Privacy Policy
Last updated: August 8, 2026
1. Overview
AutoKept ("we", "us") respects your privacy. This policy describes what we collect, why we collect it, how we handle data from connected services, and your choices when you use getautokept.com and app.getautokept.com (the "Service").
2. Information we collect
Account information: email and profile data from Clerk when you sign up. Connected service data: OAuth tokens, and the account data you authorize us to access, for integrations you connect (Google, INDmoney, messaging platforms, etc.), stored encrypted. Usage data: messages, tool activity, and token usage to run the assistant and enforce plan limits. Device & log data: IP address, browser type, and diagnostic logs for security and reliability. Mobile app diagnostics: if you use the AutoKept mobile app, crash reports, screen-usage events and API response times, described in full in section 11.
3. How we use information
We use your information to: provide and operate the Service; authenticate you; execute actions you request via connected tools; send briefings and notifications you enable; improve reliability and security; and comply with legal obligations. We use your data only to provide and improve features that are visible to you in AutoKept, and only in the ways this policy discloses.
4. Google user data and Limited Use
AutoKept's access to, and use and transfer of, information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data obtained through AutoKept is: (a) used only to provide and improve user-facing features that are prominent in the AutoKept interface (for example, reading and summarizing your email for briefings, drafting and sending messages you request, and managing your calendar), and only with your consent; (b) never sold, and never transferred to third parties except as needed to provide or improve these user-facing features, for security purposes, to comply with applicable law, or as part of a merger or acquisition with your explicit prior consent; (c) never used for advertising, including retargeting, personalized, or interest-based advertising, and never used to determine credit-worthiness or for lending purposes; and (d) never used to develop, improve, or train generalized or non-personalized AI/ML models — when AI models process your Google user data, it is solely to generate a response or perform an action you have requested. Human access: we do not allow humans to read your Google user data unless (a) you give explicit consent to view specific messages or data, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations. Access is otherwise limited to automated processing.
5. AI processing
To operate the assistant, your messages and relevant connected data may be sent to AI model providers to generate responses and perform the actions you request. We configure these providers to process your data for inference only. Your personal content, including Google user data, is not used by us or our providers to train generalized or public AI/ML models.
6. Third-party services
We rely on third parties including Clerk (authentication), cloud hosting, database providers, Google APIs, messaging platforms, AI providers, and — for the mobile app only — Sentry (crash reporting and performance monitoring) and Mixpanel (product analytics). Each receives only the data needed to provide their function, and their handling of that data is governed by their own policies in addition to this one. Sentry and Mixpanel never receive your financial data; see section 11.
7. Storage & security
OAuth credentials and connected-service data are encrypted at rest, and access is scoped per user account. We use industry-standard safeguards, but no system is 100% secure. You are responsible for keeping your sign-in credentials safe.
8. Retention & deletion
We retain data while your account is active and as needed to provide the Service. You may disconnect any integration at any time from Settings, which revokes our access and stops further processing for that integration. You may request full account deletion by contacting reach@getautokept.com; we will delete or anonymize your data, including stored Google user data and OAuth tokens, when it is no longer required, subject to legal retention needs.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Contact us at reach@getautokept.com to exercise these rights.
10. Cookies & analytics
We use essential cookies and similar technologies for authentication and session management (including Clerk). We may use analytics to understand product usage; where applicable, you can control non-essential cookies through your browser.
11. Mobile app diagnostics and analytics
The AutoKept mobile app reports crashes and basic usage so we can find what is broken and see which parts of the app people use. We use Sentry for crash reporting and performance monitoring, and Mixpanel for product analytics.
What is sent: crash and error reports (the error, its stack trace, your device model, OS version and app version); the names of screens you open; a short list of named actions — logging an expense, opening a person's ledger, opening the across-months view, switching between the People and Analysis views, loading an earlier window, and completing sign-in; API response times, together with the route path, HTTP method and status code; and your AutoKept account identifier, so that reports from the same account can be grouped.
What is never sent: your transaction amounts, merchant names, the names of people you send money to or receive it from, your note text, your search terms, your category totals, and the contents of any API request or response. Query strings are removed from every route path before it leaves your device, and console output is not collected. These limits are enforced in the app's code, not only by policy: the set of events the app is able to send is fixed at build time, and an event carrying anything else will not compile.
This reporting cannot currently be switched off from within the app. We are telling you that plainly rather than leaving it to be discovered: it is the reason the limits above are enforced in code rather than left to policy, and the reason we keep what is collected as narrow as it is. If you would prefer that your device not report at all, contact us at reach@getautokept.com and we will tell you where this stands.
12. Children
The Service is not intended for users under 18. We do not knowingly collect data from children.
13. International transfers
Your data may be processed in countries other than your own, including where our infrastructure and subprocessors operate. This includes Sentry and Mixpanel, which process mobile app diagnostics on infrastructure located in the United States. We take steps to protect data in line with this policy.
14. Changes
We may update this Privacy Policy. We will revise the "Last updated" date when we do, and material changes may be communicated through the Service or by email where appropriate.
15. Contact
Privacy questions and data requests: reach@getautokept.com