Kept — Privacy Policy

The money you didn't know you were losing.

Last updated: 31 August 2026

The short version. Kept reads the transaction alert SMS your bank sends you, in order to find recurring charges on your account. Those messages are read and stored only on your phone. They are never uploaded, sold, or shared.

1. What Kept accesses, and why

Kept requests the Android READ_SMS and RECEIVE_SMS permissions. It uses them for exactly one purpose: to find the recurring debits charging your bank account — UPI Autopay mandates, NACH/ECS standing instructions and card renewals — so it can show you what each costs and where to cancel it.

In India, banks and UPI apps send transaction alerts by SMS. Those alerts are the only complete record on your phone of what is being automatically debited. There is no public API that lets an app list your UPI mandates, which is why this permission is necessary rather than convenient.

Kept does not send SMS. It does not request access to your call log, contacts, location, camera, microphone or files.

2. What stays on your device

Message content is parsed on your device and the results are stored in a local database on your device. Before anything is written to storage, Kept removes account numbers, transaction reference numbers and long digit sequences.

Your SMS messages are never transmitted off your device — not to Kept, not to any third party, not in whole and not in part.

3. What leaves your device

Kept has one optional feature that uses the network: AI enrichment, which identifies merchants the app's built-in list doesn't recognise and finds their cancellation pages. You can turn it off in Settings, and Kept remains fully functional without it.

When it is on, and only for merchants not already recognised, Kept sends:

SentNot sent
The merchant text your bank printed
The charge amount
How often it repeats
The payment rail (UPI Autopay, NACH, card)
How many times it has occurred
The SMS message itself
Your account number or its last digits
Transaction reference numbers
Your name, phone number or email
Your contacts, location or device identifiers

This request goes to Kept's own server function, which forwards it to Anthropic's Claude API for identification and returns the result. The data is used to answer that one request and is not stored afterwards.

4. Accounts and identifiers

Kept has no login wall. Finding your recurring charges, naming them from the built-in catalog and opening the screen where each one is cancelled all work with no account, and none of it leaves your device.

An account is needed for one thing only: the optional AI enrichment described above. The server has a fixed budget and no paid tier, so it needs to know who is asking in order to stop one person exhausting it. You create the account from the AI card in Settings — with an email address and password, or by signing in with Google — and never at startup.

If you create one, Kept holds your email address and a user identifier, and the server keeps a count of how many items you have enriched. It does not store what those items were. Your email is not used for marketing, is never sold, and is not shared with anyone beyond the Google Firebase services that authenticate it. There is no advertising identifier and no analytics.

Signing out stops the app using the account. To have the account deleted — the email address and the usage count both — write to kept.privacy@gmail.com and it will be removed. Uninstalling removes everything stored on the device.

5. What Kept never does

Kept contains no advertising SDK and no third-party analytics SDK.

6. Retention and deletion

Everything Kept derives from your messages lives in a local database that is not backed up to the cloud. Uninstalling the app deletes it permanently. You can also clear it at any time from Android Settings → Apps → Kept → Storage → Clear data.

7. Children

Kept is not directed at children and is not intended for anyone under 13.

8. Changes

If this policy changes in a way that affects what data is collected or where it goes, the updated policy will be published here with a new date before the change ships.

9. Contact

Questions about this policy or about your data: kept.privacy@gmail.com