Privacy Policy

Reciptix LLP (“we,” “our,” or “us”) operates the Keeplea mobile application and website (“the Service”). Reciptix LLP is a limited liability partnership registered in the United Kingdom and is the data controller for personal data processed through the Service. This Privacy Policy explains what we collect, why, who we share it with, and what rights you have.

Summary

1. Information We Collect

Account Information. When you create an account, we collect your email address (required) and optionally your name and profile photo. If you sign in with Apple, Google, or another authentication provider, we receive the basic profile information that provider chooses to share.

Your Captured Content. This is the data you create as you use the app. It includes:

Importing photos. You can optionally import photos you already have to help fill your library. This uses your device’s standard photo picker, which gives Keeplea only the specific photos you select — Keeplea never gets access to the rest of your photo library. Imported photos are handled exactly like the photos you capture.

Subscription and Purchase Data. If you subscribe to a paid plan, we receive subscription status, plan tier, currency, renewal date, and original transaction identifiers from Apple, Google, or RevenueCat. We do not see or store payment card numbers or bank account details — those are handled by Apple and Google.

Shared Collection Data. If you share a collection of items with another user, your display name and profile photo (but not your email address) become visible to the other members of that collection, and theirs to you. Items you add to a shared collection, and the details Keeplea generates from them, become visible to its members.

Location (Optional). Keeplea derives an approximate location for an item from whatever your device provides, with no separate in-app setting to turn on. If a photo carries its own embedded GPS data — whether you captured it or picked/imported it — we read that; you control whether it’s there via your device’s own photo picker or share-sheet options (for example, iOS’s picker lets you exclude location per photo, and Android’s picker strips it automatically). For photos you take with the in-app camera, we can also take a coarse, one-time device location fix at the moment of capture; that only happens if you’ve allowed the location permission the app asks for the first time you use the camera, and you’re free to deny or later revoke it. That derived location is always rounded to city-level precision (roughly 1 km) before it’s stored, and we don’t track your location in the background or over time; we use it only to help organize your captured items by place and detect trips. Separately, the original photo you capture is stored as you captured it (see “Your Captured Content” above) — if your device embeds precise GPS coordinates in the photo file itself, that embedded data is stored along with the photo, but we do not read or use those embedded precise coordinates for anything beyond deriving the rounded location described here. Neither the derived location nor your photos are shared with anyone outside the service providers described in Section 4, and neither is ever sold. You control this at the OS level at any time — deny or revoke the location permission in your device settings, or exclude location when picking or sharing a photo; items you’ve already captured keep whatever location was attached at the time, but nothing new gets tagged once you withdraw that permission or strip it at the OS level.

Device and Technical Data. To operate the Service, we automatically collect:

What we do not collect. We do not collect advertising identifiers (IDFA on iOS, GAID on Android). We do not access your contacts, calendar, or your photo library — Keeplea only ever receives the specific photos you pick in your device’s standard photo picker (whether you’re capturing or importing), never your library as a whole. We only access device location for photos you take with the in-app camera, and only if you allow the location permission described above — it’s a one-time coarse fix at the moment of capture, never continuous background tracking — which we round to approximate, city-level precision before it’s stored.

2. How We Use Your Information

We use the information described above to:

What we never do:

Under UK GDPR and EU GDPR, we rely on the following legal bases to process your personal data:

4. Third-Party Services and Sub-Processors

We rely on the following service providers to deliver the Service. Each processes personal data only on our behalf and only for the purposes described.

We may add or change sub-processors over time. Material changes will be reflected in this policy.

5. Data Storage, Security, and Retention

Where your data is stored. Your data is stored using Google Firebase, primarily in data centers operated by Google. Some data may be processed in the United States or other regions where our service providers operate (see Section 6 on international transfers).

Security. We implement industry-standard technical and organizational measures to protect your data, including encryption in transit (HTTPS/TLS), encryption at rest, role-based access controls, App Check, and authentication.

Retention. We retain your account and saved items for as long as your account remains active. When you delete your account — you can do this in the app under Settings, or by contacting us — we delete your personal data and saved items from our active systems within 30 days. Some information may remain in encrypted backups for up to 90 days before being permanently removed. Anonymized usage statistics, security logs, and aggregate metrics may be retained longer for product improvement and compliance purposes.

6. International Data Transfers

Reciptix LLP is registered in the United Kingdom. Most of our service providers are based in the United States or operate global infrastructure. When your personal data is transferred outside the UK or the European Economic Area, we rely on appropriate safeguards to protect it, including:

7. Data Access by Our Team

Your content is processed automatically by our systems. Our team does not proactively browse or read user data.

Access to individual user data by our team is limited to specific situations:

8. Your Data Protection Rights

Depending on where you live, you may have some or all of the following rights regarding your personal data:

To exercise any of these rights, contact us at support@keeplea.app. You can also delete your account directly in the app under Settings. We will respond within one month of receiving your request.

9. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights regarding your personal information.

Categories of personal information we collect. In the past 12 months, we have collected the following categories: identifiers (email, user ID, device identifiers); commercial information (subscription data); internet or other electronic activity (usage events, crash reports); geolocation data (the country/region inferred from IP address, and the approximate location attached to your captures, from photo metadata or a coarse camera-capture fix); and other information you provide (your captured photos and the items you save).

Your CCPA/CPRA rights:

To exercise these rights, contact us at support@keeplea.app. We will verify your request by confirming your identity through the email address associated with your account.

10. Cookies and Tracking Technologies

In the app: the Keeplea mobile app does not use browser cookies. It does use device identifiers and similar technologies (Firebase Installation ID, App Check tokens, push tokens) as described in Section 1.

On our website: our website (keeplea.app) uses cookies for essential functionality and, with your consent where required, for analytics and advertising (Google Analytics 4, Google Ads, and the Meta Pixel). Visitors in the UK, EU, and Switzerland are asked to consent before any non-essential cookies are set, and can decline; you can change your mind by clearing the site’s stored preference.

In our emails: our transactional and lifecycle emails may include open tracking pixels so we can measure delivery and engagement at an aggregate level. If you would prefer not to be tracked in this way, most email clients allow you to disable image loading.

11. Children’s Privacy

Keeplea is not directed at children under 13. The Service is intended for users aged 13 and over. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and you believe your child under 13 has provided us with personal data, please contact us at support@keeplea.app and we will delete the account.

Where local law sets a higher minimum age for consenting to data processing (for example, 16 in some EU/EEA countries under the GDPR), that higher age applies.

For users in the United States: in compliance with the Children’s Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13.

12. Data Breach Notification

If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (in the UK, the Information Commissioner’s Office) within 72 hours of becoming aware of the breach, where required by law. If the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date below and, for significant changes, notify you by email or through the app. Your continued use of the Service after the changes take effect constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy, want to exercise your rights, or wish to make a complaint, please contact us at support@keeplea.app.

You can also read our Terms of Use.

Last Updated: July 18, 2026