Privacy policy

Your data, plainly.

Keelen Labs ("Keelen", "we") operates keelen.ai. This policy describes what we collect and why. The short version: we store what the product needs to run your loop and bill you — nothing more — and your code is not ours.

What we collect

Account data: your email address and workspace name, used for sign-in (magic links), product notifications you can act on (a paused project, a question the PM needs answered), and billing receipts.

Connected credentials: the GitHub App installation you authorize and the AI engine credentials you connect (Claude, Codex, GLM, or Kimi). These are encrypted at rest under independent, rotatable keys, are never sent back to your browser, and are deleted when you revoke them.

Operational data: project configuration, iteration logs (automatically scrubbed of secrets), pull-request metadata, and timeline metrics such as run duration and token counts. This is the data that powers your dashboard.

Billing data: payments are processed by Stripe. We store your Stripe customer and subscription identifiers — never card numbers.

Your code

Your repository content lives in your GitHub account. During a run it is cloned into an isolated single-use virtual machine that is destroyed when the run ends — no persistent volume. We keep iteration logs and diffs' metadata so you can audit what the loop did; we do not keep a copy of your repository.

We do not train machine-learning models on your code. Your AI usage flows directly to the provider whose credential you connected, under that provider's terms.

We do capture iteration trajectories: the prompts we send, the diffs the loop produced, and the tool calls it made during a run. We use them for one purpose, to improve the loop itself (its scheduling decisions and the quality of the rules it writes). Trajectory capture is controlled by a workspace setting. You can turn it off in Settings, and capture stops for every project in that workspace.

We never sell trajectory data, and we never share one customer's trajectories with another customer.

What we never do

We do not sell your data. We do not share it with advertisers. We do not read your repositories outside of the runs you configure. We do not use your credentials for anything except operating the loop you turned on.

Third parties we rely on

We rely on a small set of subprocessors for source hosting, AI model access, payments, compute, storage, email, and error monitoring. Each one receives only what its function requires.

See the full subprocessor list

Retention and deletion

We keep your iteration history while your workspace is active, and we delete it when you delete your workspace. Your plan sets how far back the dashboard shows that history. That is a display limit, not a deletion schedule.

Some records are swept on a fixed timer today: audit-log entries after 90 days, scheduler decision records after 45 days, QA evidence artifacts after 14 days, and design-review artifacts after 14 days.

Revoking a credential deletes it immediately. Deleting a project soft-deletes its records. Deleting your account removes your personal data from live systems within 30 days, with two carve-outs: we keep billing records for as long as tax and legal duties require, and we keep aggregate product analytics with the identifiers removed.

To exercise access, correction, or deletion rights, email privacy@keelen.ai from your account address.

Cookies, analytics, and error monitoring

We use a session cookie to keep you signed in and first-party product analytics (page views and feature events) to improve the product.

Your browser also stores three first-party identifiers, and they are set on your first visit, before you sign up: keelen_anon_id in localStorage (a persistent pseudonymous device id), keelen_acq in localStorage (the first UTM parameters and referrer we saw), and a session id in sessionStorage.

We use the Sentry browser SDK for error monitoring. It sends exception reports through a tunnel on our own origin, so it is first-party traffic. We configure it to send no personal data by default, to sample 10 percent of performance traces, and to record no session replay.

There are no third-party advertising trackers and no session replay anywhere on the site.

Changes

If this policy changes in substance, we will notify account holders by email before the change takes effect.

Revision of 2026-08-13 (previous effective date 2026-07-04): we now describe iteration-trajectory capture and the workspace setting that controls it, we replaced the plan-retention claim with the sweeps that actually run today, we named the deletion carve-outs for billing and aggregate analytics, we disclosed the browser-storage identifiers and the Sentry error monitoring, and we moved the subprocessor list to its own page.

Contact: privacy@keelen.ai · Effective 2026-08-13