Privacy Policy

Last updated: September 2026

At KeepKnown, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our email filtering service.

1. Information We Collect

Account Information

When you create an account, we collect:

  • Your email address
  • Your name (if provided)
  • Payment information (processed securely by Stripe or PayPal)

Connected Inbox Data

When you connect Google Workspace, Gmail, Outlook, or Microsoft 365, we request access to the provider data needed to run your filters:

  • Gmail API: To process incoming email headers, including sender information and subject lines, create labels, and move emails to labels
  • Contacts API: To read your contact list and identify emails from known senders
  • Microsoft Graph: To process supported Outlook message metadata, manage folders or categories, apply supported actions, and identify known senders

Work/school Microsoft accounts may need admin consent. Shared, on-premises Exchange and archive mailboxes are not supported. You can revoke access through Google or Microsoft at any time.

How We Handle Your Email Data

We do not read or store email body content. The filtering engine processes selected email headers, including sender information and subject lines, to evaluate rules you configure.

The mobile app does not read your device contacts, photos, files, or location. Gmail and Microsoft provider credentials remain on KeepKnown's secured server and are not stored in the mobile app.

The mobile app sends a small allowlisted set of screen and workflow events, exception types, and sanitized crash fingerprints to KeepKnown after authentication. These diagnostics never include message content, sender or inbox addresses, provider tokens, request URLs, or exception messages, and are not used for advertising or cross-app tracking.

Contact email addresses and subject lines are not stored in plaintext. We store:

  • Per-user lookup token (HMAC-SHA256): Used to match an incoming sender to a known contact without storing the plaintext address
  • Encrypted copy (optional): Used for authorized product views, including rule inspection and message previews
  • Encrypted subject line: Decrypted in memory for deterministic subject matching and authorized previews; excluded from general evaluation logs

AI-Assisted Rule Creation and Previews

When you use plain-English rule creation, OpenAI receives your instruction, clarification answers and supported rule-building context. Instructions may contain sender addresses or other information you enter. We do not send mailbox samples, email bodies, attachments or provider credentials to the rule-building AI service. Do not paste private message contents into an instruction.

Rule-building sessions and sensitive rule values are stored encrypted. The filtering engine uses stored metadata, such as sender, subject, labels and categories. A preview evaluates up to 100 stored message snapshots and displays up to 10 examples to the authorized account owner. Drafting and previewing do not modify messages. General marketing analytics record workflow events, not your rule instructions.

Google and Microsoft mailbox permission scopes allow reading and changing mail even though the filtering engine operates on metadata. Google uses labels; Microsoft uses categories and folders. Gmail recovery supports certain actions when the message and prior state remain available. Microsoft does not provide the Gmail restore controls or general undo.

2. How We Use Your Information

We use the information we collect to:

  • Provide and maintain the KeepKnown email filtering service
  • Apply the rules you approve, including optional unfamiliar-sender screening with the KK:OUTSIDERS Gmail label or Microsoft category
  • Process your subscription payments
  • Send you service-related communications
  • Improve and optimize our service
  • Respond to your support requests

3. Data Storage and Security

Encryption

All data transmitted between KeepKnown's website or mobile apps and our servers is encrypted using TLS. Google and Microsoft OAuth credentials are encrypted before being stored on the server.

Data Retention

  • Contact hashes: Retained while your account is active
  • Email processing records: Stored to support activity history and recovery; contact us for information about deletion of these records
  • Encrypted subject metadata: Retained with your account so configured protocols and previews can evaluate subject conditions
  • Account data: Retained until you delete your account
  • Mobile push registrations: Retained while notifications are enabled or until you sign out or delete your account
  • Mobile analytics and crash fingerprints: Retained for 30 days for product reliability and diagnostics

Where We Store Data

Contact hello@keepknown.com for current information about hosting locations and international processing. Third-party services process the data described below.

4. Third-Party Services

We use the following third-party services:

  • Google APIs: Gmail and Contacts APIs to provide our core service
  • Microsoft Graph: Outlook and Microsoft 365 APIs to provide our core service
  • Firebase Cloud Messaging: Delivery of optional mobile notifications
  • Stripe: Payment processing
  • PayPal: Alternative payment processing
  • Amazon SES: Transactional emails
  • OpenAI: AI-assisted rule creation using the instruction and clarification data described above
  • Google Analytics: Website usage and conversion events

Each of these services has their own privacy policy governing their use of your data.

5. Your Rights

You have the right to:

  • Access: Request a copy of the data we hold about you
  • Correction: Update or correct your account information
  • Deletion: Delete your account and all associated data
  • Revoke Access: Disconnect your supported Google or Microsoft account from your dashboard
  • Data Portability: Request an export of your data

You can export or delete your data directly in the KeepKnown mobile app. You can also use our account deletion page or contact hello@keepknown.com.

6. Google API Services User Data Policy

KeepKnown's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we:

  • Only request access to data necessary to provide our service
  • Never use Google user data for advertising purposes
  • Never sell Google user data to third parties
  • Never use Google user data to determine creditworthiness or for lending purposes

7. Children's Privacy

KeepKnown is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

9. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

Questions?

If you have any questions about our privacy practices , please contact us:

hello@keepknown.com