policy acceptance records. Retained as long as reasonably necessary to prove consent, contract formation, and compliance.
- Security, audit, and model-processing records. Retained for three years, unless a legal hold applies. These records are minimized and are not meant to duplicate captured content.
- Support messages. Retained for two years after the request is closed.
- Marketing leads and enterprise inquiries. You can unsubscribe at any time. Inactive lead records are deleted after two years, except suppression records and active business relationships.
- Billing and tax records. Retained for seven years or the period required by applicable tax and accounting law.
- Legal holds. If information is subject to a legal hold, it is retained until the hold is released, and then the ordinary schedule resumes.
About backups: KEPT does not create separate customer-data backup exports, but our managed database provider maintains disaster-recovery copies that expire on a schedule. When a deletion is completed, the deleted content is not returned to service from those copies, and residual copies age out on the provider's schedule.
10. Security
We apply administrative and technical safeguards designed to protect your information:
- Customer information is scoped by workspace, with database row-level security and service authorization designed to deny cross-workspace access by default.
- Knowledge access depends on authenticated roles and explicit permissions.
- Uploaded files are stored in private object storage and retrieved only through authorized service paths.
- Provider credentials and secrets are held in managed deployment environments and are not shipped to the browser.
- Important authorization, security, consent, deletion, and model-processing events are recorded to support investigation and accountability.
No online service can guarantee perfect security. A fuller overview is on the Security page. To report a suspected security issue, contact support@kept.solutions.
11. User and state privacy rights
Depending on your state of residence, you may have the right to:
- Access the personal information we hold about you and receive a copy.
- Correct inaccurate personal information.
- Delete personal information, subject to the limited records described in Section 9.
- Export your captured knowledge and other information we hold about you, in a portable format. Export coverage is described in Section 5, and we are expanding it.
- Appeal a decision if we decline a request, where state law provides an appeal right.
To exercise any of these rights, or to withdraw capture consent, email support@kept.solutions. We will verify your identity in a manner proportionate to the request, confirm receipt, and respond as applicable law requires. We will not discriminate against you for exercising your rights.
Because KEPT does not sell personal information and does not share it for cross-context behavioral advertising or targeted advertising, there is no sale or sharing to opt out of.
If you participate in a business workspace, your request may need to be handled by your organization, as described in Section 12.
12. Business-workspace participants
If you use KEPT as a participant in a business workspace, the business customer that administers the workspace controls the workspace content, and KEPT processes it on that customer's behalf.
This means that for requests about workspace content, such as access to or deletion of knowledge captured for your employer's workspace, we may need to route your request to your organization, and your organization is responsible for responding under its own policies and legal obligations. We will tell you when we do this, and we will assist your organization as our contract with it requires.
For information KEPT controls directly, such as your account registration, security records, or a support request you sent us, you can contact us at support@kept.solutions and we will handle the request ourselves.
Participation in KEPT is consented. You may decline to begin a capture session and may stop an active session at any time. Declining a session does not authorize your employer to monitor you through another method.
13. Geographic availability
KEPT is offered only to users in the United States at launch and is not offered to users outside the United States.
14. Age restriction and children
Users must be at least 18 years old. KEPT is not intended for children or minors, and KEPT does not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided personal information to KEPT, contact support@kept.solutions and we will delete it.
15. Policy changes
We may update this notice as the product, our vendors, or the law changes. When we do, we will update the effective date and last-updated date at the top of this page. For material changes, we will provide advance notice by email or through the product before the change takes effect, and where the change materially affects capture or consent, we may ask for renewed consent. Prior versions are retained and are available on request to support@kept.solutions.
16. Contact
Questions and privacy requests may be sent to support@kept.solutions.
Kept AI Inc.5965 Peachtree Corners East
Norcross, GA 30071
United States