1. Summary
- No account, login or sign-up.
- No advertising SDKs.
- No analytics or telemetry.
- No crash reporting services.
- Your memories remain on your device.
- Network requests occur only for optional user-initiated features such as link previews and AI processing.
We never sell, rent or monetize your personal information.
2. Information We Collect
Keeper does not collect any personal information on our servers, because we do not operate any servers. The content you choose to save on your own device through Keeper may include:
- Notes you type
- Links (URLs) you share into the app
- Screenshots and images you share into the app
- PDF files you share into the app
- Video files you share into the app
- Other file types you share into the app
- Tags, favorite status and personal notes you attach to saved memories
- Optional metadata Keeper derives from the above (titles, OCR text, AI-generated summaries or tags — see section 4)
Keeper also records a small amount of local-only usage state to power features such as "Recent searches," "Popular tags," and "Rediscover." This is stored in the same encrypted on-device database and is never transmitted anywhere.
3. Where Your Data Is Stored
| Item | Location | Protection |
|---|---|---|
| Memories database | keeper_secure.db in the app's private data directory | Full-database encryption with SQLCipher (AES‑256). Passphrase generated on first launch. |
| App settings | keeper_secure_settings (EncryptedSharedPreferences) | Android Keystore-backed |
| Theme preferences | keeper_design_preferences (EncryptedSharedPreferences) | Android Keystore-backed |
| Database passphrase | keeper_db_credentials (EncryptedSharedPreferences) | Android Keystore-backed |
| Captured files (shared screenshots, PDFs, video frames) | filesDir/captures/ in the app's private data directory | Private to the Keeper process; not world-readable |
| Exported backups | The location you pick via the Android file picker | Outside Keeper's control once exported |
Uninstalling Keeper removes all of the above except backups you exported yourself.
4. Network Usage
Keeper makes outbound network requests only in the following cases, all triggered by an explicit user action.
4.1 Link metadata preview
When: You share a URL into Keeper.
What is sent: Keeper fetches the page itself (just like a web browser) to read its <title>, og:title, og:description, and og:image. Requests are capped at 256 KB and time out after 10 seconds.
Where it goes: Directly to the website's own server. Keeper does not route this through any third party.
4.2 AI metadata enrichment (optional)
When: You have configured a Google Gemini API key and you save a memory whose content can be summarized (note text, link content, OCR text, etc.).
What is sent: The text content of that memory is sent to Google's Gemini API to generate a short summary and suggested tags.
Where it goes: https://generativelanguage.googleapis.com, operated by Google.
If no key is configured (the default): No request is made to Google. Keeper falls back to a fully on-device, rule-based analyzer.
Your data and Google: When this feature is enabled, the text portion of the affected memory is governed by Google's Gemini API terms and privacy practices. Please review Google's API documentation for details on how they handle prompt content.
4.3 Image fetching for previews
When: A saved memory has an associated image URL (for example, the og:image captured in 4.1, or a YouTube thumbnail).
What is sent: A standard HTTP image request.
Where it goes: Directly to the image host (for example, i.ytimg.com for YouTube thumbnails). Keeper does not proxy these requests.
No other network calls are made by the app.
5. Permissions
| Permission | Why |
|---|---|
INTERNET | Required only for the optional cases in section 4. The app functions fully offline if you never share a link and never configure an AI key. |
POST_NOTIFICATIONS (Android 13+) | Optional "Rediscover" reminder toggle in Profile → Notifications. Denying it disables the toggle; the rest of the app is unaffected. |
Keeper does not declare READ_MEDIA_IMAGES, READ_EXTERNAL_STORAGE, CAMERA, RECORD_AUDIO, ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, READ_CONTACTS, READ_PHONE_STATE, SMS, CALL_LOG, FOREGROUND_SERVICE, or RECEIVE_BOOT_COMPLETED.
Image and file inputs go through Android's Photo Picker (ActivityResultContracts.PickVisualMedia) and the system Storage Access Framework (share-intent content:// URIs, OpenDocument / CreateDocument). Both surfaces grant Keeper time-limited read access to the specific file you chose — no broad-storage permission is required.
Keeper does not request location, contacts, microphone, camera, calendar, phone, SMS, call logs, biometric data, or any background access permissions.
6. App Lock & Biometrics
Keeper supports an optional app lock backed by Android's BiometricPrompt API. When you enable it:
- The biometric check is performed by Android itself. Keeper never reads, stores, or transmits your fingerprint, face, or device passcode.
- The "Lock after timeout" and "Lock on app restart" toggles are local-only and simply re-prompt the OS authenticator when the app returns to the foreground.
- If your device has no enrolled biometric or device credential, the lock cannot be enforced and the app opens normally.
7. Backup & Restore
Backups happen only when you tap Export in the Profile screen and pick a destination via the Android Storage Access Framework. The backup is a JSON file written to the location you choose. Keeper does not upload the backup anywhere. The security of that file once it leaves Keeper is determined by where you store it (local folder, cloud drive, etc.).
Restore is symmetrical: you pick a JSON file via the Android file picker, and Keeper imports it into the on-device database.
Android's system backup is configured by backup_rules.xml and data_extraction_rules.xml in the app sources.
8. Third-Party Services
Keeper integrates with the following third parties only under the conditions in section 4:
- Google Gemini API — optional, off by default. Used only if you supply your own API key.
- Arbitrary web servers — when you share a link, Keeper fetches that link's own server, and possibly the image host referenced by its
og:image.
No advertising networks, analytics providers, attribution SDKs, or other third-party integrations are present in the app.
9. Children's Privacy
Keeper is not directed toward children under 13. Since Keeper has no backend servers, it does not knowingly collect children's personal information.
10. Your Rights
Because all of your Keeper content lives on your own device:
- Access: Open the app — every memory is visible.
- Export: Use the Export button in Profile to obtain a JSON copy of all data.
- Delete a single item: Open the memory and tap delete.
- Delete everything: Uninstall Keeper, or clear app data from Android Settings → Apps → Keeper → Storage → Clear data.
We cannot delete data on your behalf because we do not have it.
11. Security
- Full-database encryption at rest using SQLCipher (AES‑256).
- All sensitive small-value storage in
EncryptedSharedPreferences, keyed by an Android Keystore master key. - Optional biometric / device-credential app lock.
usesCleartextTrafficis disabled in the manifest — outbound HTTP requests are made over TLS.- No background services, no foreground services, no boot receivers.
No system is perfectly secure. Keep your device updated and use a screen lock to maximize protection.
12. Changes to This Policy
If this policy is updated, the Last Updated date at the top of this page will change. Material changes will be noted in the project's GitHub release notes. Continued use of the app after a change constitutes acceptance of the revised policy.
13. Contact
For privacy questions, please:
- Open an issue on the project's GitHub repository, or
- Email: support@keeper.com
We will respond on a best-effort basis. Because Keeper has no account system, please do not send us your personal memory content — we cannot identify, look up, or act on it.
T1. What Keeper Is
These terms govern your use of the Keeper Android application ("the app"). By installing or using the app you accept the terms below. If you do not accept them, uninstall the app.
Keeper is a local-first personal-notes app: notes, links, screenshots, PDFs, videos, and other files you save through the share sheet or the in-app capture form. Content lives on your device, in the app's private encrypted storage. See the Privacy Policy above for how data is handled.
T2. Your Account, Your Data
- Keeper has no account system. There is no sign-up and no login.
- The data you save is yours. Back it up with the in-app Export action if it matters to you; uninstalling the app or clearing app storage removes the on-device copy.
- We are not able to recover data on your behalf, because we do not have it.
T3. Acceptable Use
You agree not to use Keeper to:
- Store content whose possession, distribution, or processing is unlawful in your jurisdiction.
- Circumvent the app's security controls or attempt to access another user's device data.
- Reverse-engineer, distribute, or resell the app in a way that violates the licenses of its open-source dependencies (see the "Open-source licenses" row in the app).
T4. AI Enrichment (Optional)
If you configure a Google Gemini API key in the app, memory text is sent to Google's Gemini API for tag / summary enrichment. When this feature is enabled, your use of that text is additionally subject to Google's Gemini API terms and privacy practices. Review Google's documentation before enabling.
Keeper does not modify or store what Google returns beyond writing it back into your local memory database.
T5. Third-Party Content
When you share a link into Keeper, the app fetches that URL and any og:image referenced by it. Keeper is not responsible for the content, availability, or licensing of any third-party page you save.
T6. Warranty Disclaimer
The app is provided "as is," without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, and non-infringement. The developer does not guarantee that the app will be error-free, uninterrupted, or that saved data will always be recoverable.
T7. Limitation of Liability
To the maximum extent permitted by law, the developer is not liable for any indirect, incidental, consequential, or punitive damages arising out of or related to your use of the app, including but not limited to loss of data. Your only remedy in the event of dissatisfaction is to stop using and uninstall the app.
T8. Changes to These Terms
If these terms are updated, the Last Updated date at the top of this page will change. Continued use of the app after a change constitutes acceptance of the revised terms.
T9. Contact
For questions about these terms, email admin@keeper.com or open an issue on the project's GitHub repository.