Privacy Policy
Reciptix LLP (“we,” “our,” or “us”) operates the Keeplea mobile application and website (“the Service”). Reciptix LLP is a limited liability partnership registered in the United Kingdom and is the data controller for personal data processed through the Service. This Privacy Policy explains what we collect, why, who we share it with, and what rights you have.
Summary
-
What we collect: the email address you sign up with, the photos you capture or import and the items you save (plus the descriptions Keeplea generates from them), an approximate location for your captures when your device provides one, and basic technical data needed to run the app.
-
What we use it for: running the app, understanding your captured photos so you can find them later, sending you the emails you’ve asked for, and improving the product.
-
Who we share it with: a small set of trusted vendors that help us deliver the Service (Google/Firebase, Google’s Gemini API, RevenueCat, Bento, and a few others — listed in full below).
-
What we don’t do: we do not sell your data, we do not use your individual photos or saved items for advertising, and we do not use your content to train AI models.
-
Your rights: you can access, correct, export, or delete your data at any time. Contact us at support@keeplea.app.
1. Information We Collect
Account Information. When you create an account, we collect your email address (required) and optionally your name and profile photo. If you sign in with Apple, Google, or another authentication provider, we receive the basic profile information that provider chooses to share.
Your Captured Content. This is the data you create as you use the app. It includes:
-
Photos (and any documents) you capture, upload, or import from your photo library of physical things you want to remember — for example appliance plates, product labels, paint bags, wine labels, or paperwork
-
The descriptions and structured details Keeplea generates from those photos to understand what each item is (such as a product name, type, attributes, and text read from the image)
-
Search-derived data we compute from those descriptions (text embeddings) so you can find items by meaning, not just exact words
-
Titles, tags, and notes you add to your items
Importing photos. You can optionally import photos you already have to help fill your library. This uses your device’s standard photo picker, which gives Keeplea only the specific photos you select — Keeplea never gets access to the rest of your photo library. Imported photos are handled exactly like the photos you capture.
Subscription and Purchase Data. If you subscribe to a paid plan, we receive subscription status, plan tier, currency, renewal date, and original transaction identifiers from Apple, Google, or RevenueCat. We do not see or store payment card numbers or bank account details — those are handled by Apple and Google.
Shared Collection Data. If you share a collection of items with another user, your display name and profile photo (but not your email address) become visible to the other members of that collection, and theirs to you. Items you add to a shared collection, and the details Keeplea generates from them, become visible to its members.
Location (Optional). Keeplea derives an approximate location for an item from whatever your device provides, with no separate in-app setting to turn on. If a photo carries its own embedded GPS data — whether you captured it or picked/imported it — we read that; you control whether it’s there via your device’s own photo picker or share-sheet options (for example, iOS’s picker lets you exclude location per photo, and Android’s picker strips it automatically). For photos you take with the in-app camera, we can also take a coarse, one-time device location fix at the moment of capture; that only happens if you’ve allowed the location permission the app asks for the first time you use the camera, and you’re free to deny or later revoke it. That derived location is always rounded to city-level precision (roughly 1 km) before it’s stored, and we don’t track your location in the background or over time; we use it only to help organize your captured items by place and detect trips. Separately, the original photo you capture is stored as you captured it (see “Your Captured Content” above) — if your device embeds precise GPS coordinates in the photo file itself, that embedded data is stored along with the photo, but we do not read or use those embedded precise coordinates for anything beyond deriving the rounded location described here. Neither the derived location nor your photos are shared with anyone outside the service providers described in Section 4, and neither is ever sold. You control this at the OS level at any time — deny or revoke the location permission in your device settings, or exclude location when picking or sharing a photo; items you’ve already captured keep whatever location was attached at the time, but nothing new gets tagged once you withdraw that permission or strip it at the OS level.
Device and Technical Data. To operate the Service, we automatically collect:
-
Device identifiers such as Firebase Installation ID
-
App Check attestation tokens, used to verify that requests come from a genuine, untampered copy of the app
-
Push notification tokens (so we can send you notifications you’ve enabled)
-
App version, operating system, device model, language, and timezone
-
IP address (logged automatically by our hosting infrastructure for security and abuse prevention)
-
Crash reports and diagnostic logs via Firebase Crashlytics
-
Usage events such as screen views, feature interactions, and error rates via Firebase Analytics
What we do not collect. We do not collect advertising identifiers (IDFA on iOS, GAID on Android). We do not access your contacts, calendar, or your photo library — Keeplea only ever receives the specific photos you pick in your device’s standard photo picker (whether you’re capturing or importing), never your library as a whole. We only access device location for photos you take with the in-app camera, and only if you allow the location permission described above — it’s a one-time coarse fix at the moment of capture, never continuous background tracking — which we round to approximate, city-level precision before it’s stored.
2. How We Use Your Information
We use the information described above to:
-
Provide the core functionality of the app — storing your items, syncing across your devices, understanding your photos, letting you find items by searching or asking, and sharing collections with people you invite
-
Process the photos you capture to recognize what each item is and extract structured details and search embeddings, using the third-party AI service described in Section 4
-
Send you transactional emails (account confirmation, password resets, and messages you’ve requested)
-
Send you lifecycle and product emails (subscription confirmations, important changes, occasional product updates) — you can unsubscribe at any time
-
Provide customer support when you contact us
-
Detect, prevent, and respond to fraud, abuse, and security incidents
-
Measure app performance, fix bugs, and improve the product
-
Comply with legal obligations
What we never do:
-
We do not sell your personal data to anyone.
-
We do not use your individual photos or saved items for advertising or marketing purposes.
-
We do not use your content to train AI models, ours or anyone else’s. The AI provider that processes your photos does so only to return a result to us and does not use your content to train its models.
-
We do not share your captured content with third parties beyond what is strictly necessary to operate the Service as described in this policy.
3. Legal Basis for Processing (UK and EU Users)
Under UK GDPR and EU GDPR, we rely on the following legal bases to process your personal data:
-
Performance of contract — to provide the Service you’ve signed up for, including storing and understanding your items, powering search, and delivering subscription benefits.
-
Legitimate interests — to keep the Service secure, prevent abuse, measure product performance, improve the app, and send product and lifecycle messages about features and updates similar to the Service. You can opt out of emails via the unsubscribe link in any message and turn off push notifications in your device settings.
-
Consent — for non-essential analytics and advertising cookies on our website (see Section 10), and for the optional location tagging of your captures described in Section 1, which you express through your device’s photo and share controls and, for in-app camera captures, the OS location permission. Where we rely on consent, you can withdraw it at any time (for location, by denying or revoking the permission in your device settings, or by excluding location when you pick or share a photo).
-
Legal obligation — where we are required to retain or disclose data to comply with applicable law.
4. Third-Party Services and Sub-Processors
We rely on the following service providers to deliver the Service. Each processes personal data only on our behalf and only for the purposes described.
-
Google / Firebase (United States and EU) — authentication, database (Firestore, including vector search), file storage (Cloud Storage), Cloud Functions, App Check, push notifications (FCM), crash reporting (Crashlytics), and analytics (Firebase Analytics / Google Analytics 4).
-
Google Gemini API (United States and EU) — recognizing and structuring the contents of your photos and generating the text embeddings that power search. Content sent to the Gemini API is processed only to return a result and is not used to train Google’s models.
-
RevenueCat (United States) — managing in-app subscriptions, entitlements, and subscription analytics.
-
Bento (United States) — sending transactional and lifecycle emails (account confirmation, subscription notifications, product updates). Bento receives your email address, name, Firebase user ID, and subscription events. Bento does not receive your captured content.
-
Apple (United States) — App Store distribution, in-app purchase processing, and push notification delivery (APNs).
-
Google Play (United States) — Play Store distribution and in-app purchase processing.
-
Website advertising and analytics (United States) — on our website only, and only with your consent where required: Google Analytics 4, Google Ads, and the Meta (Facebook) Pixel, used to measure traffic and our advertising. These do not have access to your in-app captured content. See Section 10.
We may add or change sub-processors over time. Material changes will be reflected in this policy.
5. Data Storage, Security, and Retention
Where your data is stored. Your data is stored using Google Firebase, primarily in data centers operated by Google. Some data may be processed in the United States or other regions where our service providers operate (see Section 6 on international transfers).
Security. We implement industry-standard technical and organizational measures to protect your data, including encryption in transit (HTTPS/TLS), encryption at rest, role-based access controls, App Check, and authentication.
Retention. We retain your account and saved items for as long as your account remains active. When you delete your account — you can do this in the app under Settings, or by contacting us — we delete your personal data and saved items from our active systems within 30 days. Some information may remain in encrypted backups for up to 90 days before being permanently removed. Anonymized usage statistics, security logs, and aggregate metrics may be retained longer for product improvement and compliance purposes.
6. International Data Transfers
Reciptix LLP is registered in the United Kingdom. Most of our service providers are based in the United States or operate global infrastructure. When your personal data is transferred outside the UK or the European Economic Area, we rely on appropriate safeguards to protect it, including:
-
The UK International Data Transfer Agreement and the European Commission’s Standard Contractual Clauses (SCCs)
-
The UK extension to the EU-US Data Privacy Framework, where applicable
-
Other transfer mechanisms recognized by UK and EU data protection law
7. Data Access by Our Team
Your content is processed automatically by our systems. Our team does not proactively browse or read user data.
Access to individual user data by our team is limited to specific situations:
-
Responding to a support request you’ve sent us
-
Investigating a technical issue or bug you’ve reported
-
Investigating suspected fraud, abuse, or a security incident
-
Complying with a legal obligation
8. Your Data Protection Rights
Depending on where you live, you may have some or all of the following rights regarding your personal data:
-
Right of access — to ask us what personal data we hold about you and to receive a copy
-
Right to rectification — to ask us to correct inaccurate or incomplete data
-
Right to erasure — to ask us to delete your data (“right to be forgotten”)
-
Right to restriction — to ask us to limit how we use your data
-
Right to data portability — to receive your data in a structured, machine-readable format and transmit it to another service
-
Right to object — to object to processing based on legitimate interests, including for direct marketing
-
Rights related to automated decision-making — we do not make decisions about you that have legal or similarly significant effects based solely on automated processing
-
Right to withdraw consent — where we rely on consent, you can withdraw it at any time
-
Right to lodge a complaint — you can complain to your local data protection authority.
To exercise any of these rights, contact us at support@keeplea.app. You can also delete your account directly in the app under Settings. We will respond within one month of receiving your request.
9. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights regarding your personal information.
Categories of personal information we collect. In the past 12 months, we have collected the following categories: identifiers (email, user ID, device identifiers); commercial information (subscription data); internet or other electronic activity (usage events, crash reports); geolocation data (the country/region inferred from IP address, and the approximate location attached to your captures, from photo metadata or a coarse camera-capture fix); and other information you provide (your captured photos and the items you save).
Your CCPA/CPRA rights:
-
Right to know what personal information we collect, use, disclose, and share
-
Right to delete personal information we have collected from you
-
Right to correct inaccurate personal information
-
Right to opt out of sale or sharing of personal information. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
-
Right to limit use of sensitive personal information
-
Right to non-discrimination for exercising your rights
To exercise these rights, contact us at support@keeplea.app. We will verify your request by confirming your identity through the email address associated with your account.
10. Cookies and Tracking Technologies
In the app: the Keeplea mobile app does not use browser cookies. It does use device identifiers and similar technologies (Firebase Installation ID, App Check tokens, push tokens) as described in Section 1.
On our website: our website (keeplea.app) uses cookies for essential functionality and, with your consent where required, for analytics and advertising (Google Analytics 4, Google Ads, and the Meta Pixel). Visitors in the UK, EU, and Switzerland are asked to consent before any non-essential cookies are set, and can decline; you can change your mind by clearing the site’s stored preference.
In our emails: our transactional and lifecycle emails may include open tracking pixels so we can measure delivery and engagement at an aggregate level. If you would prefer not to be tracked in this way, most email clients allow you to disable image loading.
11. Children’s Privacy
Keeplea is not directed at children under 13. The Service is intended for users aged 13 and over. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and you believe your child under 13 has provided us with personal data, please contact us at support@keeplea.app and we will delete the account.
Where local law sets a higher minimum age for consenting to data processing (for example, 16 in some EU/EEA countries under the GDPR), that higher age applies.
For users in the United States: in compliance with the Children’s Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13.
12. Data Breach Notification
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (in the UK, the Information Commissioner’s Office) within 72 hours of becoming aware of the breach, where required by law. If the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date below and, for significant changes, notify you by email or through the app. Your continued use of the Service after the changes take effect constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy, want to exercise your rights, or wish to make a complaint, please contact us at support@keeplea.app.
You can also read our Terms of Use.
Last Updated: July 18, 2026