Legal
Privacy Policy
Last updated: 5 August 2026
Kept is a self-hosted personal-finance tool for Australian households. This policy explains, in plain English, what data Kept handles, why, and how it is protected. It applies to the Kept web app served at keptsavings.com and myfamilyfinance.app.
1. Who we are
Kept ("Kept", "we", "us") is an independently operated, self-hosted personal-finance application run by its operator in Melbourne, Australia. Kept lets you bring together your bank statements, accounts, transactions, assets and income into one clear picture of your household money. You can reach us at [email protected].
2. Data we collect
Kept only collects the data it needs to provide the app. There is no advertising network, no data broker, and no tracking of you across other websites.
2.1 Account and sign-in data (Google)
You sign in to Kept with Google Sign-In (Google Identity Services). When you sign in, Google gives Kept a signed identity token, from which Kept reads:
- your email address;
- your name;
- your Google account ID (the
subidentifier), used to verify the token; and - your profile picture URL.
Kept stores your email, name and profile picture in the short-lived session token it issues to keep you signed in (this session expires after about one week). Kept does not receive or store your Google password, and it does not request access to your Gmail, Google Drive, contacts or any other Google service. Access to Kept is limited to an allow-list of approved email addresses configured by the operator.
2.2 Financial data you add
Kept works from the financial information you choose to give it. Depending on how you use the app, this can include:
- Transactions — dates, descriptions, amounts, running balances, the account they belong to, categories and merchant names.
- Accounts — account names, account numbers, account types, owners and opening balances.
- Assets — properties (including addresses and purchase details), shareholdings (tickers and quantities), superannuation (fund and member details) and their valuations.
- Categories, income sources, loans, subscriptions and financial-planning settings you configure.
This data enters Kept in the ways described in section 3.
2.3 Email statement/invoice ingestion (optional)
Kept has an optional feature that connects to an email mailbox over IMAP to automatically collect invoice and statement PDFs you receive by email. If — and only if — you choose to configure an email account for this, Kept stores that mailbox's connection details (host, username and mailbox), and the mailbox password is stored encrypted at rest. If you don't set this up, Kept never touches your email.
2.4 Analytics and error data
Where enabled by the operator, Kept uses PostHog to understand product usage and to capture errors so the app can be improved and fixed. This may include page views, feature interactions, error/exception details and session diagnostics. This is product analytics only — it is never sold and is not used for advertising.
3. How your data gets into Kept
Kept does not connect to your bank and does not ask for your bank login. Your financial data reaches Kept only when you provide it, through:
- CSV files you export from your bank and upload;
- PDF bank statements you upload (Kept reads common Australian bank formats); and
- the optional email/IMAP invoice collection described above, if you enable it;
- values you type directly into the app.
4. How we use your data
We use the data above solely to provide and improve the Kept app for you — for example to:
- authenticate you and keep you signed in;
- import, categorise, de-duplicate and display your transactions;
- calculate balances, net position, cashflow, subscriptions, income and asset values;
- fetch public market prices (via Yahoo Finance) for shares you track — only the ticker symbol is sent, never your personal data; and
- diagnose errors and improve the product.
5. How we use Google user data (Limited Use)
Kept's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, the Google user data Kept receives (your email, name, Google ID and profile picture) is used only to authenticate you and provide the app's features. Kept does not:
- use Google user data for advertising;
- sell or transfer Google user data to data brokers, information resellers, or any party for those purposes;
- allow humans to read your Google user data, unless you give explicit consent, it is necessary for security or to comply with the law, or the data is aggregated and anonymised; or
- transfer Google user data to third parties except as needed to provide or improve the app, to comply with the law, or as part of a merger or acquisition.
6. Sharing and disclosure
We do not sell your personal or financial data. We only share data in these limited cases:
- Service providers strictly needed to run the app: Google (sign-in verification), the hosting infrastructure the app runs on, PostHog (analytics/error tracking, where enabled), Yahoo Finance (public share-price lookups by ticker only), and — only if you enable it — your chosen email provider for invoice collection.
- Legal reasons: where we are required to by law, or to protect rights, safety and security.
7. Where your data is stored
Kept is self-hosted. Your financial data is stored in a PostgreSQL database controlled by the operator, hosted on the operator's own infrastructure. The operator is based in Australia. Some service providers named above (for example Google and PostHog) may process limited data outside Australia in the course of providing their service.
8. Data retention and deletion
We keep your data for as long as you use Kept. You are in control of your data:
- You can delete individual transactions, accounts, assets, imports, subscriptions and connected email accounts from within the app.
- Kept includes tools to clear your transaction data in bulk.
- To have your entire account and all associated data permanently deleted, email [email protected]. We will remove your access and delete your data from the database. Backups, where they exist, are cycled out on a rolling basis.
9. Security
We take reasonable steps to protect your data:
- Access to Kept is restricted to an operator-approved allow-list of email addresses.
- Sign-in uses Google's identity tokens; Kept never sees your Google password.
- Sessions are protected by signed, expiring tokens.
- Stored email-mailbox passwords (for the optional invoice feature) are encrypted at rest.
- Traffic to the app is served over HTTPS.
No method of storage or transmission is completely secure, so we cannot guarantee absolute security, but we work to protect your information.
10. Children
Kept is intended for adults. It is not directed at anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
11. Your rights
Consistent with the Australian Privacy Principles, you may request access to the personal information we hold about you, ask us to correct it, or ask us to delete it. Contact us at [email protected].
12. Changes to this policy
We may update this policy from time to time. When we do, we will change the "last updated" date at the top of this page, and for material changes we will take reasonable steps to notify you, such as a notice in the app. Continued use of Kept after a change means you accept the updated policy.
13. Contact
Questions about this policy or your data? Email [email protected].