Skip to content
KEEP

Privacy

Privacy Policy

This describes what information KEEP collects across this website and the separate Control Plane application, what it doesn't collect, and what stays entirely on infrastructure you or your MSP control. It matches the same evidence discipline as the rest of this site — see Security & Data Ownership for the full architectural detail this page summarizes for a privacy audience specifically.

Scope

What this policy covers

Three distinct surfaces, each handled differently:

This website

Public, informational, static. It collects nothing about you directly.

KEEP's Control Plane

The separate account, licensing, and entitlement service this policy covers in the most detail below.

Your KEEP deployment

Software that runs on your own or your MSP's infrastructure — see Security & Data Ownership for what it does and doesn't send anywhere.

This Website

What this website collects

Nothing, directly. This site has no forms and no analytics or tracking scripts. It links out to KEEP's Control Plane for account creation and sign-in — the sections below cover what that separate application collects and the one cookie it sets.

Cookies & Sessions

Cookies, and how sign-in works

This website sets no cookies of its own — no analytics, advertising, or tracking cookies, and none from any third party.

When you sign in on KEEP's Control Plane, it sets exactly one cookie: a signed, HttpOnly session cookie that keeps you signed in for up to 8 hours. It exists solely to authenticate you to your own account — it isn't used for tracking, advertising, or analytics, and it's the only cookie the Control Plane sets. (Source: KEEP Control Plane architecture documentation)

Account Registration

Information collected when you create an account

Creating an account on KEEP's Control Plane collects:

  • Your organization / account name
  • Account type (MSP or Solo)
  • Your email address
  • A password you choose
  • Optionally, a checkbox signal that you're interested in evaluating KEEP, with the time it was recorded

When you register, KEEP takes the password you supply and immediately converts it into a one-way bcrypt hash before anything is stored. The plaintext password you typed is never saved — not in your account record, not anywhere else in KEEP's systems.

That's the complete set collected at registration. (Source: KEEP Control Plane architecture documentation)

Your Deployment

What KEEP's Control Plane receives from a running deployment

Once a Hub or Spoke is running, it periodically checks in with the Control Plane directly to confirm license and entitlement status, and — once per boot — reports a network fingerprint: the MAC address of your gateway device and the MAC addresses of neighboring devices on that same network segment, used only to detect a cloned or duplicated device. Nothing about what those neighboring devices are or do is included, only their MAC addresses. (Source: KEEP architecture documentation)

KEEP's Control Plane does not receive your device inventory, incident history, scan results, or any other operational data your deployment produces. That data stays on your own Hub's database, which you or your MSP control. (Source: KEEP Control Plane architecture documentation)

Optional AI Features

Merlin(Intelligence) — only if you turn it on

If you enable Merlin(Intelligence), specific features send only the descriptive context that feature needs to an external AI provider — Anthropic (Claude) by default, or a provider you configure yourself. Credentials are never included, and your full device inventory or database is never sent. If Merlin(Intelligence) is disabled, nothing leaves your environment for AI purposes at all — this is an architectural guarantee, not a setting KEEP has to remember to honor. (Source: KEEP Data Handling documentation)

Third Parties

Infrastructure KEEP relies on

A small, fixed set of infrastructure providers process account and billing data on KEEP's behalf, each for a specific purpose:

  • This website is hosted on Vercel.
  • KEEP's Control Plane application runs on Railway, backed by a Neon-hosted PostgreSQL database.
  • Paid subscriptions are processed by Stripe. KEEP does not receive or store your card number — Stripe collects payment details directly.
  • Account verification emails are sent through Resend.
  • If you enable Merlin(Intelligence), Anthropic (or your own configured AI provider) receives the descriptive context described above.

(Source: KEEP Control Plane architecture documentation)

Retention

How long information is kept

We keep your account information for as long as your account remains active. We haven't formalized a broader data-retention schedule beyond that yet.

Evaluators

If you're evaluating KEEP

Data collection during an evaluation works the same way it does for any account — nothing about being in evaluation changes what stays local or what reaches KEEP. See Evaluate KEEP for the full evaluation lifecycle, and Security & Data Ownership for the removal process if you decide not to continue. (Source: KEEP Evaluation Program documentation)

Your Choices

Accessing or updating your information

You can review and update your account information directly on your Control Plane account dashboard. There is no self-serve way to delete your account today.

Children's Privacy

Not directed to children

KEEP is a business tool for managed service providers and IT teams. It is not directed to children, and we do not knowingly collect information from anyone under 16.

Changes

Changes to this policy

If this policy changes in a way that materially affects how we handle your information, we'll update this page and change the date below.

Last updated: September 16, 2026

Contact

Questions about this policy

For privacy questions or requests, contact privacy@keepmsp.io.

See also Terms of Use, which governs use of this website and the KEEP service.