Privacy Policy

What we collect, and why.

This policy explains what personal data Keelnest processes when you visit our site, run the free check, or use the service, and the choices you have. It is written to be read, not skimmed past.

Effective 12 September 2026

1. Who we are

Keelnest (“we”, “us”) provides monitoring, publish verification and cost tracking for web applications. For data you give us as a customer, we are the controller. For observation data that comes from your applications and your customers, you are the controller and we process it on your instructions under these terms and the Terms of Service. Contact us at privacy@keelnest.com.

2. Data we collect from you

  • Account data. Name, email address, workspace name, the sign-in method you choose (email link, password, Google or GitHub), profile picture if your identity provider supplies one, and your role in each workspace.
  • Billing data. Your tier, invoices and payment status. Card details are entered directly with our payment processor, Polar, and never reach our servers.
  • Configuration. The applications you add, their URLs, the providers you connect, journeys you confirm, budgets, response targets, clients and maintenance plans.
  • Provider credentials. OAuth tokens, GitHub App installations, Stripe restricted keys and provider admin keys you connect. See section 6 for how they are protected.
  • Communications. Emails you send us, support requests and survey answers.

3. Data we collect by observing your applications

This is the data the product exists to collect. It is scoped to the applications you add and the providers you connect.

  • Availability and configuration. HTTP responses, response times, TLS certificate details, security headers, redirect and origin settings, and the names of environment variables compared between publishes. Values are never stored.
  • Deployments. Deployment metadata, commit identifiers, changed file paths and webhook payloads from Vercel, Netlify and GitHub, or a build fingerprint when a builder does not report publishes.
  • Journeys. Results of the browser walkthroughs you confirm, with timings, assertions, sanitized screenshots and traces. Test accounts and safe test payment methods are stored as secret references.
  • Payments. Hourly aggregates of payment counts and totals, webhook endpoint health and event types from Stripe. We do not request card numbers, and we minimize customer identifiers to what a finding needs.
  • Usage and cost. Token usage and billed cost from OpenAI, Anthropic and hosting providers, per application and per day.
  • Errors. If you install the optional capture snippet: error messages, stack traces, page URLs and browser details, with credentials and personal data redacted at ingestion.

4. Data we collect automatically

  • Site and product analytics. Pages viewed, features used, approximate location from IP address, browser and device type. We use this to understand what works and to fix what does not.
  • Logs. Request logs with IP address, timestamps and status codes, kept for security and debugging.
  • Cookies. A session cookie to keep you signed in and a preference cookie for theme and layout. We do not use advertising cookies or cross-site tracking.

5. The Free Silent Failure Check

When you run the public check we store the URL you entered, the findings, the time and a share identifier so the result can be opened by link. Checks are passive: we fetch public pages and headers as a browser would, and when testing an exposed key we read at most one row to demonstrate exposure without collecting the data. The share link contains no personal data. Results are deleted after 30 days.

6. How we protect provider credentials

Credentials are encrypted at rest with a key held only in the runtime secret store, never in the database, logs or backups in plain form. We request the narrowest scope each provider offers and use short-lived tokens where they are supported. Credentials are used only for the reads described on the security page, are redacted from every log, screenshot, trace and model prompt, and are deleted immediately when you revoke a connection.

7. Why we process data and on what basis

  • To provide the service you signed up for: monitoring, verification, explanations, reports and alerts. Basis: performance of a contract.
  • To bill you and keep required financial records. Basis: contract and legal obligation.
  • To keep the service secure, prevent abuse and investigate incidents. Basis: legitimate interest.
  • To improve the product using aggregated usage analytics. Basis: legitimate interest; you can opt out in Settings.
  • To send product emails about incidents, publishes and your account. Alerts are part of the service; marketing emails are sent only with consent and every one has an unsubscribe link.

8. AI explanations

When you request an explanation or a repair, incident evidence is sent to a model provider (currently Anthropic and OpenAI) with secrets and personal data redacted. Providers are contractually barred from training on this data. Explanations are stored with the incident so your team can read them later.

9. Who we share data with

We share data only with processors that help us run the service, under data processing agreements, and never sell it. Current processors: Cloudflare (compute, browser rendering, network), a managed Postgres provider (database), Polar (billing), a transactional email provider (alerts and account email), Anthropic and OpenAI (explanations, redacted), and an error monitoring provider for our own application. We disclose data to authorities only when legally required, and we tell you when we are allowed to.

10. International transfers

Our processors operate in the European Union and the United States. Where data leaves the EEA or the United Kingdom, transfers rely on standard contractual clauses or an adequacy decision. Reports are rendered in the timezone you choose, but storage location follows the processors above.

11. How long we keep data

  • Observation data: the history window of your tier (7 days to 1 year), then deleted.
  • Screenshots and traces: 30 days, or the tier’s window if shorter.
  • Audit events: 1 year.
  • Account and billing records: for the life of the account, then as long as tax law requires.
  • Deleting an application deletes its evidence within 24 hours. Deleting a workspace deletes everything within 30 days, backups included.

12. Your rights

You can access, correct, export or delete your data from Settings. If you are in the EEA, the United Kingdom, Switzerland or a jurisdiction with similar law, you also have the right to restrict or object to processing, to portability, and to lodge a complaint with your supervisory authority. Write to privacy@keelnest.com and we answer within 30 days. We never discriminate for exercising a right.

13. Children

The service is for businesses and is not directed at anyone under 16. We do not knowingly collect data from children; tell us if you believe we have, and we will delete it.

14. Security incidents

If a breach affects your data we notify you without undue delay, and within 72 hours where the law requires it, with what happened, what data was involved and what we are doing about it.

15. Changes to this policy

We may update this policy as the product and the law change. Material changes are announced by email and in the app at least 14 days before they take effect. The date at the top is the version in force.

16. Contact

privacy@keelnest.com for anything about this policy, security@keelnest.com for vulnerability reports.