Privacy Policy

Last updated 2026-09-05

The short version

KeptWell holds some of the most sensitive information a family ever shares — diagnoses, scans, conversations with doctors. We treat it that way. We don't sell your data, we don't share it with advertisers, and we don't use it to train AI models.

This page explains what we collect, what we do with it, and what choices you have. If anything is unclear, email us at hello@keptwell.org.

What we collect

  • Account information. Your name and email address. If you sign up from a specific marketing page (for example, /parents), we record which page so we can understand what reaches people.
  • Medical documents and notes. When you upload a document, lab result, scan, or audio recording, we store it. When you write a note inside a circle, we store that too. On the web everything you upload flows through our servers into our file storage; the iPhone app sends audio recordings straight from your device into that same storage. Audio recordings are then sent to AssemblyAI for transcription.
  • AI chat history. When you chat with KeptWell about your family's care, we save your messages so the conversation persists across sessions. Chat content is encrypted at rest. AI chat history is private per user — even other members of the same care circle cannot read your conversations.
  • Operational data. We keep what we need to run the service and debug problems: page views, error reports, request timing. We do not track you across other websites.

Health records you connect

KeptWell can import health records from two places: the Health app on your iPhone, and your hospital's patient portal. Nothing is imported until you connect a source yourself, and the patient decides what to connect.

  • What we receive. Lab results, medications and dose history, conditions, allergies, procedures, immunizations, vitals, and clinical notes — whichever of these the source you connected makes available.
  • Where it lives. On our servers, encrypted at rest, in the same storage as documents you upload by hand. Members of your care circle can read it. KeptWell never writes your health records to iCloud.
  • How AI uses it. Imported records are processed by OpenAI and Anthropic to write summaries and answer your questions, exactly like uploaded documents. Neither provider trains on this data.
  • Disconnecting. You can disconnect a source at any time. When you do, you choose whether the records already imported stay in your circle or get deleted with it.

How we use it

To provide the service. Reading documents, generating summaries, answering questions, sending notification emails, sharing inside care circles — that is what your data is for.

To improve the service. We look at aggregate, non-identifying patterns to make KeptWell better. We do not use your data to train AI models.

That is the entire list. We do not sell your data, share it with advertisers, or use it for any kind of profiling.

Who we share data with

KeptWell runs on a small set of carefully chosen third parties. We share only what each one needs to do its job, and nothing more.

OpenAI and Anthropic do not use API inputs or outputs to train their models by default, and KeptWell does not opt in to model training.

Under their standard API terms, content may be retained for up to 30 days for safety and abuse monitoring, and longer when required by law or needed to enforce their usage policies.

  • OpenAI. Reads and summarizes uploaded documents and powers AI chat when OpenAI is the active provider for those tasks. KeptWell disables response storage for these requests.
  • Anthropic. Handles supporting AI tasks through the Claude API. It also powers AI chat and reads and summarizes documents when Anthropic is the active provider for those tasks, including during rollback.
  • AssemblyAI. Transcribes audio recordings of appointments. It receives the recording through a time-limited link, plus the names of your circle members so it can spell them correctly. It retains content under its API terms.
  • Cloudflare. Stores your uploaded files and extracted document text, indexes that text for search, and serves files through signed URLs that expire after five minutes by default. There are no permanent public URLs to your files. Cloudflare's AI Gateway also proxies our requests to the AI providers, so prompt content passes through it in transit.
  • Database and infrastructure providers. Host the PostgreSQL database and application servers that run KeptWell.
  • Sentry. Receives error reports so we can fix bugs. Identifying details are scrubbed before reports are sent.
  • Email delivery service. Sends sign-in links and notification emails on our behalf.

How we protect it

Sensitive fields — chat messages, journal entries, patient names, API keys — are encrypted at rest. All traffic is TLS in transit. Uploaded files live behind signed, time-limited URLs. Every record is scoped to a care circle, and members of one circle cannot see data in another circle. Our Security page describes this in more detail.

How long we keep it

  • Account data. Kept while your account is active. If you delete your account, we delete your data within 30 days.
  • Documents and notes. Kept until you delete them or delete your account. Deleted files are removed from object storage within 30 days.
  • Chat history. Kept until you clear it or delete your account.
  • Operational logs. Kept by our hosting provider and rotated within 90 days.

Your rights

  • Export. Download your full circle — documents, notes, timeline — as a ZIP, anytime, from inside the app.
  • Delete. Delete individual items, or delete your entire account. Account deletion removes all data we hold for you within 30 days, including the documents and notes you uploaded, even in circles other family members keep using.
  • Correct. Edit any record we hold (name, email, document metadata) from inside the app.
  • Access. Ask us what we have on you and we will show you. Email hello@keptwell.org.

Children

KeptWell is built for adults coordinating care for family members. If a circle is created for a minor child receiving care, the adult who creates and manages the circle is responsible for the data inside it. The service is not directed at children, and we do not knowingly collect personal information from children under 13.

International users

KeptWell is operated from the United States. If you use the service from outside the US, you are agreeing that your data may be processed in the US, where data-protection laws may differ from those in your country.

Changes to this policy

We update this page when our practices change. Material changes — new categories of data we collect, new third parties we share with — are flagged with a heading at the top of this page and, where appropriate, an in-app notice.

Contact

Questions, concerns, requests, or anything that needs a real human:

hello@keptwell.org