← OneKeep

Security at OneKeep

Last updated:

OneKeep holds some of the most sensitive things your household owns — passport and ID scans, policy numbers, bills, and shared codes. That concentration is the whole value, and the whole responsibility. Security isn't a feature we bolted on; it's a precondition for everything we build. If something can't ship securely, it doesn't ship.

The short version

  • Your data is encrypted in transit and at rest, and stored in the EU.
  • We never sell your data and never use it to train AI — ours or anyone else's.
  • When you photograph a document, we read the useful details and don't keep the image.
  • Each member only sees the sections they've been granted — enforced on our servers, not just hidden.
  • We are not a bank: we never connect to your bank account or move money.
  • You can export or delete everything yourself, any time.

How your data is protected

Encryption. Everything travels over TLS and is encrypted at rest — database and backups included.

EU data residency. Your data is stored in the European Union, with GDPR as our baseline worldwide.

Least privilege. Access is governed by row-level security tied to household membership. A member's device is only sent the sections they're allowed to see; children are deny-by-default.

Minimal by default. We collect only what a reminder or a household actually needs, and discard document images after reading their dates.

No training on your data. Our document-reading AI provider works under a contract that forbids retaining your content or training on it.

Secure codes

Shared passcodes (wifi, door codes, safes) are end-to-end encrypted on your device before they reach us. We store only unreadable ciphertext and cannot see your codes — even if compelled. They never enter the document-reading pipeline or our logs. An independent external security review is completed before this feature becomes generally available.

Payments

Subscriptions are processed by the app stores. OneKeep never receives your card details, and never connects to your bank.

Reporting a vulnerability

Found something? Please tell us at security@onekeep.app. We welcome responsible disclosure and will respond promptly.

Privacy Policy · Terms · Home