Effective date: August 6, 2026
This Privacy Policy explains how Keeps collects, uses, stores, shares, and protects information when you use the Keeps mobile application ("Keeps," the "App," or the "Service").
Keeps is a creative photo journal for capturing stamp-framed photos and cutout stickers, organizing them into collections, calendar views, and scrapbook projects, sharing public stamps with friends, chatting, receiving optional notifications, and using customizable home screen widgets.
Legal review note: This document is a detailed product-specific draft based on the current Keeps app behavior. It is not legal advice. Before publishing, Nosiah Studio should have it reviewed for the jurisdictions where the App will be offered and should keep App Store privacy labels and Google Play Data Safety answers consistent with it.
1. Who We Are
Keeps is provided by:
- Legal name: Nosiah Studio
- Contact email: nosiahstudio@gmail.com
- Address: Hanoi, Vietnam
References to "we," "us," and "our" mean Nosiah Studio. References to "you" and "your" mean the person using Keeps.
2. Summary
Keeps collects and uses information to provide a cloud-based photo stamp, collection, social, chat, widget, and subscription experience.
In practical terms:
- You sign in with Apple, Google, or an available email-and-password option through Supabase authentication.
- Your stamp photos are uploaded to Supabase Storage.
- Your profile, captions, collections, projects, friend relationships, chat messages, reactions, and subscription status are stored in Supabase.
- Purchases are processed by Apple App Store or Google Play and validated through RevenueCat.
- Camera access is used to capture stamp photos.
- Photo library or storage access may be used when you choose to select, save, export, or share images.
- Firebase Analytics and Firebase Crashlytics process limited app usage, device, and diagnostic information to help us understand feature usage and improve reliability.
- Firebase Cloud Messaging and Apple or Google notification services process registration identifiers and limited device or app information to deliver optional chat, friendship, and system notifications.
- Firebase Analytics may process approximate region-level location inferred from information such as an IP address. Keeps does not request precise device location.
- Keeps does not sell personal and sensitive user data.
- Keeps does not display ads. Advertising-ID collection is disabled on Android, ad-personalization signals are disabled by default, and Keeps does not intentionally send photo content, captions, messages, email addresses, authentication tokens, or payment details to Firebase Analytics or Crashlytics.
3. Information We Collect
3.1 Account and Authentication Information
When you sign in, Keeps may receive or process account information from Apple, Google, an email-and-password sign-in option, or Supabase authentication, including:
- Supabase user ID.
- Email address.
- Display name.
- Profile image or avatar URL provided by the sign-in provider.
- Authentication provider information.
- Authentication session information needed to keep you signed in.
- Account creation and sign-in timestamps maintained by authentication providers.
Apple or Google may process additional information according to their own privacy policies when you use their sign-in services.
3.2 Profile Information
You may create or update profile information, including:
- Display name.
- Username.
- Bio.
- Avatar image.
- Avatar URL.
- Public stamp counts and profile-related display data.
Profile avatars are stored in Supabase Storage in the profile-avatars bucket. The current storage policy allows profile avatar files to be publicly readable so avatars can be shown in profile, friend, feed, and chat features.
3.3 Stamp Photos and Stamp Metadata
When you capture, save, edit, view, or delete a stamp, Keeps may collect and store:
- The stamp-framed photo.
- Caption.
- Public or private visibility setting.
- Capture date and time.
- Created and updated timestamps.
- Stamp ID.
- Cloud storage path.
- Image URLs or signed URLs used to display the stamp.
- Technical image-processing data needed to create the final stamp frame.
- Cutout sticker images and processing state when you use Sticker Camera.
Stamp photos are stored in Supabase Storage in the stamps bucket. Private stamp files are intended to be accessible only to your account. Public stamp files may be visible to other authenticated users or to friends through social features depending on App behavior and database access rules.
3.4 Camera and On-Device Photo Processing
Keeps uses your device camera to capture photos when you choose to take a stamp photo.
The App may process captured photos on your device to crop, frame, style, identify a subject, create a cutout sticker, and prepare the final image before upload. Sticker cutout features may use native operating-system image-processing APIs. This processing may temporarily use device memory, temporary files, app cache, or operating system cache.
Keeps is designed to store stamp photos in cloud Supabase storage rather than maintaining a permanent local stamp file library in the App. However, your device, operating system, image cache, home screen widgets, or app cache may temporarily retain image data for normal performance and display behavior.
3.5 Captions, Visibility, and Saved Stamp Edits
Keeps may store:
- Captions you write.
- Whether a stamp is public or private.
- Later edits to caption or visibility where editing is available.
- Whether a stamp is part of a project, collection, calendar date view, profile view, or social view.
Captions may be visible to other users when a stamp is public or when a caption is included in a message or stamp reply.
3.6 Collections and Calendar Features
Keeps may store data used to organize stamps, including:
- Default collection information.
- Custom collection names.
- Stamp collection assignments.
- Stamp ordering or position in collections.
- Calendar date grouping based on captured date.
- Timestamps used to sort or display stamps.
3.7 Scrapbook/Page Projects
If you use project or page studio features, Keeps may store:
- Project title.
- Project ID.
- Project owner ID.
- Project canvas data.
- Stamps or stamp references used inside a project.
- Project creation and update timestamps.
Project canvas data may include layout information, item positions, text content, selected stamps, and other information needed to restore and display a project.
3.8 Friends and Social Relationships
Keeps may collect and store:
- Friend requests sent and received.
- Friend relationship status, such as pending or accepted.
- Friend IDs.
- Friend display names, usernames, avatars, and public profile details.
- Friend list and friend search results.
- Public stamps shown in social feed or friend profile features.
Friendship features are used to control who can chat, send stamp replies, and see certain friend-related views. You may remove an accepted friend where the unfriend control is available.
3.9 Messages, Reactions, and Stamp Replies
If you use chat, reactions, or stamp reply features, Keeps may collect and store:
- Message text.
- Emoji or reaction icons.
- Sender ID.
- Receiver ID.
- Message ID.
- Message timestamp.
- Referenced public stamp ID.
- Referenced stamp storage path.
- Referenced stamp caption.
Messages are intended to be visible to the sender and receiver. Stamp replies are intended to be limited to visible public friend stamps. Chat messages may continue to appear in the other participant's conversation after you delete your account or content unless deletion is legally required or technically implemented for both participants.
Keeps may let users download a shared stamp image to their device or open a report email containing references needed to identify reported content. A report may include the reported stamp ID, owner information, reporter information, and details the reporter chooses to provide.
3.10 Subscription and Purchase Information
Keeps may collect and store subscription status information, including:
- Whether your current plan is Keeps Basic or Keeps Pro.
- Product identifier for the plan, such as
keeps_pro_monthly,keeps_pro_yearly, orkeeps_pro_lifetime. - RevenueCat customer ID or app user ID information needed to validate entitlements.
- RevenueCat entitlement and customer information needed to determine whether Pro access is active.
- Restore or ownership state needed to prevent paid access from being transferred to the wrong Keeps account.
Apple App Store or Google Play processes payments. Keeps does not receive or store your full payment card number, full billing address, bank account details, or app store password.
3.11 Home Screen Widget Information
If you customize, add, or use Keeps home screen widgets, Keeps may save limited configuration data locally on your device and share it with the operating-system widget extension, including:
- Widget type, such as Camera or Stamp.
- Camera widget icon, title, subtitle, and selected paper color.
- Stamp widget paper color, selected stamp ID, image URL, and a locally cached copy of the selected image.
- A default Keeps logo when no stamp or sticker is selected or available.
- Widget update timestamps.
- Deep links used to open the Camera or Calendar page.
Widget configuration is designed to remain local to the device. A selected stamp image may first be retrieved from Supabase and then cached locally so the widget can display it. Widget content may be visible to anyone who can see your device home screen.
3.12 Device Permissions and Device Information
Keeps may request or use:
- Camera permission, to capture stamp photos.
- Photo library or device storage permission, where needed to select, save, export, or share images.
- Notification permission, to display optional chat, friendship, and Keeps announcement notifications.
- Internet/network access, to sign in, sync data, upload and load photos, send messages, validate purchases, and operate cloud features.
The current app code does not show intentional collection of precise location, contacts, microphone audio, health data, SMS, call logs, or advertising identifiers.
3.13 Onboarding and Local Preferences
Keeps may store limited local preference data on your device, such as whether onboarding has already been completed. This is used to avoid showing onboarding repeatedly.
This local preference data is not intended to be a permanent local copy of your cloud stamp library.
3.14 Diagnostics and Technical Information
Keeps uses Firebase Analytics and Firebase Crashlytics to process limited technical and usage information needed to operate, maintain, debug, and improve the App, such as:
- App version, operating system, device model, language, and general runtime context.
- App lifecycle, session, engagement, and other usage events automatically collected by Firebase Analytics.
- Pseudonymous app-instance and installation identifiers generated by Firebase.
- Approximate region-level location that Firebase Analytics may infer from information such as an IP address.
- Crash stack traces, exception types, thread state, and technical diagnostics associated with a crash.
- Error states and service response status when included in a crash report.
Keeps does not intentionally add stamp photos, captions, chat or reply content, email addresses, display names, authentication tokens, precise location, or payment details to custom analytics events or Crashlytics metadata.
Firebase Analytics and Crashlytics collection is enabled in production releases. Development builds keep collection disabled by default unless a developer explicitly enables it for verification.
Keeps does not request or intentionally collect precise GPS location. Approximate analytics location is used to understand broad regional usage rather than a user's exact position.
3.15 Push Notification Information
Keeps uses Firebase Cloud Messaging together with Apple Push Notification service or Google Play services to deliver notifications when you allow them.
Push-notification information may include:
- FCM or APNs registration token.
- Firebase installation or app-instance identifier.
- Keeps user ID associated with a registered token.
- Device platform, model, operating-system version, language, time zone, app identifier, and app version.
- Notification type and routing identifiers, such as a message, friendship event, actor ID, or related entity ID.
- Notification delivery, failure, retry, and invalid-token status.
- Administrator identifier and notification title or body for audited system announcements.
Keeps may send notifications for new chat messages, friend requests, accepted friend requests, and system announcements. Registered tokens are stored in Supabase and may be subscribed to a Firebase topic used for authenticated-user announcements.
Notification permission is optional. You can change it in device settings. Keeps attempts to unregister the current token when you sign out and removes invalid tokens when delivery providers report them as unusable. Service providers may retain delivery and diagnostic records according to their own policies.
4. How We Use Information
We use information to:
- Create and manage your account.
- Authenticate you and keep your session secure.
- Load your profile and display profile information.
- Capture, process, upload, save, display, edit, and delete stamp photos.
- Create and save cutout stickers.
- Organize stamps by calendar date, collection, profile, and project.
- Save and restore scrapbook/page projects.
- Enforce public and private stamp visibility.
- Search for users and manage friend requests.
- Show friend profiles and social feeds.
- Send and receive chat messages, reactions, and stamp replies.
- Deliver and route optional chat, friendship, and system notifications.
- Let users remove friends, download shared images, and report content.
- Display and update home screen widgets.
- Validate purchases and unlock Keeps Pro features.
- Enforce Basic and Pro plan limits.
- Prevent paid access from being applied to the wrong account.
- Provide customer support.
- Understand aggregate app usage and improve product features.
- Diagnose crashes, prioritize stability issues, and improve reliability.
- Detect, prevent, and respond to fraud, abuse, security incidents, and policy violations.
- Debug, maintain, and improve the App.
- Comply with legal obligations and app store requirements.
5. Legal Bases for Processing
Where a legal basis is required, we process information based on one or more of the following:
- Performance of a contract, to provide Keeps and the features you request.
- Your consent, such as when you grant device permissions or choose to make content public.
- Legitimate interests, such as securing the Service, preventing abuse, improving reliability, and supporting users.
- Legal obligations, such as responding to valid legal requests or maintaining records required by law.
You may withdraw consent for camera, photo-library, storage, or notification permissions through your operating system settings, but some features may stop working.
6. How We Share Information
We do not sell personal and sensitive user data.
We may share information as described below.
6.1 With Service Providers
We use service providers to operate Keeps, including:
- Supabase, for authentication, database, storage, and realtime functionality.
- Apple, for Sign in with Apple, App Store distribution, device permissions, Apple Push Notification service, and in-app purchase processing.
- Google and Firebase, for Google Sign-In, Google Play distribution, Firebase Cloud Messaging, app analytics, crash diagnostics, device or installation information, approximate analytics location, and in-app purchase processing.
- RevenueCat, for purchase validation, subscription status, entitlement checks, and restore behavior.
- Device operating system services, for widgets, camera, image handling, app links, and local app storage.
These providers process information according to their own terms and privacy policies and, where applicable, on our behalf to provide the Service.
6.2 With Other Keeps Users
Information may be visible to other users when:
- You make a stamp public.
- You send or accept a friend request.
- You appear in friend search or friend lists.
- You send a message, reaction, or stamp reply.
- Another user downloads a stamp you chose to share.
- Your profile is shown in social, friend, chat, or public stamp features.
- Your public stamp appears in a social feed or friend profile.
6.3 For Legal, Safety, and Business Reasons
We may disclose information when we reasonably believe it is necessary to:
- Comply with law, legal process, or government request.
- Enforce these Terms or other policies.
- Protect the rights, property, privacy, or safety of users, Nosiah Studio, or others.
- Detect, prevent, or investigate fraud, abuse, security incidents, or technical issues.
- Support a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction.
7. Public Information and Visibility Choices
Some information may become visible to other users depending on your choices and App features.
Public or social information may include:
- Public stamp photos.
- Public stamp captions.
- Display name.
- Username.
- Avatar.
- Bio.
- Public stamp counts.
- Friend relationship status where relevant to the feature.
- Message text and reactions sent to another user.
Private stamps are intended to be visible only to your account and permitted service operations. However, if you change content from public to private, other users may already have seen, downloaded, cached, copied, screenshotted, or received related content.
You should not make content public or send content in chat if you do not want another person to see it.
8. Data Storage and Security
Keeps uses Supabase for cloud database and storage functionality. The current Supabase schema uses row-level security and authenticated access controls so users can access their own data and permitted public or friend data.
Security measures may include:
- Authentication through Supabase.
- Row-level security policies in the database.
- Storage bucket access policies.
- Signed URLs for protected stamp image access.
- Secure network transport used by service providers.
- Plan and entitlement validation through RevenueCat.
- Device operating system permission controls.
No method of transmission, storage, or processing is completely secure. We cannot guarantee absolute security.
9. Data Retention
We keep information for as long as needed to provide Keeps, maintain your account, comply with legal obligations, resolve disputes, prevent fraud or abuse, enforce agreements, and support billing or accounting records.
General retention approach:
- Account and profile data: kept while your account exists.
- Stamp photos and metadata: kept while the stamp or account exists, unless deleted earlier.
- Captions and visibility settings: kept with the related stamp.
- Collections: kept while the collection or account exists.
- Projects: kept while the project or account exists.
- Friend relationships and requests: kept while needed to provide friend features or until removed according to App behavior.
- Chat messages and reactions: kept while needed to provide conversation history, safety, and account features.
- Subscription records: kept as needed for entitlement validation, support, fraud prevention, tax, accounting, app store compliance, and legal requirements.
- Widget configuration and cached image data: kept on-device or in widget storage until replaced, reset, removed, cleared by the operating system, or the App is uninstalled.
- Push registration tokens: kept while associated with a signed-in user and usable for delivery, subject to sign-out cleanup, token refresh, invalid-token removal, and service-provider retention.
- Notification job, failure, delivery, and system-announcement audit records: kept as needed for delivery, troubleshooting, abuse prevention, security, and operational accountability.
- Local onboarding preference: kept on-device until the App is deleted, reset, or the preference is cleared.
- Analytics and crash diagnostic data: retained according to Firebase and Google Analytics retention settings and as needed to understand usage trends, investigate stability issues, and protect the Service.
- Backups and logs: may retain deleted data for a limited period according to provider backup and log retention practices.
10. Account Deletion and Data Deletion
You may request deletion of your account through the App where available or by contacting us at nosiahstudio@gmail.com.
When your account is deleted, we will delete or de-identify data associated with your account, subject to:
- Reasonable time needed to process deletion.
- Backups and technical logs.
- App store and payment processor records controlled by Apple, Google, or RevenueCat.
- Legal, tax, accounting, security, fraud prevention, dispute, or billing requirements.
- Content already shared with another user, such as messages, where preserving the other user's conversation record may be necessary unless deletion is legally required.
Deleting your Keeps account does not automatically cancel an active App Store or Google Play subscription. You must cancel subscriptions through the relevant app store account settings.
11. Your Choices and Controls
You can:
- Update your profile details in the App.
- Choose public or private stamp visibility where the feature is available.
- Edit saved stamp captions and visibility where your plan and the feature allow it.
- Delete stamps where deletion controls are available.
- Delete collections and projects where deletion controls are available.
- Manage friend relationships and friend requests where controls are available.
- Download shared stamp images where the feature is available.
- Report shared content through the in-app report action or support email.
- Manage camera, photo library, and storage permissions through device settings.
- Manage notification permission through device settings.
- Remove Keeps widgets from your home screen through device controls.
- Cancel subscriptions through Apple App Store or Google Play.
- Request account deletion by using the App's deletion request option or contacting us.
12. Regional Privacy Rights
Depending on where you live, you may have rights to:
- Request access to personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of personal information.
- Object to or restrict certain processing.
- Request a copy of certain information in a portable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a data protection authority.
To exercise privacy rights, contact us at nosiahstudio@gmail.com. We may need to verify your identity before responding.
13. International Processing
Your information may be processed and stored in countries other than where you live, including countries where Nosiah Studio or its service providers operate. Those countries may have data protection laws different from your country.
By using Keeps, you understand that information may be transferred to and processed in other countries as needed to provide the Service.
14. Children's Privacy
Keeps is not intended for children under 13, or the minimum age required by law in your location.
We do not knowingly collect personal information from children below the applicable minimum age. If you believe a child has provided personal information to Keeps, contact us at nosiahstudio@gmail.com so we can take appropriate action.
15. Sensitive Content
Keeps may allow users to create photos, captions, messages, and other content. You should avoid uploading or sharing sensitive personal information unless necessary.
Do not upload or share:
- Government ID numbers.
- Payment card details.
- Passwords or authentication codes.
- Private health information.
- Another person's private information without permission.
- Content involving sexual exploitation, child abuse, non-consensual imagery, or illegal activity.
16. No Sale of Personal Data
We do not sell personal and sensitive user data for money.
We do not display third-party advertising. Firebase Analytics and Crashlytics are used for app measurement and reliability, and Firebase Cloud Messaging is used for notification delivery. These services are not used by Keeps to sell personal data or intentionally collect photo, caption, or message content for advertising. Advertising-ID collection is disabled on Android and ad-personalization signals are disabled by default. If these practices change, this policy and app store disclosures will be updated before the changed collection begins.
17. Third-Party Privacy Policies
Keeps depends on third-party services. You should also review their privacy policies:
- Supabase: authentication, database, storage, and realtime infrastructure.
- Apple: Sign in with Apple, App Store, in-app purchases, device permissions, push notification delivery, and iOS services.
- Google and Firebase: Google Sign-In, Google Play, Firebase Cloud Messaging, app analytics, crash diagnostics, approximate analytics location, in-app purchases, Android services, and related infrastructure.
- RevenueCat: subscription and entitlement management.
Nosiah Studio does not control all privacy practices of these third parties.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify you, such as through the App or by updating the effective date.
Your continued use of Keeps after an update means the updated policy applies.
19. Contact
Questions, requests, or complaints about privacy can be sent to:
nosiahstudio@gmail.com