Last updated:
Data controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COUNTRY]. Contact: privacy@onekeep.app. ICO registration: [PENDING].
OneKeep helps your household keep track of life admin. We ask you to entrust us with sensitive information, so: your data is encrypted and stored in the EU; we never sell it and never use it to train AI; when you photograph a document we read the useful details and don't keep the image; you can export or delete everything any time; and we are not a bank — we never connect to your bank or move money.
| Category | Examples | Why |
|---|---|---|
| Account | Email, auth identifier, sign-in provider | Create and secure your account |
| Household content | Tracked items, bills, budget, lists, chores, meals, recipes, contacts, calendar, inventory, upkeep | Provide the service |
| Document images (transient) | Photos/PDFs you capture | Read dates/fields — not retained |
| Sensitive details you choose to store | Passport/ID numbers, policy numbers, emergency card | Because you asked us to track them |
| Subscription | Purchase/entitlement status, tier, seats | Manage your plan |
| Device & diagnostics | Push token, app version, crash data | Deliver reminders, fix issues |
We practise data minimisation — collecting only what a reminder or a household actually needs.
We do not sell or rent your data; do not use your data or documents to train AI (our extraction provider is contractually barred from retaining content or training on it); do not connect to your bank or hold bank credentials; do not show third-party ads; and do not put personal data in URLs or analytics.
When you photograph or upload a document, the image is sent over an encrypted connection to our extraction service (a vision AI provider under a zero-retention, no-training contract). We keep only the structured fields you confirm — we do not store the image, and you confirm what's saved before it's saved.
Household members share data according to the per-section access the owner grants. A member only sees the sections they've been given; the server enforces this. Owners can change access at any time.
Shared passcodes are end-to-end encrypted on your device before they reach us. We store only ciphertext and cannot read them, even if compelled. They never enter the extraction pipeline or our logs.
We use vetted providers to run OneKeep (database/auth/storage, document extraction, notifications, subscriptions, analytics), each required to meet GDPR standards, with EU processing where possible. A current list is available on request.
Child accounts are created by an account owner (a parent/guardian), collect minimal data, are deny-by-default for sensitive sections, and are never marketed to. We handle children's data under applicable law (UK GDPR / ICO Children's Code / COPPA where relevant).
Your data is stored in the EU and encrypted in transit and at rest, with access governed by row-level security tied to household membership. See our security overview.
We keep your data while your account is active. You can export or delete everything in the app; see data deletion. On deletion we purge your households' data; some records may be retained only where the law requires.
Under UK/EU GDPR you can access, correct, delete, restrict, object to, or port your data. OneKeep provides self-serve export and deletion in the app; for anything else contact privacy@onekeep.app. You may complain to the ICO or your local supervisory authority.
We'll update this policy as OneKeep evolves and notify you of material changes in-app or by email.