Keepilo Deutsch
Menu

Legal

Privacy policy for Keepilo and this website

Short version: this website sets no cookies and runs no analytics, and the app has no server to send anything to. The long version follows.

Last updated: 11 August 2026. This is a courtesy translation; in case of conflict the German privacy policy applies.

Controller

Responsible for data processing within the meaning of Article 4 (7) GDPR, and contact point for all data protection matters:

Andreas Schneider
Tränkstraße 3
65558 Holzheim
Germany
info@keepilo.com

This website

Server log files

This website is operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in their data centre in Helsinki, Finland, and therefore within the European Union. As with every web server, requests are recorded in log files: IP address, date and time, the file requested, the referring page, browser and operating system version. This is technically necessary to deliver the pages and to detect attacks.

Legal basis is Article 6 (1) (f) GDPR; our legitimate interest is the secure and stable operation of the site. The logs are deleted after seven days at the latest and are not merged with any other data. A data processing agreement under Article 28 GDPR is in place with the hosting provider.

Cookies, analytics, advertising

None. This site sets no cookies, uses no local storage, contains no analytics, no tracking pixels, no ad banners and no social media plugins. That is why you are not being asked to consent to anything. The app stays free of advertising as well; what follows concerns links in blog posts on this website only.

Affiliate links in the blog (Amazon Associates)

In blog posts we recommend equipment and occasionally link to it on Amazon. Those are affiliate links: if you buy through them we earn a small commission, and the price stays the same for you. We take part in the affiliate programme of Amazon Europe Core S.à r.l., and as an Amazon Associate we earn from qualifying purchases. Every post containing such links says so clearly at the top, before the first link.

Simply reading changes nothing: an affiliate link is an ordinary link in the text. Nothing is loaded from Amazon, no script runs, no cookie is set and no identifier is assigned. We do not learn whether you looked at a link.

Only when you click such a link do you leave this website. From that point Amazon processes your data, in particular your IP address and the associate tag contained in the address; Amazon sets its own cookies and can attribute a later purchase to our recommendation. Amazon is its own controller for that, under its own privacy policy. We have no influence over it and no access to it.

All we receive from Amazon is a statement without any personal reference: which products were bought through our links, in what quantity, and the resulting commission. We cannot see who bought anything, and we cannot work it out either. The legal basis for placing these links is Article 6 (1) (f) GDPR; our legitimate interest is funding the freely available content. No consent is required, because nothing is stored on or read from your device on our side.

Fonts and other resources

All fonts, images, styles and scripts are delivered from this server. Nothing is loaded from Google Fonts, a CDN or any other third party, so no data about you is passed to anyone else when you read this page.

Contacting us by email

If you write to info@keepilo.com, we process your address and the content of your message in order to answer it (Article 6 (1) (b) and (f) GDPR). We keep the correspondence as long as it is needed for the matter and any statutory retention obligations, then delete it. There is no contact form on this site, and no newsletter.

The Keepilo app

We collect nothing

Keepilo has no account, no sign-up and no server holding your data. There is no advertising, no tracking and no analytics component in the program. What you enter (supplies, people, medical cards, emergency plan, chat history) stays on your device.

When the app goes online

Only when you download something: the models for search and the assistant, content packages, map regions, and the list of available content. As with any download, the delivering server sees your IP address and typically logs it briefly. Those files are hosted at GitHub, at Hugging Face and in Hetzner storage in Finland; we evaluate nothing there.

The legal basis for that transfer is Article 6 (1) (b) GDPR: without the download the function cannot be provided. The app downloads nothing on its own; every download is triggered by you.

The Hetzner storage is in Helsinki and therefore inside the EU. GitHub and Hugging Face are based in the United States, so downloading from them transfers your IP address to a third country. That transfer is necessary for the download you started (Article 49 (1) (b) GDPR); where the provider is certified under the EU-US Data Privacy Framework, it additionally rests on the European Commission's adequacy decision (Article 45 GDPR). Those providers are their own controllers for their server logs.

Everything else runs offline

The assistant computes on your device. Your questions, your documents and the answers never leave it, not anonymised and not to improve any model.

Location on the map

The map can show your location. The app asks first and you may say no, the map works without it. Your device works out the position itself (GPS needs no network); it is only displayed, never stored and never transmitted. There is no background tracking.

Camera and microphone

Keepilo needs the camera for barcode scanning, the magnifier, profile pictures, photographing documents, and reading QR codes during a transfer. The images stay on the device; a barcode is checked against an offline package, not against a service. The app does not use a microphone.

Shared supplies (only if you set it up)

This feature is off until you start it. Once you do, the app syncs your supplies – items, batches and entries – through our service sync.keepilo.com with the devices you paired yourself by QR code. Documents, people, health data, emergency plan and vault do not go along.

Every change is sealed on your device (AES-256-GCM) with a key only your paired devices hold. The service carries sealed packages; it cannot open them, and neither can we. The key lives in your device’s keychain and is never sent to us.

What the service does see: your IP address, the time of each request, the size of the packages and a random identifier for your household. There is no account, no name and no email address.

How long anything stays there: one encrypted copy of your current supplies, for as long as shared supplies are in use – no history. If no device checks in for twelve months, everything is deleted. If you end shared supplies in the app, everything is deleted right away.

The service runs on our server at Hetzner Online GmbH in Germany (processor). The legal basis is Art. 6(1)(b) GDPR. No transfer to third countries takes place.

What you pass on yourself

An export creates a file containing your data. Where it goes is your decision; the app does not send it anywhere by itself. The "sharing" preset contains health data and asks before it includes it.

Deleting

There is nothing to revoke and nothing to request, because nothing is held by us. Deleting the app deletes all data, including the automatic backups in the app folder. Export first if you want to keep it.

Health data

Medical cards and long-term medication are special categories of personal data under Article 9 GDPR. They are stored in the same local database as everything else and are never transmitted. Protect them with the app lock (PIN and fingerprint or face); on iOS and Android the operating system's own encryption applies on top.

Document vault

The vault is a separate, encrypted place inside the app for ID documents, insurance papers, contracts and powers of attorney. Contents are stored on your device encrypted with AES-256-GCM; the key is derived from your password using Argon2id. The index of stored documents is encrypted too, and the file names reveal nothing about their contents.

The password is stored nowhere, not even as a verifier. It exists only at runtime and is discarded when the vault locks. That is why there is no reset: we cannot open the vault, and neither can anyone else. The assistant does not read the vault; it is neither indexed nor searched. A full backup takes it along encrypted, the sharing package leaves it out. Passing on individual documents is a deliberate act, with a one-time code that you transmit yourself.

Stores and payment

The app is sold through Apple, Google and Microsoft. The data created by a purchase (payment, invoice, refund) is processed by the respective store as controller, under its own privacy policy. We receive no payment data and no list of buyers.

Your rights

You have the rights under Articles 15 to 21 GDPR: access, rectification, erasure, restriction of processing, data portability and objection. For the app they largely run empty, because we hold no personal data about you: there is no record we could give you access to. Your data is exclusively on your device and under your control there.

For the website, those rights apply to the server log files and to any email correspondence. Write to info@keepilo.com and we will deal with it.

You also have the right to lodge a complaint with a supervisory authority under Article 77 GDPR. The authority responsible for our seat is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate, Hintere Bleiche 34, 55116 Mainz, Germany.

Changes to this policy

If the app or the site changes in a way that affects data processing, this page changes with it, and the date at the top is updated. The version inside the app under "Legal" is kept identical to this one.