Keel is built privacy-first. Your financial information lives on your device, not on our servers. We don't track you across apps or services, we don't sell your data, and we don't show ads. We collect a small amount of anonymous usage information to understand whether the app and website are useful—never your financial entries. This policy explains, in plain language, exactly what happens to your data.
The short version: Your financial data stays on your phone. We have no database of your balances, debts, or income. The app sends only what is needed for an AI Coach request, subscription verification, optional anonymous usage events, or feedback you choose to submit. The website measures anonymous traffic, performance, calculator completion, and store-button clicks. It never receives the values you type into the calculator.
Who we are
Keel is operated by Ng Qi Heng, an individual developer based in Malaysia ("we", "us", "Keel"). If you have any questions about this policy or your data, contact us at hello@get-keel.app.
What we collect — and what we don't
We want to be precise here, because most apps aren't.
We do NOT collect:
- No advertising identifiers, and no ads.
- No cross-app or cross-site tracking. We never share your data with data brokers, advertisers, or other companies for marketing.
- No name, email, phone number, or account registration (Keel has no user accounts).
- No precise location data. Website reporting may show country-level traffic in aggregate.
- No bank logins, bank connections, or access to your real financial accounts.
- No financial information in our usage analytics — no balances, amounts, interest rates, card or account names, scores, or dates. See "Anonymous usage events" below.
What stays on your device:
- Everything you enter into Keel — your assets, subscriptions, installment/BNPL plans, credit card balances, income, expenses, and any optional name you set for the greeting — is stored locally on your device only. We do not have a copy. We do not have a server database of your financial data.
- If you delete the app, this data is removed from your device.
Anonymous usage events
To understand how Keel is actually used — and to find where it confuses people — the app records a small set of anonymous events. We built this ourselves rather than using a third-party analytics service, so this information never reaches any outside company.
What an event records: that a screen was opened, that a locked feature was tapped, or the outcome of a purchase attempt. Each event is a fixed label from a short, predefined list — for example, "the paywall was shown, from the Coach tab".
What an event can never contain: any financial information whatsoever. No balances, no payment amounts, no interest rates, no card, account, or subscription names, no health scores, no debt-free dates, and no free-form text. This is enforced on our server, which rejects any event carrying a value that looks like money or free text.
How it's identified: events are grouped using the same randomly generated installation identifier described under Subscriptions. It contains no personal information and is not linked to a name, email, or account, because we don't have those. Before an event is stored, this identifier is cryptographically hashed, so our records hold a one-way fingerprint rather than the identifier itself.
Where it goes and for how long: events are sent to our own server on Cloudflare and stored in our database for 90 days, after which they are automatically deleted. They are never sold, shared, or combined with data from any other source.
Turning it off: open Settings → Help improve Keel and switch it off. Events stop being created immediately, anything queued on your device is deleted, and nothing further is sent. The setting is on by default.
Website analytics
We use Cloudflare Web Analytics to understand which pages are visited, where traffic broadly comes from, and how quickly the website loads. Cloudflare states that this service does not use cookies, fingerprint visitors, or collect personal data. Its dashboard can show aggregate dimensions such as page path, referral domain, country, device type, browser, and Core Web Vitals. Website analytics can be viewed for up to six months.
For a small set of meaningful actions, the website also sends an anonymous event to a first-party endpoint hosted on Cloudflare. The allowlisted events are calculator started, calculator completed, and App Store or Google Play button clicked. An event may include the page path, store platform, country-page label, referral domain, and campaign tags from the URL. It never includes calculator inputs, balances, interest rates, names, messages, IP addresses, a user or session identifier, or a full referring URL. These action events are kept for 90 days in Cloudflare Analytics Engine.
The AI Coach
Keel includes an optional AI Coach. When you send it a message, here's exactly what happens:
- Keel builds a sanitised snapshot of your financial picture. This snapshot is deliberately stripped of identifying details: it contains no name, no bank or institution names, and no account numbers. Credit cards are described only by their interest rate (for example, "18% card"), never by their issuer.
- Any optional name you set for the in-app greeting is never included in this snapshot — it stays on your device and is never sent to the AI.
- This snapshot, along with your message, is sent over an encrypted connection to our proxy server (hosted on Cloudflare), which forwards it to our AI provider, Google (Gemini API), and streams the reply back to you.
- We do not store your Coach conversations. Our proxy passes your snapshot and message through to the AI provider and discards them. They are not written to any database and not kept in our logs. The server does verify that your subscription is active — see below — and briefly caches that yes/no answer, but never your financial snapshot or messages.
- To confirm that Coach access is included in your subscription, our server checks your subscription status with RevenueCat using your installation identifier, and remembers that yes/no answer for a few minutes so it doesn't have to ask on every message.
About the AI provider (Google): We use Google's Gemini API on a paid tier. Under Google's paid-tier terms, Google does not use your prompts or the AI's responses to train or improve its products, and acts as a data processor. Google may log requests transiently for a limited period solely to detect abuse and maintain the safety and security of the service. You can read Google's terms at ai.google.dev/gemini-api/terms.
If you never use the AI Coach, none of your information is ever sent off your device for this purpose.
Subscriptions
Keel offers an optional premium subscription. Purchases are processed through the Apple App Store or Google Play, depending on your device, and subscription status is managed by RevenueCat, a subscription-management service. To do this:
- A randomly generated identifier is created on your device and used to recognise your subscription. This identifier is not linked to your name, email, or any personal information — because we don't collect those.
- RevenueCat, Apple, and Google Play process your purchase to confirm and maintain your subscription. Their handling of payment information is governed by their own privacy policies: RevenueCat, Apple, and Google Play.
Notifications
If you choose to enable reminders (for payday or card payment due dates), these are scheduled locally on your device. No notification data is sent to or processed by any server. This includes the reminder before a free trial ends, if you choose to enable it. Like all Keel reminders, it is scheduled on your device — no notification data is sent to any server. You can turn them off anytime in Settings, and they require your permission to begin with.
Feedback you send us
If you use the in-app feedback form, the message you write is sent to our server and forwarded to us by email so we can read and act on it. Please don't include sensitive personal or financial details in it — it's a free-text message and whatever you type is what we receive. Feedback is stored so we can keep track of what's been raised, and it isn't used for anything else.
Third parties we rely on
To be fully transparent, the only external services involved in running Keel are:
- Google (Gemini API) — processes the sanitised snapshot when you use the AI Coach (paid tier; does not train on your data).
- Cloudflare — hosts this website, our AI Coach proxy, anonymous app and website event infrastructure, feedback storage, and privacy-focused website traffic and performance analytics. As an infrastructure provider, Cloudflare may process network requests at the edge per its own policies.
- RevenueCat, Apple, and Google Play — process subscriptions if you choose to subscribe.
We use no advertising analytics, advertising SDKs, cross-site trackers, session recordings, or behavioural profiles. Website and app measurements stay within the Cloudflare infrastructure already used to operate Keel.
Your control over your data
- Because your data lives on your device, you are in control of it. You can edit or delete any entry at any time.
- You can export your data from within the app.
- Deleting the app removes your local data from your device.
- You can disable the AI Coach and notifications at any time.
- You can turn off anonymous usage events at any time in Settings → Help improve Keel.
Children
Keel is not directed at children under 18 and we do not knowingly collect data from them.
Changes to this policy
If we update this policy, we'll change the date at the top and, where appropriate, note it in the app. Continued use after changes means you accept the updated policy.
Contact
Questions about your privacy? Email hello@get-keel.app and we'll respond.
Keel — operated by Ng Qi Heng, Malaysia. This policy is provided for transparency and does not constitute legal advice.