Legal

Privacy Policy

Last updated: January 2026 · The same calm tone and typography you see on the Keepscircle homepage.

1. Data We Collect

We collect the details you provide when creating a surprise (name, email, celebration date), the content you upload (photos, audio, copy), and technical diagnostics that help us keep the builder fast and secure.

  • Account basics such as your email and plan tier.
  • Participant data you voluntarily add so we can invite or notify them.
  • Usage analytics (device, timestamps, feature engagement) captured in aggregate.

2. How We Use Data

Your information is used to personalize timelines, send reminders, render reveals, and enforce storage quotas. We do not sell or rent your data.

  • Operate and improve the Keepscircle builder and public surprise pages.
  • Send service emails such as invite requests, approvals, and reveal notifications.
  • Provide customer support when you contact us through hello@keepscircle.com.

3. Sharing & Third Parties

We share data only with essential infrastructure partners such as Supabase (database), AWS S3 (storage), and Stripe (payments). Each partner is bound by confidentiality agreements.

  • Collaborators you invite can see content you explicitly share inside a surprise.
  • We may disclose information if required by law or to prevent harm.

4. Cookies & Tracking

Session cookies keep you authenticated inside the builder and NextAuth maintains the secure session. Analytics cookies are limited to anonymous product insights.

5. Your Choices

You can download or delete your data by emailing support or by using the dashboard controls (data export rolling out soon). You may unsubscribe from non-essential emails at any time.

  • Disable cookies in your browser if you prefer; core features may require them.
  • Request deletion and we will purge personal data within 30 days unless law requires retention.

6. Security

We use SSL encryption, strict access controls, and audit logging across our Supabase Postgres instance. No method is 100% secure, but we take industry-standard precautions.

7. Children

Keepscircle is not intended for children under 16. If we learn that we processed such data, we will delete it promptly.

Contact & Data Requests

Reach us at privacy@keepscircle.com or hello@keepscircle.com for any privacy inquiry, including GDPR or CCPA-style requests.