← Back to Legal Overview

Privacy Policy

Last updated: 28 August 2026 · In effect now

This policy is already in effect; our Terms change on 29 August 2026. A privacy policy describes what we actually do with your data, so publishing a more accurate one and then waiting a month to apply it would make no sense — the practices it describes are the current ones. Our Terms and Conditions and Refund Policy are agreements rather than descriptions, so their new versions take effect on 29 August 2026 after 30 days' notice. We emailed every account about all three.
In short. Keepr Circle is a private family photo service. Your photos are yours: we don't sell them, we don't advertise against them, and we never use them to train AI models — not ours, and not anyone else's. Photos are analysed on our own servers so you can search them, they are never sent to an outside AI company, and you can turn that analysis off — and delete what it produced — in Profile → Privacy. You can export everything at any time, on any plan, and deleting removes the files as well as the records. This page explains all of that, including the parts that are less flattering.

1. Introduction

Keepr Circle ("we", "our", "us") provides a photo storage and sharing service (the "Service"). This policy explains what we collect, why, how long we keep it, and what you can do about it.

Who is responsible for your data. The controller of the personal data described here is Keepr Circle, registered in the Netherlands. Registered name, Chamber of Commerce (KvK) number and registered address: to be completed. You can reach us about anything in this policy at [email protected].

It describes how the Service works today. If our practices change, we will update this policy and the date above.

2. Information we collect

2.1 Account information

You sign in with Google or with an email address and password, through Firebase Authentication (a Google service). From this we receive and store:

We never receive or store your password. If you sign in with a password, Firebase holds it, not us.

2.2 Content you upload

2.3 Information we derive from your photos

To make your library searchable and to group near-identical shots, our servers compute two things from each photo and store them alongside it:

Section 4 explains how this works and what it does not do.

2.4 How you use the Service

2.5 Payment information

Subscriptions are processed by Stripe. Card details go directly to Stripe and we never see or store them. We store your Stripe customer identifier, your plan, and your billing history. Charges are currently made in US dollars regardless of where you are.

3. Why we process it

PurposeData usedLegal basis
Creating and securing your accountAccount informationContract
Storing and delivering your photosUploaded content, sharing settingsContract
Preparing photos for viewing (resizing, video transcoding)Uploaded contentContract
Search, and grouping near-identical shotsPhoto content, derived hashes and embeddingsContract
Chat, comments, notificationsMessages, activity, push tokensContract
BillingPayment information, storage usedContract
Reminder emails and notifications, and deciding when to stop sending themTime zone, activity days, send recordsLegitimate interests
Diagnosing faults and improving reliabilityDiagnostic events, device informationLegitimate interests
Finding gaps in our help documentationQuestions asked of the help pages (no account identifier)Legitimate interests
Understanding our public marketing pagesAnalytics on those pages only (section 10)Legitimate interests
Meeting legal obligationsAs requiredLegal obligation

4. Automated analysis of your photos

This section exists because "we use AI on your photos" and "we take your photos and feed them to an AI company" are very different things, and the difference matters.

What happens

When you upload a photo, our servers run a machine-learning model over it to produce the embedding described in section 2.3. That embedding is what makes it possible to search your library by describing a picture. A separate, much simpler calculation produces the perceptual hash used to group burst shots.

What does not happen

Turning it off

Profile → Privacy → Photo indexing. It is on by default, and you can switch it off at any time. The switch applies to photos you add from then on: we stop running the image model over new uploads. It does not change anything already stored, so photos we have already analysed stay searchable and switching it off and back on costs you nothing.

Removing what we have already produced is a separate button on the same screen, Delete the index of your photos. That deletes the embeddings described in section 2.3 for every photo you have uploaded — they are removed, not hidden. Two features get worse as a result: searching your library by describing a picture will no longer find those photos, and only exact copies are grouped as duplicates rather than near-identical ones. Your photos, your albums and the groups you already have are not affected. A second button re-indexes photos that have none, which happens in the background.

This setting covers the analysis described above. Were we ever to introduce face recognition, it would require your separate, explicit consent and would not be covered by this setting or enabled by it.

Searching in your own language

If you search in a language other than English, your search words are translated to English before the search runs, because the image model understands English best. This translation happens on our servers. Your photos are not translated, moved, or sent anywhere.

Availability

Search by description is available on plans of 500 GB and above, or through membership of a Family Hub whose plan meets that threshold. Duplicate grouping runs on all plans.

5. Who we share it with

5.1 Other people, according to your settings

Nothing is shared by default. Sharing happens when you do it.

5.2 Service providers

ProviderWhat they handle
WasabiStorage of your photos and videos
RailwayHosting for our application, database, and a separate media-processing service that transcodes videos and computes the signals in section 2.3
Firebase Authentication (Google)Sign-in and password handling
StripePayments
SendGridEmail delivery
Content delivery networkFaster delivery of your media

These providers process data on our instructions. We do not sell personal information to anyone, and we do not share it with advertisers.

5.3 Legal requirements

We may disclose information where legally required — valid legal process, lawful law enforcement requests, or an emergency involving a risk to someone's safety.

6. Security

What we do not claim. Nothing in Keepr is end-to-end encrypted. Your photos and videos travel over HTTPS and are encrypted at rest by our storage provider; circle chat messages are encrypted a second time by us before they are stored. In both cases the keys belong to us and to that provider rather than to you, and that is the whole of the difference: end-to-end encryption makes a provider unable to read your content, whereas here the protection is that Keepr is not built to. Content is decrypted automatically in order to show it to someone who already has access, and for nothing else. We do not review it, we do not use it for advertising, and we do not send it to another company for analysis. Beyond that, access is limited to the legal disclosures described in section 5.3. If you need a mathematical guarantee rather than an operational one, use a tool built for that.

7. Your rights and controls

7.1 Export everything, on any plan

You can request a full export of your account — your photos and videos plus your account information, circles and memberships. We prepare it in the background and email you a link, usually within half an hour. The link works for 7 days, after which the prepared file is removed and you can request another. There is no limit and no charge, including on the free plan.

7.2 Deleting individual photos and albums

Deleting a photo or an album is immediate and permanent. There is no trash, no recycle bin and no undo, and the content goes for everyone who could see it. The stored files are removed from our storage as well, within about 7 days of the deletion — see section 8.

7.3 Deleting your account

You can delete your account from within the app. It is confirmed with a six-digit code emailed to your address.

Confirming schedules the deletion for 7 days later rather than performing it immediately, so that an accidental deletion can be undone. During those 7 days:

After 7 days the deletion runs and cannot be reversed.

7.4 Other rights

You have the right to access the personal data we hold, to correct it, to receive it in a portable format (the export above), to request its deletion, to object to or restrict processing, to withdraw consent, and to complain to a supervisory authority.

7.5 Controls in the app

8. How long we keep things

8.1 While your account is active

One record outlives a deleted account, and it is anonymous: when an account closes we keep the date, how long it existed, the plan it was on and whether it was paying, roughly how much was stored and how many photos there were (as bands, not exact figures), how many circles and hubs it belonged to, whether it had been used in the last 30 days, and the reason you chose from the list if you chose one. It contains no name, no email address, no user identifier and no hash of one, so it cannot be traced back to you. We keep it because otherwise we would have no way to know how many people leave, or why.

8.2 When you delete content or your account

Database records are removed at the point of deletion. The stored files are queued for removal and deleted from object storage within about 7 days.

The short delay is deliberate: it means a storage failure is retried rather than silently losing files after we have already told you the content is gone. It is not a recovery period — nothing can be restored during it.

One record outlives the account. To delete your files we have to keep a list of which files to delete, and that list necessarily includes your account identifier (it forms part of each file's storage path). This queue is removed once the files are deleted. It contains no photos, messages or profile information.

8.3 Billing and legal

8.4 If a payment fails

If a subscription payment fails or a plan is cancelled, a personal account keeps full access for 14 days while we retry, then becomes read-only. A Family Hub becomes read-only straight away, with 30 days to resolve the payment. Read-only means everything stays visible and downloadable and only new uploads stop.

Nothing is deleted because a payment failed. Read-only lasts indefinitely and has no expiry after which we delete anything. There is no retention countdown here.

8.5 Content other people can still see

If you gave ownership of photos to someone else, or someone else uploaded photos into your album, those belong to them and are not removed when you leave.

9. Where your data is processed

Our object storage is configured to a European region (Amsterdam) by default. Our application and database are hosted with Railway, and some of our providers — including Stripe, SendGrid, Firebase and our content delivery network — operate globally, so some processing and delivery happens outside the European Economic Area.

Where data leaves the EEA we rely on appropriate safeguards, including Standard Contractual Clauses with our providers.

10. Cookies and analytics

10.1 Essential

10.2 Marketing pages

On our public, signed-out marketing pages we record which sections of the page were reached, how long each was on screen, which buttons were used, which questions were opened, the website that linked you to us, your browser's language, and whether you were on a phone, a tablet or a desktop. If you start creating an account from one of those buttons, we record which button it was. This is our own measurement, kept on our own servers: no third-party analytics service is loaded on any Keepr page, and there is no cookie behind it. Nothing about a visitor is stored — no name, no email, no account identifier and no hash of one — because a signed-out visitor has none of those. We use it to find where the page loses people.

Two limits worth stating plainly. For the referring website we keep the site's address only, never the full link, because a full referrer routinely contains the search terms someone typed — and those can contain anything. And screen size is recorded as one of three bands rather than actual dimensions. Language is the language alone — "nl", not "nl-BE" — because the question is whether this page should exist in Dutch, not which country you read from. All of it answers what we need without narrowing anyone down.

Measurement starts on your first visit rather than waiting for a choice, and you can switch it off at any time: use Turn it off on the notice shown on your first visit, or Profile → Privacy → Usage measurement, which is permanent and always available. Switching it off stops all measurement in that browser, including the diagnostic events described in section 2.4.

Until August 2026 these pages loaded Microsoft Clarity for the same purpose. It has been removed, and no data goes to Microsoft from any part of Keepr.

10.3 What we don't do

We do collect diagnostic and engagement data inside the app, as described in section 2.4. We would rather describe that accurately than claim we track nothing.

11. Children

Keepr Circle is designed for families, but an account holder must be at least 16 in the European Economic Area and the United Kingdom, and at least 13 elsewhere. Where local law sets a different minimum age for using an online service without a parent's permission, that age applies.

We do not knowingly collect information from anyone below that age. If we learn that we have, we will delete it. Photographs of children are of course common on a family photo service; those are the account holder's content, and the account holder is responsible for having the right to share them.

12. Regional rights

12.1 European Union and United Kingdom

You have the rights listed in section 7.4, including the right to lodge a complaint with your supervisory authority. Because we're established in the Netherlands, that is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) — but you can also complain to the authority in the EU country where you live, or to the ICO if you're in the UK.

12.2 California

You have the right to know what we collect, to delete it, to opt out of sale (we do not sell personal information), and not to be treated differently for exercising those rights.

13. Changes to this policy

We will update this policy when our practices change. For material changes we will notify you by email or in the app at least 30 days before they take effect, and the "last updated" date above always reflects the current version.

14. Contact us

We respond to privacy requests within 30 days, or sooner where the law requires it.