Privacy policy

How Keel looks after your data

Keel is a food, weight and meal-planning diary. This policy says what Keel keeps, why, who else handles it, and how to take it back. It describes Keel as it works today.

Effective 7 October 2026. Keel is run by Tyler Elton, an individual ("we"), who is the controller of your data. Questions: privacy@keelhome.app.

The short version

What Keel collects

WhatExamplesWhy
AccountThe ID your sign-in provider gives Keel, which providers you use, your name and profile photo from that providerTo know it is you and to show your name to people you connect with
DiaryFoods and amounts you log, meals, exercise, weights, water, 5-a-day, alcohol units, day notesThe diary itself, daily totals and trends
ProfileSex, date of birth, height, activity level, goal weight, weekly goal, macro splitTo work out your daily targets
Food preferencesDiet, allergies, dislikesTo keep meal plans, recipes and shopping safe for you and your household
Foods you addCustom foods, foods read from a label photo, saved meals, recipesSo you can log them again. They stay private to you (or your group)
People and groupsWho you are connected with, what each of you shares, reactions, short notes, shared meals, groups, meal plans, shared goals, profiles you manage for someone elseThe family and friends features you choose to use
GroceriesYour shops and shopping rules, budget, what is in your cupboards, shopping lists, products and prices your agent foundShopping lists and baskets
Apple HealthWeight, body fat, active energy and steps, if you allow itYour weight trend, targets and activity (see below)
ConnectionsDevices you sign in on (with the device's name), agents you connected and whenSo each one works, and so you can sign out or disconnect them
Assistant recordsFor each request to Keel's built-in assistant: timings, how many tools it used, an error code if it failed (not your messages). Changes it proposed for you to confirm, and the suggestions it last showed on each screenTo keep the assistant working and fast, and to carry out what you confirm

Keel does not store your email address; your sign-in provider and Google Identity Platform hold it. Keel's own logs hold no diary content and no IP addresses: a request log has only the type of request, whether it worked and how long it took. Food searches travel inside requests, not in web addresses, and Keel is set up to keep web addresses out of stored logs anyway: Cloudflare keeps no per-request log for Keel's addresses and removes the part of an address after the "?" from anything else it logs, and Google Cloud's own request log, which would store full addresses, is excluded. To slow down attacks on sign-in, Keel counts recent sign-in attempts against a keyed hash of your IP address that changes every day; those counts are deleted after a day.

Keel has no analytics, no advertising and no tracking cookies. The sign-in pages keep what they need for the sign-in itself in your browser's session storage and in short-lived cookies that only work on Keel's own address.

Your consent to health data

Most of what you tell Keel is health data, which UK law treats as special category data, so Keel keeps it only with your explicit consent. Straight after you first sign in, the iPhone app shows the screen below (consent version 1). Until you choose I agree, Keel saves no health data for you, and Not now signs you out.

If the words on that screen change, the version goes up and the app asks you again. Only you can agree, in the Keel iPhone app: agents you connect, such as Claude, cannot agree for you, and a carer's consent covers only the profiles they manage for a child. To withdraw, open You in the iPhone app and choose Withdraw consent. Keel stops saving health data and stops sending it to the assistant's AI providers straight away, and offers to delete your account and everything it holds. Nothing is deleted unless you choose that.

Signing in

You sign in with Apple, Google or Facebook through Google Cloud Identity Platform. Keel never sees or stores a password. Identity Platform receives your email address, name and profile photo from the provider you choose, and Keel receives a signed confirmation of who you are. The Identity Platform user pool Keel uses is shared with other services run by Tyler Elton, so one email address is one account across them.

AI processing

Keel uses AI in the places below. Where data leaves your phone, it goes from Keel's servers to OpenRouter, which passes it to the model provider that runs the model.

These providers process the data only to answer that request. Zero data retention is switched on in Keel's OpenRouter account settings, so OpenRouter sends Keel's requests only to model providers that do not keep what is sent, or train on it.

Open Food Facts

To find packaged foods, Keel's servers send barcodes and food search words to Open Food Facts, a free, open food database. These lookups come from Keel, not your device, and carry nothing that identifies you. Products found are kept in Keel's shared food list, which holds no personal data.

Apple Health

Keel reads from Apple Health only what you allow in the iPhone app: weight, body fat, active energy and steps. It writes back the food and water you log, if you allow that too. You can change this at any time in the Health app or in Keel under You, then Integrations.

Agents you connect, such as Claude

You can connect AI agents to Keel, for example by adding Keel as a connector in Claude. You sign in to Keel and approve the agent first; Keel shows what it will be able to do. After that it can read and change your diary for you within that access, and Keel sends it whatever its requests ask for, so what it does with that data is covered by its own provider's policy (for Claude, Anthropic's privacy policy).

To disconnect an agent, remove Keel from the agent's settings (in Claude: Settings, then Connectors), or choose Disconnect next to it in the Keel iPhone app under You, then Integrations, Connected agents. There you can also narrow what it may do in each area (diary, meals, groceries, people) to none, see only, or see and change. Disconnecting stops it straight away. Deleting your account disconnects every agent.

Who else handles your data

ProviderWhat for
Google Cloud (London, europe-west2)Runs Keel's servers and database, holds the encryption keys and backups
Google Cloud Identity PlatformSign-in with Apple, Google or Facebook
CloudflareDelivers Keel's web addresses and passes requests securely to Google Cloud
OpenRouter, and the model providers it routes to (Typesafe, Google)The built-in assistant, and label reading on Keel Plus
Open Food FactsBarcode and food lookups (no personal data)
AppleApple Health on your iPhone, and Sign in with Apple if you use it

Data sent outside the UK

Some of these providers handle data outside the UK. Where they do, UK law requires a safeguard, and these are the ones Keel relies on:

How it is protected

Everything travels over encrypted connections. In the database, these fields are each encrypted with a key that belongs only to you (or to your group): your name and photo, the descriptions on diary entries and exercise, day notes, notes people send you, shared meal offers, your allergies and dislikes, recipe steps, and the assistant's saved suggestions and proposals. Those keys are themselves locked by Google Cloud's key service. Everything else, such as which foods you log, amounts, calories, weights, your profile and dates, is protected by Google Cloud's standard encryption of stored data. Keel's servers can still read your diary while working on a request; that is how they total your day, fit portions and build lists.

How long it is kept

Deleting your data

In the Keel iPhone app, go to You, then Delete account. This deletes your diary, profile, foods, meals, weights, Apple Health readings, preferences, groceries, connections with people, device sign-ins and agent connections at once, and destroys your encryption keys. A group you alone manage passes to its longest-standing member, or is deleted if you are its only member. Profiles you manage for someone else are deleted with yours. Foods from Open Food Facts stay in the shared list, as they hold nothing about you.

Deleting your Keel account does not remove your sign-in record from Google Identity Platform, because that sign-in is shared with other services. Email privacy@keelhome.app and we will remove it. Readings Keel wrote to Apple Health stay in Apple Health until you delete them there.

Children

Keel is for people aged 13 and over. A parent or carer can keep a managed diary for a younger child; the child has no login of their own, and the carer controls it. The child can take it over with their own sign-in once they are 13.

Your rights

Under UK data protection law you can ask for a copy of your data, ask us to correct or delete it, object to how we use it, or ask for it in a portable format. Where Keel relies on your consent, you can withdraw it at any time. Email privacy@keelhome.app. You can also complain to the Information Commissioner's Office at ico.org.uk.

Why Keel is allowed to use your data

UseLawful basis
Your account, and the parts of Keel that hold no health data: foods you add, groceries, people and groupsContract: it is the service you asked for
Health data: your diary, weight and body measurements, exercise, profile and goals, allergies and dislikes, and Apple HealthYour explicit consent, given on the consent screen above. You can withdraw it in the iPhone app under You, then Withdraw consent
Security logs and sign-in attempt countsLegitimate interests: keeping Keel and your account secure
Sharing with people in your circle and groupsYour consent, given each time you choose to share

Changes

If this policy changes in a way that matters, we will say so in the app before the change applies. The date at the top shows the current version.

Contact

Tyler Elton
privacy@keelhome.app