Keel · Document
Keel Privacy Policy
Keel is a routine tracker built to keep your data on your phone. This policy explains what little we collect, why, where it lives, and how to delete it. No legalese where plain words will do.
The short version
- Keel works fully offline, with no account. Used this way, your data never leaves your device.
- If you choose to sign in, your tracked content syncs to a server so you can restore it.
- We do not sell your data, share it for marketing, run ads, or use third-party analytics or tracking SDKs.
- You can delete everything, account and all server data, from inside the app, immediately.
What Keel collects, and why
Nothing, by default. Without an account, everything you enter — including routines, programs, dose logs, inventory, side-effect entries, blood panels, observations, lab values, and notes — is stored only on your iPhone. We have no copy and no way to see it.
With an optional account. If you sign in — with Apple or with a one-time email code — we store:
- Your auth identity — your email address, your sign-in identifier, and the display name you entered (or that Apple provided), so you can log back in and be greeted by name.
- Your content — routines, programs, dose logs, inventory profiles, side-effect entries, blood-panel entries and lab values, observation events, and the notes you enter with those records, so they can sync and be restored.
- Your subscription link — if you start an App Store purchase while signed in, Keel gives Apple your Keel account UUID as an
appAccountToken. This lets the purchase and resulting Pro entitlement be associated with that Keel account. Keel's server-side entitlement record may include the product, entitlement end date, environment, timestamps, and Apple's original transaction identifier. Keel never receives your payment-card details.
That is the complete list for account, sync, and entitlement functionality. We use it to restore your content, keep it associated with the correct account, and provide purchased Pro access.
Optional location (weather only). If you grant location access, Keel uses your approximate (coarse) location to fetch local weather from Open-Meteo for the ambient sky header. Approximate coordinates are sent to Open-Meteo to answer that request. Keel does not store your location, and it is never tied to your account. Decline the permission and the feature simply stays off.
Notifications. Dose reminders are scheduled and delivered on your device using local notifications; notification delivery and notification content are not sent to Keel's server. If you sign in, the reminder configuration attached to a routine — such as whether reminders and follow-ups are enabled, their timing, snooze choices, sound, and privacy setting — syncs with that routine.
Payments. Subscriptions are billed by Apple through the App Store. Keel never sees your payment-card details. When you purchase while signed in, the account linkage described above applies.
Where your data lives
Synced data is stored with Supabase, our database provider, on servers in the United States. Synced content rows are scoped to the authenticated account. Server-side entitlement records are service-only and are not exposed directly to the app client. Data is encrypted in transit using TLS.
Retention
- No account: we retain nothing, because we have nothing.
- With an account: we keep your synced data for as long as your account exists — no longer.
- Deletion is immediate: deleting your account removes the auth user and every server row at once, via cascading deletion. There is no grace-period copy held back.
Deleting your data
You do not need to email anyone.
- Delete your account: Settings → Delete account. This immediately deletes your sign-in identity and all server data, and clears the app's data from the device.
- Delete all data: a separate Settings option erases everything you have tracked from this device. While signed in, synced data is removed by deleting the account; Keel does not yet offer a server-side erase that keeps your sign-in identity.
- Delete the app: removing the app deletes its on-device data.
Export
You can export your log history as a CSV file at any time. The export is generated on your device.
Third parties
Keel involves a small, fixed set of service providers, each for a narrow purpose:
| Service | Purpose | What they receive |
|---|---|---|
| Supabase (United States) | Authentication and data sync, only if you sign in | Email/auth identity, your synced content, and the server-side Pro entitlement record associated with your account |
| Apple | Sign in with Apple; App Store billing | Purchase and billing data under Apple's terms; for a signed-in purchase, your Keel account UUID is sent as appAccountToken to associate the purchase with that account |
| Open-Meteo | Local weather for the sky header, only if you grant location | Approximate coordinates, per request; not stored by Keel |
| Cloudflare | Website hosting and content delivery; abuse protection; email-address obfuscation; operational network-error handling | Website request data such as IP address and standard browser/HTTP information; security signals used to detect abuse; and operational network-error reports. Cloudflare may set a security cookie when its protection systems require it. Keel does not use Cloudflare for advertising or product analytics. |
There are no advertising networks, no product-analytics SDKs, and no data brokers. We do not sell personal data and do not share it for marketing.
Children
Keel is for adults 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
Changes to this policy
If this policy changes, we will update the version number and effective date here and note meaningful changes in the app. We will not quietly expand what we collect.
Contact
Questions about privacy or your data: [email protected]