Privacy policy
How Keel looks after your data
Keel is a food, weight and meal-planning diary. This policy says what Keel keeps, why, who else handles it, and how to take it back. It describes Keel as it works today.
Effective 7 October 2026. Keel is run by Tyler Elton, an individual ("we"), who is the controller of your data. Questions: privacy@keelhome.app.
The short version
- Keel keeps your diary so it can count, plan and remind for you. We never sell it and never use it for advertising.
- Keel's database is in Google Cloud in London. Some fields are encrypted with a key that belongs to you; the rest is protected by Google's standard storage encryption. Keel is not end-to-end encrypted: our servers read your diary to do the sums.
- When you use Keel's built-in assistant, the relevant data goes to AI providers through OpenRouter to answer you, unless your iPhone's own model answers, when it stays on your phone. Label photos are read on your phone.
- Agents you connect, such as Claude, see what you ask them about. You can disconnect them at any time.
- You can delete your account in the app. That removes your diary.
What Keel collects
| What | Examples | Why |
|---|---|---|
| Account | The ID your sign-in provider gives Keel, which providers you use, your name and profile photo from that provider | To know it is you and to show your name to people you connect with |
| Diary | Foods and amounts you log, meals, exercise, weights, water, 5-a-day, alcohol units, day notes | The diary itself, daily totals and trends |
| Profile | Sex, date of birth, height, activity level, goal weight, weekly goal, macro split | To work out your daily targets |
| Food preferences | Diet, allergies, dislikes | To keep meal plans, recipes and shopping safe for you and your household |
| Foods you add | Custom foods, foods read from a label photo, saved meals, recipes | So you can log them again. They stay private to you (or your group) |
| People and groups | Who you are connected with, what each of you shares, reactions, short notes, shared meals, groups, meal plans, shared goals, profiles you manage for someone else | The family and friends features you choose to use |
| Groceries | Your shops and shopping rules, budget, what is in your cupboards, shopping lists, products and prices your agent found | Shopping lists and baskets |
| Apple Health | Weight, body fat, active energy and steps, if you allow it | Your weight trend, targets and activity (see below) |
| Connections | Devices you sign in on (with the device's name), agents you connected and when | So each one works, and so you can sign out or disconnect them |
| Assistant records | For each request to Keel's built-in assistant: timings, how many tools it used, an error code if it failed (not your messages). Changes it proposed for you to confirm, and the suggestions it last showed on each screen | To keep the assistant working and fast, and to carry out what you confirm |
Keel does not store your email address; your sign-in provider and Google Identity Platform hold it. Keel's own logs hold no diary content and no IP addresses: a request log has only the type of request, whether it worked and how long it took. Food searches travel inside requests, not in web addresses, and Keel is set up to keep web addresses out of stored logs anyway: Cloudflare keeps no per-request log for Keel's addresses and removes the part of an address after the "?" from anything else it logs, and Google Cloud's own request log, which would store full addresses, is excluded. To slow down attacks on sign-in, Keel counts recent sign-in attempts against a keyed hash of your IP address that changes every day; those counts are deleted after a day.
Keel has no analytics, no advertising and no tracking cookies. The sign-in pages keep what they need for the sign-in itself in your browser's session storage and in short-lived cookies that only work on Keel's own address.
Your consent to health data
Most of what you tell Keel is health data, which UK law treats as special category data, so Keel keeps it only with your explicit consent. Straight after you first sign in, the iPhone app shows the screen below (consent version 1). Until you choose I agree, Keel saves no health data for you, and Not now signs you out.
Keel is a food and health diary, so most of what you tell it is health data. Keel needs your explicit consent before it keeps any.
What Keel keeps
What you eat and drink, your weight and body fat, exercise, water, 5-a-day, alcohol and day notes, your height, sex, date of birth, activity level and goals, your allergies and dislikes, and the Apple Health readings you allow.
Why
Only to run Keel for you: your diary, daily targets and trends, and meal plans and shopping that are safe for you. Never for advertising, and never sold.
Who processes it
Google Cloud stores it in London. When you use Keel's assistant, the parts it needs go to AI providers through OpenRouter, which keep none of it, unless your iPhone's own model answers on your phone. People and agents you connect see only what you choose to share.
You can withdraw consent at any time in You. Keel then stops saving health data, and offers to delete what it holds. Not now signs you out.
If the words on that screen change, the version goes up and the app asks you again. Only you can agree, in the Keel iPhone app: agents you connect, such as Claude, cannot agree for you, and a carer's consent covers only the profiles they manage for a child. To withdraw, open You in the iPhone app and choose Withdraw consent. Keel stops saving health data and stops sending it to the assistant's AI providers straight away, and offers to delete your account and everything it holds. Nothing is deleted unless you choose that.
Signing in
You sign in with Apple, Google or Facebook through Google Cloud Identity Platform. Keel never sees or stores a password. Identity Platform receives your email address, name and profile photo from the provider you choose, and Keel receives a signed confirmation of who you are. The Identity Platform user pool Keel uses is shared with other services run by Tyler Elton, so one email address is one account across them.
AI processing
Keel uses AI in the places below. Where data leaves your phone, it goes from Keel's servers to OpenRouter, which passes it to the model provider that runs the model.
- Keel's built-in assistant (Ask Keel, and the suggested options on each screen). To answer, Keel sends the parts of your diary that matter for the question, such as recent foods, meals, what is planned and what you typed, together with the time of day. Jev (by Typesafe) reads every request to decide how to handle it. A question may then be answered by your iPhone's own model (Apple Intelligence), in which case what you typed and its answer stay on your phone and only the diary lookups it asks for reach Keel. On Keel Plus, Google Gemini may answer instead. Otherwise Keel offers to hand the request to an agent you connect, such as Claude.
- Label photos. When a barcode is not found, you can photograph the nutrition label. Your phone reads it; the photo does not leave your phone. On Keel Plus you can choose to have Google Gemini read it instead, and then the photo goes to Gemini. Keel does not keep the photo; it keeps the values once you confirm them.
These providers process the data only to answer that request. Zero data retention is switched on in Keel's OpenRouter account settings, so OpenRouter sends Keel's requests only to model providers that do not keep what is sent, or train on it.
Open Food Facts
To find packaged foods, Keel's servers send barcodes and food search words to Open Food Facts, a free, open food database. These lookups come from Keel, not your device, and carry nothing that identifies you. Products found are kept in Keel's shared food list, which holds no personal data.
Apple Health
Keel reads from Apple Health only what you allow in the iPhone app: weight, body fat, active energy and steps. It writes back the food and water you log, if you allow that too. You can change this at any time in the Health app or in Keel under You, then Integrations.
- Health data is used only to run Keel for you: your weight trend, your targets, and adding exercise back to your allowance.
- It is never used for advertising or marketing, never sold, and never given to data brokers or advertising platforms.
- It is shared only where you choose: with people you connect with, at the sharing level you pick; with agents you connect, when you ask them; and with the AI processors above when the built-in assistant needs it to answer you.
- Connecting Apple Health happens only in the Keel iPhone app. Claude and other agents cannot connect it.
Agents you connect, such as Claude
You can connect AI agents to Keel, for example by adding Keel as a connector in Claude. You sign in to Keel and approve the agent first; Keel shows what it will be able to do. After that it can read and change your diary for you within that access, and Keel sends it whatever its requests ask for, so what it does with that data is covered by its own provider's policy (for Claude, Anthropic's privacy policy).
To disconnect an agent, remove Keel from the agent's settings (in Claude: Settings, then Connectors), or choose Disconnect next to it in the Keel iPhone app under You, then Integrations, Connected agents. There you can also narrow what it may do in each area (diary, meals, groceries, people) to none, see only, or see and change. Disconnecting stops it straight away. Deleting your account disconnects every agent.
Who else handles your data
| Provider | What for |
|---|---|
| Google Cloud (London, europe-west2) | Runs Keel's servers and database, holds the encryption keys and backups |
| Google Cloud Identity Platform | Sign-in with Apple, Google or Facebook |
| Cloudflare | Delivers Keel's web addresses and passes requests securely to Google Cloud |
| OpenRouter, and the model providers it routes to (Typesafe, Google) | The built-in assistant, and label reading on Keel Plus |
| Open Food Facts | Barcode and food lookups (no personal data) |
| Apple | Apple Health on your iPhone, and Sign in with Apple if you use it |
Data sent outside the UK
Some of these providers handle data outside the UK. Where they do, UK law requires a safeguard, and these are the ones Keel relies on:
- Google Cloud. Keel's servers, database, encryption keys and erasure records are in London (europe-west2). Automatic database backups are stored in Google's European Union multi-region, and server logs and sign-in records are held in Google's global locations. The EU is covered by UK adequacy regulations; anywhere else is covered by the UK Addendum to the EU Standard Contractual Clauses in Google Cloud's data processing terms.
- Cloudflare. Requests pass through Cloudflare's data centre nearest to you, which may be outside the UK. Covered by UK adequacy regulations where they apply, otherwise by the UK Addendum to the EU Standard Contractual Clauses in Cloudflare's data processing terms.
- OpenRouter and the model providers it routes to. OpenRouter is in the United States, and model providers may run the request in the United States or elsewhere. Covered by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
- Open Food Facts is in France, which UK adequacy regulations cover. Keel sends it no personal data.
- Apple. Apple Health data stays on your iPhone and in your Apple account, under Apple's own privacy policy; Keel does not send your diary to Apple. Sign in with Apple is also under Apple's policy.
How it is protected
Everything travels over encrypted connections. In the database, these fields are each encrypted with a key that belongs only to you (or to your group): your name and photo, the descriptions on diary entries and exercise, day notes, notes people send you, shared meal offers, your allergies and dislikes, recipe steps, and the assistant's saved suggestions and proposals. Those keys are themselves locked by Google Cloud's key service. Everything else, such as which foods you log, amounts, calories, weights, your profile and dates, is protected by Google Cloud's standard encryption of stored data. Keel's servers can still read your diary while working on a request; that is how they total your day, fit portions and build lists.
How long it is kept
- Your diary and everything else above: for as long as you have an account.
- Sign-in codes: about a minute. Sign-in attempt counts: a day.
- Database backups: 7 days. A backup is taken every day and kept for 7 days, and changes are kept for 7 days so the database can be restored to a point in time. When you delete your account, the keys for your encrypted fields are destroyed, so those fields can no longer be read in any backup. Other data in a backup goes when that backup expires.
- Server logs in Google Cloud: 30 days. Google Cloud's audit logs, which record changes to Keel's infrastructure and hold no diary data, are kept for 400 days.
- Cloudflare: Keel keeps no per-request logs there. Cloudflare's request logs are switched off for Keel's addresses, and Keel writes no log lines of its own.
Deleting your data
In the Keel iPhone app, go to You, then Delete account. This deletes your diary, profile, foods, meals, weights, Apple Health readings, preferences, groceries, connections with people, device sign-ins and agent connections at once, and destroys your encryption keys. A group you alone manage passes to its longest-standing member, or is deleted if you are its only member. Profiles you manage for someone else are deleted with yours. Foods from Open Food Facts stay in the shared list, as they hold nothing about you.
Deleting your Keel account does not remove your sign-in record from Google Identity Platform, because that sign-in is shared with other services. Email privacy@keelhome.app and we will remove it. Readings Keel wrote to Apple Health stay in Apple Health until you delete them there.
Children
Keel is for people aged 13 and over. A parent or carer can keep a managed diary for a younger child; the child has no login of their own, and the carer controls it. The child can take it over with their own sign-in once they are 13.
Your rights
Under UK data protection law you can ask for a copy of your data, ask us to correct or delete it, object to how we use it, or ask for it in a portable format. Where Keel relies on your consent, you can withdraw it at any time. Email privacy@keelhome.app. You can also complain to the Information Commissioner's Office at ico.org.uk.
Why Keel is allowed to use your data
| Use | Lawful basis |
|---|---|
| Your account, and the parts of Keel that hold no health data: foods you add, groceries, people and groups | Contract: it is the service you asked for |
| Health data: your diary, weight and body measurements, exercise, profile and goals, allergies and dislikes, and Apple Health | Your explicit consent, given on the consent screen above. You can withdraw it in the iPhone app under You, then Withdraw consent |
| Security logs and sign-in attempt counts | Legitimate interests: keeping Keel and your account secure |
| Sharing with people in your circle and groups | Your consent, given each time you choose to share |
Changes
If this policy changes in a way that matters, we will say so in the app before the change applies. The date at the top shows the current version.
Contact
Tyler Elton
privacy@keelhome.app