Privacy
Last updated 3 September 2026
Kept saves your bookmarks, organizes them with AI, and helps you find them again. Doing that means holding your library and knowing a little about how you use it. This page says exactly what that means — all of it, in plain language, including the parts that are less comfortable to write down.
What is live right now
This page describes Kept as a finished product, so that it does not quietly grow more invasive as features arrive. Some of it is not switched on yet. As of the date above:
- Your library is stored only in your browser. Syncing across devices is not live yet, so Kept's servers do not hold your bookmarks today.
- Semantic search, the opens log and the weekly digest are not live yet.
- There are no paid plans yet, so no payment details exist anywhere.
Each line disappears from this box when that part ships. Nothing else on the page changes.
What Kept stores
This is the complete list.
- Your account. Your email address, an account identifier, and the dates your account and trial began.
- Your library. The bookmarks you save — addresses, titles, descriptions, tags and folders — so they reach every device you sign in on. A copy also lives in your browser, which is what makes Kept fast and lets it work offline.
- Search data derived from your library. Each bookmark gets a numeric fingerprint of its meaning, which is what lets you search by describing something rather than by remembering its exact words.
- Which bookmarks you open, and when. Kept keeps a log of opens. It is how Kept resurfaces things you saved and forgot, and what the weekly email is built from. See below — this is the one worth reading twice.
- Your usage counts. How many AI saves and searches you have used this month, which is what your plan limits are checked against.
- A record of each AI request. When it happened, which model ran, and how much text went in and out, measured in tokens. This records the size of a request and never its contents.
- Your subscription status, once paid plans exist. Whether you are subscribed and until when — never your card number, which only Stripe ever sees.
The opens log, plainly
When you open a bookmark from Kept, Kept records that you opened it and when. Over time that is a record of what you return to and what you never look at again.
It is worth being direct about this, because it is the most personal thing on the list and it would be easy to bury. It exists because a bookmark manager that only stores things is a filing cabinet you stop opening. The log is what lets Kept say “you saved this six months ago and it is relevant again”.
It records opens from inside Kept. It is not a record of your browsing, and Kept has no way to see pages you visit without saving.
What happens when you save a page
You ask Kept to save a page. Its text and basic details go to Kept's server, which passes them to OpenRouter, which routes them to the AI model that writes the title, description, tags and folder — currently Anthropic's Claude. The result is saved to your library.
Kept does not keep the page's full text. What it keeps is the tidy summary that comes back — the title, description, tags and folder — not a copy of the page itself. OpenRouter and the model provider handle what passes through them under their own policies.
Two things here can send an extra request beyond the save itself, and they do not behave the same way.
Preview image. Pages inside logged-in apps — a dashboard, an inbox — publish no preview image, because they are not meant to be shared. So when a saved page has no image of its own, Kept asks that site's own home page for its brand image: saving a page on dash.example.com means Kept fetches example.com. It sends the bare domain and nothing else — never the address of the page you saved, and never to anyone but that site.
The page's own icon — a weaker guarantee. A saved page names its icon in its own HTML — and that address is not always on the site you saved from. Plenty of sites serve their icon from a CDN instead. Kept requests that exact address, in full: the whole address, including any path or query, not just a domain. That means the host receiving it can be a third party with no relationship to the site you saved. It is a single check for whether an image exists there, not a fetch of the page itself. Like every address Kept requests, it is checked first against the rule that blocks private and internal addresses. When there is no usable icon this way, Kept falls back to a Google-supplied one instead (below).
This happens for pages you save and for bookmarks you import. It does not happen as you browse.
Kept sends you the things an account needs — confirmations, receipts, notice when something changes here. It also sends a weekly digest of what is worth revisiting, built from your opens log. You can turn the digest off without affecting your account, and every marketing or lifecycle email has an unsubscribe link that works.
Connecting an AI assistant
Kept can let an AI assistant you use search your library on your behalf. This is optional and off until you connect it. When you do, that assistant can read your bookmarks — which is the point of connecting it — and Kept has no control over what the assistant does with what it reads. Access is read-only: nothing connected this way can change or delete anything.
The companies involved
Kept is run by one person and rents the infrastructure it needs rather than building it. These are the services that touch any part of your data:
| Service | What it does |
|---|---|
| Clerk | Signs you in and holds your login details |
| Supabase | The database holding your library and everything above |
| Vercel | Runs the website and keeps standard server logs |
| OpenRouter | Passes AI requests to the model that answers them |
| Stripe | Takes payment. Kept never sees your card number |
| Resend | Delivers the emails described above |
| PostHog | Counts visits and sign-ups on this website, and records what you do inside the extension itself — installing it, an AI save succeeding, hitting the AI save limit — never the address, title or content of any page. Before you sign in, those extension events are tied to an identifier created once for your install, which stays the same until you remove the extension; once you sign in, they are folded into your account |
| Internet Archive | If a public page is temporarily down when Kept tries to read it, Kept asks the Internet Archive whether it holds an older copy, which means sending that page's address. Kept never does this for a page behind a login, for a private or internal address, or for anything it could read normally |
| If you choose to sign in with Google. Also supplies a site's icon when Kept cannot get a usable one straight from the site itself — your browser fetches that icon, so Google sees the site's domain name and your IP address, but never the full address of the page you saved | |
| The saved page's own icon host | A saved page names its icon in its own HTML, and Kept requests that exact address — the whole address, including any path or query, not just a domain. That host is not always the site you saved from; a CDN is the ordinary case, and it can be a third party with no relationship to that site. This is a single check for whether an image exists there, never a fetch of the page itself |
Kept's servers and database are in the United States. If you are in the UK or the EU, using Kept means your data is handled there.
What the extension asks permission for
Chrome shows these when you install Kept. Here is what each is actually for:
| Permission | Why Kept needs it |
|---|---|
| Storage | Keeps your library and settings inside your browser |
| Favicons | Shows site icons next to bookmarks, from Chrome's own cache — no network request |
| Cookies | Reads the sign-in cookie from Kept's sign-in service, at clerk.keptbookmarks.com — a separate address from the site itself, which is where your session actually lives — so signing in on the website carries over to the extension |
| Access to websites | Reads a page's content when you save it, or when you open the pin bar on it. Needed for importing bookmarks you already had, where there is no tab open to read from |
“Access to websites” is the alarming-sounding one, so to be plain: Kept reads a page when you save it, when you open the Kept pin bar on it, and when you import bookmarks you already had. Opening the pin bar reads the page you are on so that a summary is ready the moment you ask for one — that text stays on your own machine and is sent nowhere unless you press “Summarize with AI”. Kept does not watch your browsing.
What Kept never does
- Sell, rent or share your data with anyone for their own purposes
- Run advertising, ad networks or tracking pixels
- Read pages in the background, or any page you have not opened Kept on
- Use your library to train AI models
- Lock your data in — export is always available, on every plan, free ones included
Getting your data out, and deleting it
You can export your whole library at any time, on any plan, without asking. That is deliberate: if Kept ever stops being worth paying for, you should be able to leave with everything.
Deleting your account deletes your library, your search data, your opens log, your usage counts and your customer record at Stripe. Not hidden, not deactivated — removed. A bookmark you delete on its own is held briefly so an accidental deletion can be undone, then purged within 30 days.
Email privacy@keptbookmarks.com and it will be done. If you are in the UK or the EU, you have the right to ask for a copy of what is held about you, to have it corrected, or to have it erased — same address, and there is no process to go through. It is one person reading the email.
Children
Kept is not aimed at children under 13 and accounts are not knowingly created for them.
Changes to this page
When what Kept does with your data changes, this page changes first and the date at the top changes with it. Anything that meaningfully affects you gets an email too — not a silent edit.