Keppet Privacy Policy
Effective 11 July 2026 · applies to the Keppet app (web and Android) and keppet.app
The short version: your financial ledger lives in your own git repository, Google Drive, or OneDrive, on your own account. Keppet's servers never store it. We keep almost nothing about you, and what little we keep is hashed. When you use the paid Keppet AI feature, your receipt image or typed text is processed transiently by a major cloud AI provider to extract the transaction. Under our paid-tier terms it is not used to train models, and Keppet does not store it. If you attach a receipt image to a transaction, that image is stored on Keppet's servers for as long as a transaction refers to it.
Your financial data: yours, literally
Keppet stores your accounts, transactions, budgets, and goals as plain-text files in a private git repository (keppet-data) on your own GitHub, GitLab, Codeberg, or self-hosted account. Your device syncs directly with your git provider using your own sign-in. Keppet's servers do not receive, store, or read your ledger. You can leave at any time. Your data is already yours, in a format you can read without us.
If you instead choose to store your data in Google Drive or Microsoft OneDrive, the same plain-JSON files are written to a private folder named keppet-data in your own Google Drive or OneDrive account. Your device syncs directly with Google Drive or OneDrive using your own sign-in. Keppet holds no copy of your ledger on these backends either. Sign-in is Google or Microsoft OAuth (see "Sign-in" below).
What Keppet's servers do keep
- A hashed sign-in counter: a one-way hash of your provider + username, with first/last sign-in dates, used to count users. No name, email, token, or financial data.
- Keppet AI usage: the same one-way hash with a count of free AI actions used and a subscription flag, used to run the free trial and the subscription. Nothing about the content of what you scanned or typed.
- Receipt images you choose to keep: stored in a private, access-controlled bucket, retrievable only by proving access to your own storage account (git repository, Google Drive, or OneDrive). Delete them anytime from the app.
- Bug reports you send: only what you type plus an optional screenshot you attach.
- An optional notification email: if you turn on "Email me when my free AI actions run out" in Settings, we store the address you give us only until that one email sends — then it's deleted automatically. Turn the option off any time in Settings to delete it sooner.
There are no third-party analytics, no advertising SDKs, and no tracking of your financial activity.
Keppet AI (the paid feature)
When you use Keppet AI (snapping a receipt or typing a purchase), your receipt image or text is sent over an encrypted connection to Keppet's server, which forwards it to our AI subprocessor, a major cloud AI provider, under Keppet's paid-tier key. Under those paid-tier terms, this content is not used to train models. Keppet's own servers process it in memory to return the transaction and do not store the image or text. The provider keeps it only in abuse-detection logs for up to 30 days, then deletes it. Separately, if you keep the receipt image as an attachment on a transaction, that image is stored on Keppet's servers for as long as a transaction refers to it, and is deleted when no transaction refers to it or on request. The resulting transaction is written to your ledger by your device with your credentials, never by our servers.
Prefer to keep AI entirely away from Keppet's servers? Use the free MCP integration (keppet-mcp): your own AI assistant reads and files transactions directly against your repository, and no financial content ever touches Keppet infrastructure.
Sign-in
You sign in with your git provider (OAuth). Your access token stays on your device and is presented directly to your provider (or relayed, unstored, through a same-origin proxy for providers that require it). Keppet has no user database, no passwords, and no server-side sessions.
Signing in with Google or Microsoft works the same way: OAuth via Google or Microsoft, with your access token staying on your device. Refreshing that token is relayed, unstored, through Keppet's server (required by how Google and Microsoft issue tokens) — the token itself is never written to a database or logged.
Deleting your data
- Your ledger: delete the keppet-data repository on your git provider — or, if you use Google Drive or OneDrive, delete the keppet-data folder there. That is the master copy.
- On your device: Settings → “Clear all data”.
- Server-side remnants (hashed counters, receipt images you attach to transactions, subscription flag): email [email protected] from any address, naming your provider + username, and we will delete them within 30 days. This is also the deletion path referenced in the Google Play listing.
Payments
The Keppet AI subscription is sold on keppet.app through a payment provider acting as merchant of record; Keppet never sees or stores your card details. The mobile app contains no in-app purchases.
Changes & contact
If this policy changes materially we will note it here with a new effective date. Questions: [email protected].