Privacy Policy
Last updated: March 4, 2026
Overview
Kept ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our link-in-bio platform.
1. Information We Collect
Account Information
When you create an account, we collect your email address, username, and any profile information you choose to provide (name, bio, avatar).
Payment Information
Payment processing is handled by Stripe. We do not store your credit card details. We receive transaction confirmations and payout information from Stripe.
Analytics Data
We collect anonymized analytics including page views, link clicks, referrer sources, device type, and general location (country level). This data helps creators understand their audience.
Subscriber Data
When visitors subscribe to a creator's page, we collect their email address and the traffic source. This data belongs to the creator and can be exported at any time.
2. How We Use Your Information
We use your information to:
- Provide and maintain the Service
- Process payments and payouts
- Send transactional emails (account verification, password reset, receipts)
- Provide analytics to creators about their audience
- Improve and optimize the Service
- Detect and prevent fraud or abuse
- Comply with legal obligations
3. Data Sharing
We do not sell your personal data. We share data only with:
- Supabase: Our database and authentication provider
- Stripe: Payment processing
- Resend: Transactional email delivery
- Vercel: Hosting and edge functions
These providers process data on our behalf and are bound by data protection agreements.
4. Creator Responsibilities
Creators who collect subscriber emails through Kept are data controllers for that data. Creators are responsible for complying with applicable privacy laws (GDPR, CAN-SPAM) when using subscriber data for email marketing. Subscribers can request removal by contacting the creator directly.
5. Cookies and Tracking
We use essential cookies for:
- Authentication (keeping you logged in)
- Session management
- Visitor identification (to track new vs. returning visitors)
We do not use third-party advertising cookies or sell data to advertisers.
6. Data Retention
Account data: Retained while your account is active. Deleted within 30 days of account deletion.
Analytics data: Aggregated analytics are retained indefinitely. Raw event data is retained for 12 months.
Subscriber data: Retained until the creator deletes it or exports it and closes their account.
7. Your Rights
Depending on your location, you may have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data
- Export your data (data portability)
- Object to certain processing
- Withdraw consent
To exercise these rights, contact us at kept.bio@gmail.com
8. Data Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, secure authentication, and regular security audits. However, no system is 100% secure, and we cannot guarantee absolute security.
9. International Transfers
Your data may be processed in the United States where our service providers are located. By using Kept, you consent to this transfer. We ensure appropriate safeguards are in place for international data transfers.
10. Children's Privacy
Kept is not intended for users under 18 years of age. We do not knowingly collect data from children. If we learn that we have collected data from a child, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the Service. The "Last updated" date at the top indicates when the policy was last revised.
12. Contact Us
For privacy-related questions or requests:
Email: kept.bio@gmail.com