Keystone logo Keystone Privacy Policy

Privacy Policy

Last updated: March 12, 2026

Your personal data belongs to you. This policy explains, in plain language, what information Keystone collects, why we collect it, how long we keep it, and the choices you have. It covers everything you do inside the Keystone website and Android app (com.hoota.keystone).

Keystone is operated by AMH Digital (“Keystone,” “we,” “us,” or “our”). We are responsible for deciding how your personal information is used, unless we are acting on behalf of another organisation that invited you to use Keystone. This policy is in addition to any other agreements you may have with us.

1. What This Policy Covers

This policy applies to any personal information we collect when you use Keystone — including through our website, mobile app, in-app purchases, emails, push notifications, customer support, and any future platforms or services we may offer. We build Keystone with privacy in mind from the start and follow applicable privacy laws worldwide, including (where relevant) the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and any similar legislation in your region.

2. What We Collect

Here is exactly what information we may collect and why:

  • Account information: Your email address, display name, login credentials (including any PIN you create), your subscription type, and whether your account is verified, guest, or premium. We need this to create and manage your account.
  • Your content (encrypted): All content you create within the app — including entries, lists, datasheets (schemas and row data), attachments, progress data, Circle entries (names, phone numbers, emails, and birthdays of people you add), subscription costs and billing details you enter, and any associated metadata — is encrypted on your device before it ever leaves it. What we store on our servers is scrambled data that we cannot read. Only you, with your PIN, can unlock it.
  • Technical information: Things like sync timestamps, anonymous identifiers, your subscription status, and basic technical details needed to deliver notifications and keep your encrypted data in sync across your devices.
  • Device information: Your app version, operating system, language preference, notification settings, and crash reports. This helps us fix bugs and improve the app. We do not collect your GPS location.
  • Advertising information: If you see ads in the app, we may collect your device advertising ID, approximate (city-level) location based on your IP address, your ad consent choices, and basic information about which ads you saw or tapped. This is used by Google AdMob to show and measure ads. We also record whether banner ads are active on your device (ad attestation) to enforce our fair-use policies for free accounts.
  • Handle & social data: If you claim a user handle (@username), we store your chosen handle, the date you claimed it, and your eligibility status. Handles are stored in plaintext (not encrypted) because they are designed to be visible to other users for social features such as challenges and direct sharing. If you participate in challenges, we store your participation records, challenge scores, and leaderboard rankings. This data is visible to other participants.
  • Widget data (local only): If you use home-screen widgets, summary data (task titles, habit names, streak counts, scores) is stored locally in your device’s SharedPreferences. This data never leaves your device and is refreshed periodically from the main app.
  • Wear OS data (local only): If you use the Wear OS companion app, minimal data (today’s tasks, habits, scores) is synced between your phone and watch via the Data Layer API. Authentication tokens are stored securely on the watch. Watch data is cached locally and refreshed from the phone app.
  • Usage counters: We track the number of sync operations your account performs each day (a daily sync budget). This counter is used solely to enforce fair-use rate limits and is automatically reset every 24 hours. We do not log the content of your sync operations.
  • Purchase information: When you buy a subscription, we receive a confirmation from Google Play (or another app store) that your purchase went through, along with basic details like your country and plan type. We never see your credit card number or bank details — the app store handles all of that.
  • Subscription tracking data (encrypted): Keystone lets you manually track your own subscriptions and spending. Any costs, billing cycles, or notes you enter are part of your encrypted content (see above). Keystone does not connect to banks, payment providers, or any financial API — all subscription information is entered by you and encrypted on your device.
  • Support messages: Anything you send us through the in-app feedback form, at [email protected], or through other support channels, including any files you attach. When you use the in-app feedback form, we automatically attach technical context to help us understand and resolve your issue — this includes your app version, device model, operating system version, platform, screen dimensions, and a device identifier. This information is sent alongside your message and is used solely for support purposes.
  • Marketing preferences: Whether you have opted in or out of promotional emails, and basic engagement data (like whether you opened an email).

What we don’t do: We never read the contents of your encrypted data — it is encrypted and we do not have the key. We do not collect information from children under 13 (or the minimum age in your country). We do not buy personal data from third parties.

3. Why We Use Your Information

We only use your information for clear, specific reasons:

  • To run the app: Sign you in, sync your encrypted data, send you reminders and notifications, maintain backups, manage your handle and challenge participation, calculate leaderboard rankings, and provide customer support.
  • To improve and protect Keystone: Fix bugs, understand which features are popular, prevent misuse, enforce fair-use limits (such as daily sync budgets and ad attestation checks), and make the app more accessible.
  • To show ads (free accounts): Display ads through Google AdMob based on your consent preferences. If you have not given consent for personalised ads, you will only see general ads.
  • To send you important messages: Things like purchase receipts, password resets, security alerts, and notices about changes to the service. These are not marketing — they are essential.
  • To send marketing (only if you opt in): Product updates or tips. You can unsubscribe at any time.
  • To meet legal requirements: Keep limited records when required by law (for example, for tax or dispute resolution).

We never sell your personal information. We do not rent mailing lists. We do not use your private content to train AI or machine learning models. Your encrypted data stays encrypted — we literally cannot read it.

4. Third-Party Services & Advertising

We work with a small number of trusted partners to keep Keystone running. These include:

  • Firebase — for sign-in, push notifications, and crash reporting.
  • Google Play — for in-app purchases and subscriptions.
  • Cloudflare — for website delivery, security, AI processing (see Section 5), and Data Layer sync infrastructure for Wear OS.
  • Google AdMob — for showing and measuring ads.
  • Email delivery services — for sending transactional and (where opted in) marketing emails.

Each partner has a contract with us that limits what they can do with your data. They may only use it to provide their specific service to Keystone, and must protect it with appropriate security measures. This list may change over time as we adopt new tools; we will update this policy accordingly.

About Ads

If you use Keystone for free, you may see ads powered by Google AdMob. Depending on where you live, we will ask whether you want personalised ads (based on your interests) or prefer general ads (based only on broad signals like your approximate location or the type of content). You can change this choice at any time in Keystone’s settings, through our consent dialog, or through your device’s ad settings (e.g., Android > Privacy > Ads). You can also manage Google’s ad personalisation at Google’s My Ad Center.

We never share your encrypted content with any advertising partner. Ad partners may use device identifiers or approximate location together with their own data to serve and measure ads, subject to their own privacy policies and applicable law.

5. AI Features & Privacy

Premium members can use a built-in AI assistant to create lists, generate tasks, design missions, write diary entries with mood tracking, and reorganise existing items. The AI also supports conversation history and personalised memory. Here is how we protect your privacy when you use AI features:

  • Processing: When you send a message to the AI assistant, your prompt is sent to Cloudflare Workers AI for processing. Cloudflare does not retain or log your inputs and outputs, and does not use your data to train or improve AI models.
  • Conversation history: Your AI conversations (messages you send and responses you receive) are stored in your account so you can return to previous chats, search across them, and pick up where you left off. Conversations are stored in a dedicated database, isolated to your user account, and are fully deletable at any time.
  • AI memory: The AI assistant can remember preferences, facts, and instructions you share across conversations (for example, “I’m vegetarian” or “I prefer morning workouts”). These memory entries are stored in your account and can be viewed, edited, or deleted individually from the AI settings screen. Memory is never shared with other users or used outside your own AI sessions.
  • Mood & diary data: If you use the AI diary feature, the AI may infer a mood score from your conversation. This metadata is stored on the resulting diary note in your account. You can delete any diary entry and its mood data at any time.
  • No training on your data: Cloudflare Workers AI does not retain inputs or outputs and does not use your data for model training. We do not use your conversations, memory, or diary entries to train, fine-tune, or improve any AI model.
  • User isolation: All AI data (conversations, memory, usage counters) is strictly isolated to your user account. No user can access another user’s AI data. Every database query includes your user ID as a mandatory filter.
  • Deletion: You can delete individual conversations, clear all AI memory, or delete your entire account. When you delete AI data, it is permanently removed from our servers.
  • Rate limiting: We track AI usage counters (number of sessions per day/hour) to enforce fair-use limits. These counters contain no conversation content and are automatically cleaned up.
  • Circle & subscription context: When you use the AI assistant, it may read your Circle entries and subscription data to answer questions (for example, “When is John’s birthday?” or “How much am I spending on subscriptions?”). This data is processed only within your session — the AI does not store or transmit your Circle contact details or financial information externally.

In short: your AI conversations are stored privately in your account for your convenience, never used to train models, and fully deletable. We never sell, share, or use your prompts or AI-generated content for any purpose other than delivering the feature to you.

6. Purchases & Payments

You can buy a Premium subscription through Google Play (or any other authorised app store). The store processes your payment directly — we never see your card number or bank details. The store sends us a confirmation so we can activate your purchase, along with basic billing details (like your country and plan) for tax purposes. For refunds, please follow the store’s own refund policy.

7. How Long We Keep Your Data

We keep your data only as long as we need it:

  • Active accounts: We keep your data for as long as your account is active.
  • Guest or unverified accounts: Automatically deleted after 3 months of inactivity.
  • Verified (Standard) accounts: Automatically deleted after 12 months of inactivity.
  • Premium accounts: Kept for the duration of your subscription. If your subscription ends, the timelines above apply based on your account type.
  • Challenge data: Challenge participation records and scores are retained for leaderboard history for the duration of your account. When you leave a challenge, your scores remain visible to other participants. When you delete your account, all challenge data is removed.
  • Deleting your account: You can delete your account at any time from the app’s account settings or by emailing [email protected]. This is permanent and cannot be undone. All personal data, including cloud backups, will be erased within 30 days, except for minimal records we are legally required to keep (e.g., for tax purposes).
  • Encrypted backups: Removed within 30 days of the related account or data being deleted.

8. Your Rights & Choices

You are in control of your data. Here is what you can do:

  • Edit or delete your content directly inside the app at any time.
  • Change or remove your handle from your profile settings. Handle changes are limited to once every 30 days.
  • Withdraw from challenges at any time by leaving the challenge. Your historical scores remain on the leaderboard unless you delete your account.
  • Delete datasheet data by deleting individual rows, entire datasheets, or your account.
  • Manage your notifications and marketing preferences in settings or by using the unsubscribe link in any email.
  • Disconnect Google sign-in from your Google Account dashboard if you no longer want Keystone to use your Google identity.
  • Delete your account from settings or by emailing us.
  • Request access to, correction of, or a copy of your data by emailing [email protected]. Note: because your content is end-to-end encrypted, we can only provide the unencrypted data that we hold (like your email and account details), not any of your encrypted app content.
  • Object to or restrict certain uses of your data where applicable law gives you that right.

Regional rights: If you are in the EU/EEA, UK, or Switzerland, you have the right to file a complaint with your local data protection authority. If you are in California (or another US state with similar privacy legislation), you may use an authorised agent to submit requests on your behalf and you have the right not to be discriminated against for exercising your privacy rights. If you are in Brazil, you have rights under the LGPD. Regardless of where you live, we will do our best to honour reasonable privacy requests in line with applicable law.

9. Where Your Data Is Stored

Your data may be processed and stored in the United States, the European Union, or other countries where our partners operate. When your data moves across borders, we make sure it is protected by appropriate legal safeguards (such as Standard Contractual Clauses or equivalent mechanisms recognised by applicable law). Your most sensitive content — everything you create in the app — is always encrypted end-to-end, so even if intercepted in transit it would be unreadable without your PIN.

10. How We Protect Your Data

  • Encryption in transit: All data sent between your device and our servers is protected with TLS (the same technology used by banks).
  • Encryption at rest: Data stored on our servers is encrypted using keys kept separate from the servers themselves.
  • End-to-end encryption: All app content, shared lists, and cloud backups are encrypted with a PIN that only you know. We cannot decrypt this data.
  • Monitoring: We monitor sign-in events, password resets, and unusual activity to detect potential security issues.
  • Internal safeguards: We maintain access controls, security training, and an incident response plan to protect your information.

11. Children’s Privacy

Keystone is not designed for children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If we discover that a child has created an account, we will delete it and all associated data promptly.

12. Changes to This Policy

We may update this policy from time to time — for example, when we add new features, change how we work with partners, or when laws change. If we make significant changes, we will let you know through a notice in the app and, where possible, by email, before the changes take effect. The “Last updated” date at the top always reflects the latest version. By continuing to use Keystone after an update, you agree to the revised policy.

13. Contact Us

If you have any questions, want to exercise your privacy rights, or need to report a security concern, please email us at [email protected]. We will acknowledge your message within three business days and aim to resolve any verified privacy request within 30 days (or sooner where the law requires it).