Privacy Policy
Effective date: 1 April 2026
The short version: Your data is stored on your device by default. If you sign in, it is backed up to secure servers in the EU. We do not sell your data. Your safety plan is never synced to any server. Keel is operated from Denmark and complies with the EU General Data Protection Regulation (GDPR).
1. Data controller
Keel is developed and operated by Keel, based in Copenhagen, Denmark. For questions about your data, contact [email protected].
2. What data Keel stores locally
All data you create in Keel is stored on your device. This includes:
- Your name, age bracket, and primary concern
- Check-in entries (mood, energy, sleep, journal, triggers, gratitude)
- AI session conversations and bookmarks
- Memories that Keel extracts from sessions
- Programme progress and assessment scores (PHQ-9)
- Streak data, badges, and challenge progress
- Your safety plan and SOS kit
- Notification preferences
3. What syncs to the cloud
If you sign in with Apple or Google, the following is backed up to secure servers in the European Union (hosted by Supabase in Frankfurt, Germany): check-ins, session summaries (not full transcripts), memories, goals, bookmarks, SOS kit items, programme progress, streak data, and assessment scores.
Full session conversation transcripts are never uploaded. Only summaries are synced. Your safety plan is never synced and remains only on your device.
4. AI conversations
When you start a session, your messages are sent to Anthropic's Claude API to generate responses. This transfer is covered by the EU-US Data Privacy Framework. Anthropic does not store or use your conversations for training. No personally identifiable information beyond your first name is included. Your clinical conditions, safety plan details, and assessment scores are used locally to tailor the AI's approach but are not sent to Anthropic as separate data points.
For details on how Anthropic handles data, see Anthropic's privacy policy.
5. AI-generated insights
Keel generates personalised insights (mood forecast, burnout risk, technique effectiveness, weekly summaries, smart notifications) using your check-in and session data. This involves a separate AI call using anonymised data. The results are cached on your device for 24 hours. Premium insight features use the same data processing as standard features.
6. Lawful basis for processing
Under GDPR, Keel processes your data based on consent (Article 6(1)(a)), legitimate interest (Article 6(1)(f)), and explicit consent for sensitive mental health data (Article 9(2)(a)). You can withdraw consent at any time by deleting your data or uninstalling the app.
7. What we do not collect
Keel does not collect analytics, device identifiers, advertising IDs, location data, IP addresses, contact lists, cookies, or health data from Apple Health or Google Fit. There is no tracking, profiling, or automated decision-making. We do not share data with advertisers.
8. Sensitive data
Keel may process data related to your mental health, including mood scores, journal entries, clinical conditions you voluntarily disclose, and PHQ-9 assessment results. This data is processed with your explicit consent under GDPR Article 9(2)(a). Authentication tokens are stored using encrypted device storage (SecureStore). Premium trial status is stored in encrypted secure storage.
9. Your rights under GDPR
You have the right to: access all your data (via the export feature), rectify inaccurate data (via profile settings), delete your data (via profile settings or by deleting your account), port your data (via data export), and withdraw consent (by deleting data or uninstalling). If you use cloud sync, deleting your account immediately removes all your data from our servers.
10. Notifications
Notifications are scheduled locally on your device. Smart notifications use your check-in patterns to determine timing and content but no notification data is sent to external servers. AI-personalised notification text is generated and cached locally. You can disable notifications at any time.
11. Data retention
Your data persists as long as you use the app. To save storage, Keel automatically trims journal text from check-ins older than 90 days and removes full message history from sessions older than 30 days (keeping summaries). If you sign in, cloud data persists until you delete it.
12. Third-party services
Keel uses: Anthropic (AI conversations, US, EU-US DPF compliant), Supabase (cloud sync and authentication, EU servers), RevenueCat (subscription management, processes only purchase tokens), and Apple/Google (authentication only). No other third parties receive your data.
13. Children
Keel is not intended for anyone under 16, in accordance with GDPR Article 8.
14. Not a medical service
Keel is a wellness companion, not a medical device or clinical tool. The PHQ-9 assessment is a screening tool, not a clinical diagnosis. Crisis detection features are safety measures, not clinical interventions.
15. Changes to this policy
If we make material changes, we will update the effective date and notify users via the app. Continued use after changes constitutes acceptance.
16. Contact and complaints
Questions or complaints? Contact [email protected]. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) at datatilsynet.dk.