Last updated: 28 August 2026 · In effect now
Keepr Circle ("we", "our", "us") provides a photo storage and sharing service (the "Service"). This policy explains what we collect, why, how long we keep it, and what you can do about it.
It describes how the Service works today. If our practices change, we will update this policy and the date above.
You sign in with Google or with an email address and password, through Firebase Authentication (a Google service). From this we receive and store:
We never receive or store your password. If you sign in with a password, Firebase holds it, not us.
To make your library searchable and to group near-identical shots, our servers compute two things from each photo and store them alongside it:
Section 4 explains how this works and what it does not do.
Europe/Warsaw), collected automatically from your app so that daily
reminder emails and notifications arrive in your morning rather than at a random
hour. There is no setting for this; it updates as your device's time zone changes.Subscriptions are processed by Stripe. Card details go directly to Stripe and we never see or store them. We store your Stripe customer identifier, your plan, and your billing history. Charges are currently made in US dollars regardless of where you are.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and securing your account | Account information | Contract |
| Storing and delivering your photos | Uploaded content, sharing settings | Contract |
| Preparing photos for viewing (resizing, video transcoding) | Uploaded content | Contract |
| Search, and grouping near-identical shots | Photo content, derived hashes and embeddings | Contract |
| Chat, comments, notifications | Messages, activity, push tokens | Contract |
| Billing | Payment information, storage used | Contract |
| Reminder emails and notifications, and deciding when to stop sending them | Time zone, activity days, send records | Legitimate interests |
| Diagnosing faults and improving reliability | Diagnostic events, device information | Legitimate interests |
| Finding gaps in our help documentation | Questions asked of the help pages (no account identifier) | Legitimate interests |
| Understanding our public marketing pages | Analytics on those pages only (section 10) | Legitimate interests |
| Meeting legal obligations | As required | Legal obligation |
This section exists because "we use AI on your photos" and "we take your photos and feed them to an AI company" are very different things, and the difference matters.
When you upload a photo, our servers run a machine-learning model over it to produce the embedding described in section 2.3. That embedding is what makes it possible to search your library by describing a picture. A separate, much simpler calculation produces the perceptual hash used to group burst shots.
Profile → Privacy → Photo indexing. It is on by default, and you can switch it off at any time. The switch applies to photos you add from then on: we stop running the image model over new uploads. It does not change anything already stored, so photos we have already analysed stay searchable and switching it off and back on costs you nothing.
Removing what we have already produced is a separate button on the same screen, Delete the index of your photos. That deletes the embeddings described in section 2.3 for every photo you have uploaded — they are removed, not hidden. Two features get worse as a result: searching your library by describing a picture will no longer find those photos, and only exact copies are grouped as duplicates rather than near-identical ones. Your photos, your albums and the groups you already have are not affected. A second button re-indexes photos that have none, which happens in the background.
This setting covers the analysis described above. Were we ever to introduce face recognition, it would require your separate, explicit consent and would not be covered by this setting or enabled by it.
If you search in a language other than English, your search words are translated to English before the search runs, because the image model understands English best. This translation happens on our servers. Your photos are not translated, moved, or sent anywhere.
Search by description is available on plans of 500 GB and above, or through membership of a Family Hub whose plan meets that threshold. Duplicate grouping runs on all plans.
Nothing is shared by default. Sharing happens when you do it.
| Provider | What they handle |
|---|---|
| Wasabi | Storage of your photos and videos |
| Railway | Hosting for our application, database, and a separate media-processing service that transcodes videos and computes the signals in section 2.3 |
| Firebase Authentication (Google) | Sign-in and password handling |
| Stripe | Payments |
| SendGrid | Email delivery |
| Content delivery network | Faster delivery of your media |
These providers process data on our instructions. We do not sell personal information to anyone, and we do not share it with advertisers.
We may disclose information where legally required — valid legal process, lawful law enforcement requests, or an emergency involving a risk to someone's safety.
You can request a full export of your account — your photos and videos plus your account information, circles and memberships. We prepare it in the background and email you a link, usually within half an hour. The link works for 7 days, after which the prepared file is removed and you can request another. There is no limit and no charge, including on the free plan.
Deleting a photo or an album is immediate and permanent. There is no trash, no recycle bin and no undo, and the content goes for everyone who could see it. The stored files are removed from our storage as well, within about 7 days of the deletion — see section 8.
You can delete your account from within the app. It is confirmed with a six-digit code emailed to your address.
Confirming schedules the deletion for 7 days later rather than performing it immediately, so that an accidental deletion can be undone. During those 7 days:
After 7 days the deletion runs and cannot be reversed.
You have the right to access the personal data we hold, to correct it, to receive it in a portable format (the export above), to request its deletion, to object to or restrict processing, to withdraw consent, and to complain to a supervisory authority.
One record outlives a deleted account, and it is anonymous: when an account closes we keep the date, how long it existed, the plan it was on and whether it was paying, roughly how much was stored and how many photos there were (as bands, not exact figures), how many circles and hubs it belonged to, whether it had been used in the last 30 days, and the reason you chose from the list if you chose one. It contains no name, no email address, no user identifier and no hash of one, so it cannot be traced back to you. We keep it because otherwise we would have no way to know how many people leave, or why.
Database records are removed at the point of deletion. The stored files are queued for removal and deleted from object storage within about 7 days.
The short delay is deliberate: it means a storage failure is retried rather than silently losing files after we have already told you the content is gone. It is not a recovery period — nothing can be restored during it.
If a subscription payment fails or a plan is cancelled, a personal account keeps full access for 14 days while we retry, then becomes read-only. A Family Hub becomes read-only straight away, with 30 days to resolve the payment. Read-only means everything stays visible and downloadable and only new uploads stop.
Nothing is deleted because a payment failed. Read-only lasts indefinitely and has no expiry after which we delete anything. There is no retention countdown here.
If you gave ownership of photos to someone else, or someone else uploaded photos into your album, those belong to them and are not removed when you leave.
Our object storage is configured to a European region (Amsterdam) by default. Our application and database are hosted with Railway, and some of our providers — including Stripe, SendGrid, Firebase and our content delivery network — operate globally, so some processing and delivery happens outside the European Economic Area.
Where data leaves the EEA we rely on appropriate safeguards, including Standard Contractual Clauses with our providers.
On our public, signed-out marketing pages we record which sections of the page were reached, how long each was on screen, which buttons were used, which questions were opened, the website that linked you to us, your browser's language, and whether you were on a phone, a tablet or a desktop. If you start creating an account from one of those buttons, we record which button it was. This is our own measurement, kept on our own servers: no third-party analytics service is loaded on any Keepr page, and there is no cookie behind it. Nothing about a visitor is stored — no name, no email, no account identifier and no hash of one — because a signed-out visitor has none of those. We use it to find where the page loses people.
Two limits worth stating plainly. For the referring website we keep the site's address only, never the full link, because a full referrer routinely contains the search terms someone typed — and those can contain anything. And screen size is recorded as one of three bands rather than actual dimensions. Language is the language alone — "nl", not "nl-BE" — because the question is whether this page should exist in Dutch, not which country you read from. All of it answers what we need without narrowing anyone down.
Measurement starts on your first visit rather than waiting for a choice, and you can switch it off at any time: use Turn it off on the notice shown on your first visit, or Profile → Privacy → Usage measurement, which is permanent and always available. Switching it off stops all measurement in that browser, including the diagnostic events described in section 2.4.
Until August 2026 these pages loaded Microsoft Clarity for the same purpose. It has been removed, and no data goes to Microsoft from any part of Keepr.
We do collect diagnostic and engagement data inside the app, as described in section 2.4. We would rather describe that accurately than claim we track nothing.
Keepr Circle is designed for families, but an account holder must be at least 16 in the European Economic Area and the United Kingdom, and at least 13 elsewhere. Where local law sets a different minimum age for using an online service without a parent's permission, that age applies.
We do not knowingly collect information from anyone below that age. If we learn that we have, we will delete it. Photographs of children are of course common on a family photo service; those are the account holder's content, and the account holder is responsible for having the right to share them.
You have the rights listed in section 7.4, including the right to lodge a complaint with your supervisory authority. Because we're established in the Netherlands, that is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) — but you can also complain to the authority in the EU country where you live, or to the ICO if you're in the UK.
You have the right to know what we collect, to delete it, to opt out of sale (we do not sell personal information), and not to be treated differently for exercising those rights.
We will update this policy when our practices change. For material changes we will notify you by email or in the app at least 30 days before they take effect, and the "last updated" date above always reflects the current version.
We respond to privacy requests within 30 days, or sooner where the law requires it.