Your information

Privacy Policy

Effective July 25, 2026

KeepUp helps invited adult partners share reminders, lists, events, and requests. This policy explains what information we use to provide that service. “KeepUp,” “we,” and “us” refer to the KeepUp service operated by Celestial Forge LLC, a Virginia limited liability company.

Information we collect

  • Account information: your email address, sign-in provider identifier, display name, timezone, and account settings.
  • Shared-space information: household membership, invites, lists, events, reminders, assistant messages, and activity needed to synchronize the people you invite.
  • Device information: operating system, app version, notification token, permission state, and reliability or security diagnostics.
  • Purchase information: subscription status and transaction identifiers supplied by Apple, Google, or our subscription processor. We do not receive full payment-card numbers.
  • Optional calendar information: calendar permission and KeepUp calendar identifiers when you choose device-calendar export.
  • Optional product analytics: only after you opt in, coarse product-interaction events such as a screen or feature being opened or a flow being completed, along with platform, app version, and a pseudonymous user-count token generated with a keyed HMAC. We treat this token as personal information because it can be associated with your account for counting and deletion; we do not describe it as anonymous or deidentified.
  • Safety and support information: when you submit a report, the reported item type and identifier, a snapshot limited to the reported item's first 1,000 characters, a revision reference, your selected reason, optional details of up to 500 characters, and case status. A report does not copy unrelated conversation or household context. We also keep the minimum block relationship and support-case information needed to enforce a block.

How we use information

We use information to authenticate you; synchronize the shared space you joined; interpret requests; create and deliver reminders; export plans you choose; provide support; process subscriptions; screen for unsafe or abusive use; investigate reports; enforce blocks and our Terms; prevent abuse; and maintain security and reliability. If you opt in to product analytics, we also use the limited interaction events to understand feature adoption, completion funnels, and where the product can be improved.

Shared and private content

Shared content is visible to active members of your invitation-only KeepUp space. Content marked “private,” “only me,” or “just me” is restricted to its creator. KeepUp’s database rules enforce this separation; a private item’s title, time, and metadata are not shown to the other member.

AI processing

When the assistant is enabled, relevant message text and limited recent context may be sent securely to an AI service provider to interpret your request. Provider keys remain on KeepUp’s server. The model proposes a constrained action; KeepUp validates the action before changing your data. We do not use household content for advertising.

Text submitted through supported app flows may also be screened before it is saved or acted on to detect unsafe or abusive content. A safety screen can reject a request but does not make KeepUp an emergency-monitoring service.

Reports, blocking, and safety review

You may report an assistant reply, a shared partner message, plan, reminder, grocery item, or partner profile from the app. Reports are available only to authorized service operators, not to the other household member. We review only the bounded reported-item snapshot, reason, optional details, identifiers, and case status needed to investigate and enforce our Terms.

Blocking a partner immediately ends the pair's shared access across every KeepUp space they have in common. In each space, ownership determines which person remains and which person leaves. New invitations between the pair are prevented until support completes a verified unblock. A block does not automatically restore or archive prior shared content, and an unblock requires a new invitation before the people can share a space again.

Crash diagnostics

When an app or server error occurs, our monitoring provider may receive the app version, operating system or device type, technical stack trace, generalized failure route, and time of the error. KeepUp configures monitoring not to send user identity, authorization headers, request bodies, query strings, console messages, or household message, list, and event content. Diagnostics are used only for security and reliability, not advertising or cross-app tracking.

Optional first-party product analytics

Product analytics is off until you affirmatively opt in through KeepUp. If enabled, KeepUp records only coarse feature names, completion outcomes, and broad interaction patterns in its own production data service. For assistant requests, a deterministic classifier may record only broad, non-medical categories and language shapes such as relative versus explicit date wording; it never places your message, a matched phrase, or a parsed date or time in analytics.

Analytics does not contain raw messages, titles, list names or items, content dates or times, locations, email addresses, partner or household identifiers, notification tokens, session or device identifiers, or advertising identifiers. KeepUp does not use these events for advertising, attribution, data-broker activity, or tracking across other companies' apps or websites. KeepUp does not access Apple's advertising identifier or show the AppTrackingTransparency prompt for this analytics.

You can turn product analytics off at any time in Settings. Turning it off immediately stops new analytics collection, clears queued events on the device, and deletes the remaining pseudonymous weekly counters linked to your account. Product features and paid functionality remain available whether or not you participate.

Service providers and disclosure

KeepUp currently uses Supabase for authentication, database, and synchronization; Render for the application API; OpenAI for assistant interpretation and managed site hosting; Cloudflare for public-site network delivery and abuse protection; Expo for push delivery and app services; RevenueCat for subscription status; Sentry for privacy-scrubbed crash diagnostics; and Apple or Google for sign-in, distribution, device permissions, notifications, and purchases. Each provider receives only the information needed for its role.

Optional product analytics is first-party: KeepUp determines the events and uses them only to improve KeepUp. A production infrastructure provider may process those records on KeepUp's instructions, but KeepUp does not provide them to a third-party behavioral analytics or advertising service. We otherwise disclose information only to the people you invite; when required by law; or during a business transaction subject to appropriate safeguards. We do not sell personal information, show third-party advertising, or share personal information for cross-context behavioral advertising.

Website security cookies

Our public-site hosting and network providers may set a short-lived, strictly necessary security cookie, such as Cloudflare's __cf_bm, to distinguish ordinary visits from malicious or automated traffic. KeepUp does not use this cookie for advertising or cross-site tracking.

Retention and deletion

Active account and shared-space information is retained while needed to provide KeepUp. Deleted items may remain recoverable for a short safety window. Safety reports and their operator-action history expire within 180 days unless counsel documents a lawful retention override. When you request account deletion, notifications stop and a seven-day recovery window begins. After that window, KeepUp deletes your account data and all messages, list items, events, reminders, and other user-generated content you authored, including content you shared with your household. The other household member's account and content they authored remain.

Pseudonymous product-analytics weekly counters and their HMAC-derived user-count tokens are retained for no more than 90 days. Turning analytics off or completing account deletion removes the remaining counters linked to that account. Weekly summary metrics may remain for up to 365 days only after the user-count token has been removed; KeepUp reports a breakdown only when its cohort contains at least five users.

For a safety report involving the deleted account, KeepUp removes the reporter, subject, household, and source identifiers; report evidence and revision; user-supplied details; operator notes and references; block-support fields; and identifying audit fields. Aggregate report source type, reason, status, and time may remain only until the report's existing expiry. Deidentified security and audit events and subscription-webhook records are retained for up to 180 days. Anonymized subscription status may remain for a surviving shared space, and payment providers may retain transaction records for tax, accounting, refunds, fraud prevention, or chargebacks. Identifiable records are retained longer only when a documented legal hold or applicable law requires it. See Account deletion.

Security

We use encrypted transport, signed account sessions, access controls, least-privilege database rules, expiring invites, secret management, and operational monitoring. No online service can promise absolute security, so please use a protected device and report concerns promptly.

Your choices

You can control notifications, calendar permissions, optional product analytics, private visibility, reporting and blocking, and subscription management from the app or device settings. Product analytics remains off unless you opt in; disabling it stops collection and deletes your linkable analytics counters. You can request access, correction, export, or deletion by contacting privacy@keepupcouples.com. A privacy export includes reports you submitted and only minimized direction/status information for blocks; it does not disclose another profile's identifier or internal support references, notes, or audit metadata. Rights vary by location; we will verify requests before responding.

Age eligibility

KeepUp is for adults age 18 and older. We do not knowingly collect personal information from anyone under 18.

International processing and changes

KeepUp launches from the United States and service providers may process information in the United States or other locations. We may update this policy as the service changes. Material changes will be communicated in the app or by another reasonable method.

Contact

Privacy questions may be sent to privacy@keepupcouples.com. KeepUp is operated by Celestial Forge LLC. The operator’s verified legal and postal details are also available in the applicable app store listing.