What appkeep holds about you, and the choices you have.
This notice explains what personal data appkeep collects about you, why, what we do with it, and the rights you have over it. We have kept it plain. Where the law needs a precise word, we use it and then explain it.
Last updated 26 August 2026Who we are (the data controller)
controllerappkeep is operated by Rebel Strategy Lab Oy, a limited company registered in Finland and based in Helsinki. For the data you give appkeep, Rebel Strategy Lab Oy is the data controller: the company that decides what is collected and why.
- ControllerRebel Strategy Lab Oy, Finland
- Business ID (Y-tunnus)3512742-3
- Registered address00600 Helsinki, Finland
- Data-protection contactprivacy@appkeep.org
appkeep currently runs as a product within Rebel Strategy Lab Oy. We intend to move it into its own company in the future. If that changes who controls your data, we will tell you before it happens and explain what it means for you (see Section 8).
We have not appointed a Data Protection Officer. For any question about your data, write to privacy@appkeep.org.
What we collect, why, and our legal basis
GDPR Art. 6We collect only what we need to run the service and to do the job you came here to do. "Legal basis" is the lawful reason the GDPR allows us to process each kind of data.
| What we collect | Why we collect it | Legal basis (GDPR) |
|---|---|---|
| Account data — your email, a hashed (scrambled) version of your password, whether your email is verified, your country, and your household situation (for example: homeowner, or owner who lives elsewhere) | To create and secure your account, sign you in, and match cost and lifespan data to your country | Performance of a contract (Art. 6(1)(b)) — we need this to provide the service you signed up for |
| Payment and subscription data — whether your subscription is active, when the paid period ends, and the reference numbers linking your account to our customer record at Stripe. Your card details go to Stripe directly and are never stored by us | To know your subscription is paid, give you the access you paid for, and handle renewal and cancellation | Performance of a contract (Art. 6(1)(b)); keeping the resulting accounting records is a legal obligation (Art. 6(1)(c)) — see Section 4 |
| Sign-in and session data — a hashed session token, your IP address, and your browser and device description (user-agent) | To keep you signed in, keep your account secure, and protect the service from abuse | Legitimate interests (Art. 6(1)(f)) — keeping your account and the service secure |
| Usage events — which page paths were opened and which basic actions happened, plus a visit code our server works out from your IP address and browser description (user-agent) so the pages of one visit hang together. The code is a one-way scramble made with a secret key we keep in memory and replace each day it is used. Neither your IP address nor your browser description is stored with these events. The only things you enter that reach them are plain numbers from the calculators — the hourly rate or the age of a component — and a quote amount only as a broad range, never the figure itself. No free-text box, no name, no email address, and no property address goes into them. Section 6 has the detail | To see which parts of the site and the product are used, so we can improve them | Legitimate interests (Art. 6(1)(f)) — understanding how our own product is used, without a third party and without profiling you |
| Property data — a name for your property, its country, type, year built, number of storeys, floor area. The street address you type for the Netherlands lookup is used to fetch floor area and year built — it is not stored | To build your home's maintenance profile, work out per-area costs, and act as your home's record (useful when you sell) | Performance of a contract (Art. 6(1)(b)) |
| Component, defect, mandate and plan data — the building components you record, the defects you report, the contractor mandates you generate, and the multi-year maintenance plan appkeep produces for you | To run the maintenance plan, the fix flow, and the mandate calculator: the product itself | Performance of a contract (Art. 6(1)(b)) |
| Contractor contact data — the name, one contact detail (email or phone), and trade of a contractor you brief or keep to reuse. This is data about someone else, which you give us | To let you brief a contractor, keep track of who you are waiting on, and offer a contractor you have used before when a similar job comes up | Legitimate interests (Art. 6(1)(f)) — running the repair job you started; we never contact the contractor ourselves and never share their details |
| Quotes you record — the figures from a contractor's quote you put against a job, whether you type them in or forward the quote email to your house's private address: the total, warranty terms, the rate for extra work, whether they visited, what the quote covers, and the contractor's name. When you forward a quote, we receive that email and read it (and any attached quote) to pull those figures out; we keep the figures and a short excerpt, not the original file. The reading is done by an AI model, run by Anthropic on our instructions. Your quote is never used to train or improve that model. The model proposes the figures and nothing else: you see what it read, next to the line it read it from, and nothing is saved to your job until you confirm it. The name and the forwarded quote are data about someone else, which you give us | To lay the quotes for one job side by side against the fair price, so you can pick a contractor on the terms you set | Performance of a contract (Art. 6(1)(b)) for the figures; legitimate interests (Art. 6(1)(f)) for the contractor's name and the forwarded quote — we never contact them and never share it |
| Waitlist sign-ups — your email, and (if you gave them) your situation, country, and the problem that brought you | To let you know when appkeep opens and send the pre-launch updates you asked for | Consent (Art. 6(1)(a)) — you can withdraw it any time by unsubscribing |
| Newsletter and onboarding emails — your email and your subscription or opt-out preference | To send the emails you opted in to | Consent (Art. 6(1)(a)) — you can withdraw it any time |
Some data you give us is about other people — a contractor you brief. If you are one of them and want to know what we hold or have it removed, email privacy@appkeep.org. We explain this in full in the contractor data notice.
We do not intentionally collect special-category data (such as health or beliefs). Please do not put such information into free-text fields, for example a defect description.
Who processes data for us, and where it goes
sub-processorsWe use a small number of service providers to run appkeep. They process data on our instructions, under contract. We keep the list short on purpose.
| Provider | What they do for us | Where |
|---|---|---|
| Hetzner | Hosting and the PostgreSQL database — this is where your account and property data live | Helsinki, Finland (EU) |
| Resend | Sends our account emails and, if you opted in, the newsletter. If you forward a contractor's quote to your house's private address, Resend also receives that email and its attachment and holds it briefly so we can read the figures from it — the contractor's name and quote pass through Resend the same way our outbound email does | EU region |
| Stripe | Payment processing for the subscription. Payment happens on Stripe's own checkout page — your card details go to Stripe directly and never touch our servers. | EU + United States — see the transfer note below |
| Anthropic | Reads a quote you forward, and only that: the email text and the attached quote go to Anthropic's API so the figures can be pulled out of them. Your quote is never used to train or improve the model. We send the quote itself and nothing that identifies you or your account, and we do not keep the file once the figures are read. | United States — see the transfer note below |
| Dutch Kadaster / PDOK (BAG public register) | If your home is in the Netherlands, we look up its floor area and year built from this public government register so you do not have to type them in. Your address is sent to the register to do the lookup. This is a public register we query, not a provider acting on our instructions. | Netherlands (EU) |
Your property data and the plan you build stay inside the EU. Two providers move data outside it, both to the United States, and both under an approved safeguard.
Stripe, when you pay: your email, and the name and billing address you enter on Stripe's checkout page. Stripe is certified under the EU–US Data Privacy Framework; if that certification ever lapses, its transfer terms fall back to the EU Standard Contractual Clauses.
Anthropic, when you forward a quote: the text of that email and the quote attached to it. The transfer is covered by our data processing agreement with Anthropic and the EU Standard Contractual Clauses. Your quote is never used to train or improve the model. You can avoid this transfer entirely by typing the figures in yourself instead of forwarding the email.
We do not sell your data, and we do not share it with advertisers.
How long we keep your data
storage limitsWe keep your data only as long as we need it. The security-log and usage-event ceilings below are fixed and enforced in code; the other periods state our current practice and this notice is updated if they change.
- While your account is active: we keep your account, property, and plan data so the service works.
- When you delete your account: we erase your personal data from the live database. Deletion is self-serve (see Section 5). If you have paid for a subscription, deletion also cancels the subscription and erases your live customer record at Stripe (your profile and saved payment details), so those details can no longer be used.
- Payment and accounting records: billing records are the one thing deletion cannot permanently erase. The Finnish Accounting Act requires us to keep accounting vouchers, such as invoices, for six years from the end of the financial year they belong to. So the transaction records of your past payments are kept for that period under a legal obligation (GDPR Art. 17(3)(b)). We keep them only because the law requires it and use them for nothing else.
- If you start signing up but do not pay: when subscriptions open, signing up creates an account before payment. If you do not complete payment, that account holds only the email, password, and country you entered. We keep it for at most 7 days, then delete it automatically.
- If you joined from the waitlist but never subscribed: your two free months keep working, and your account stays open afterwards. If you have not subscribed by twelve months after the free period ends, we delete the account. We email you a month before, so you can subscribe to keep it, or download a copy first.
- If you joined from the waitlist but never set up your home: the account holds only the email, password, and country you entered. If twelve months pass from the day you created it with no home registered, we delete it. The same warning email arrives a month before, and setting up your home keeps the account — your two free months start then.
- Contractor details you save (someone else's data): the name and one contact detail of a contractor you brief or keep to reuse are deleted automatically once you have not used that contractor for 24 months.
- Security logs (IP address, user-agent, session records): kept for at most 90 days from when they were collected, then automatically deleted.
- Usage events (the analytics in Section 6): kept for at most 24 months from when the event happened, then automatically deleted. If you delete your account sooner, the events tied to your account go with it.
- Backups: deleted data may remain in our encrypted backups for a short period until those backups rotate out, after which it is gone from the backups too.
- Waitlist emails: kept until you unsubscribe, or until a reasonable wind-down period after launch, then deleted.
- Newsletter subscriptions: if you subscribed to get the guides by email without joining the waitlist, we keep your email and, if you gave it, your country until you unsubscribe. Every guide email carries a one-click unsubscribe, and using it stops the emails.
Your rights
GDPR Art. 15–21Under the GDPR you have the following rights over your personal data. They are free to use, and we will respond within one month (we can extend by two further months for complex requests, and will tell you if we do).
- Access — get a copy of the data we hold about you (Art. 15).
- Rectification — correct data that is wrong or incomplete (Art. 16).
- Erasure — have your data deleted, the "right to be forgotten" (Art. 17).
- Restriction — ask us to pause processing in certain cases (Art. 18).
- Portability — get your data in a portable, machine-readable format to take elsewhere (Art. 20).
- Objection — object to processing based on our legitimate interests (Art. 21).
- Withdraw consent — where we rely on your consent (newsletter, waitlist), you can withdraw it at any time, without affecting processing done before you withdrew.
How to exercise them
- Download your data (access and portability): you can export everything appkeep holds about you from within your account ("Download my data"). It comes as a machine-readable JSON file.
- Delete your account (erasure): you can delete your account yourself from within your account ("Delete my account"). This erases your personal data from the live service, subject to the short backup window and the accounting-record retention in Section 4.
- Anything else (rectification, restriction, objection, withdrawing consent, or if the self-serve tools do not cover your situation): email privacy@appkeep.org and we will handle it.
Right to complain. If you think we have handled your data wrongly, you can complain to a data-protection supervisory authority. Because we are established in Finland, our lead authority is:
You can also complain to the supervisory authority in the EU country where you live or work, if that is not Finland. We would appreciate the chance to put things right first, but you do not have to ask us before you complain.
Cookies and analytics
cookiesappkeep keeps cookies to a minimum.
- Strictly necessary: when you sign in, appkeep sets one secure session cookie so you stay signed in. This is the only cookie appkeep sets, and it is set only at sign-in; visiting the site sets no cookie. The session cookie is required for the service to work, so it does not need your consent.
- Screen state inside your account: once you are signed in, your browser remembers a little screen state while the tab is open — which quotes you have already asked a contractor to firm up, so a card does not offer you the same thing twice. It is kept only until you close the tab, it holds no identifier, and nothing is put there before you sign in.
- Analytics is first-party, cookieless, and keeps nothing in your browser. To see how the product is used and improve it, we count page paths and basic events on our own servers, in our own database. Nothing is stored in your browser for this and nothing is read from it: no analytics cookie, no id kept on your device, no third-party analytics provider, no session recording. To tell one visit apart from another, our server turns your IP address and browser description into a short code, using a secret key it holds in memory and replaces each day it is used. Your IP address is not stored alongside these events, and once that key is replaced, the code cannot be traced back to you or matched to the next day. It builds no profile and it cannot follow you from one day to the next. The code groups a visit rather than identifying a person: people sharing one internet connection can land on the same code, and one person changing network gets a new one.
We do not use third-party advertising or tracking cookies. The lawful basis for this first-party, cookieless analytics is our legitimate interest in understanding how the public site is used (Art. 6(1)(f)). We store nothing on your device for analytics and read nothing from it, so there is no analytics banner to click. These events are deleted after 24 months (Section 4).
Objecting to the analytics. You have the right to object to processing based on our legitimate interests (Section 5), and we should be straight with you about what that can achieve here. Because these events carry no identifier that reaches you — no cookie, nothing on your device, and a visit code that stops being traceable when the day's key is replaced — we cannot find your events to single them out, and the usual way of honouring an opt-out would mean putting a marker on your device, which is the thing this design removes. So there is nothing we can suppress for you individually. What does work: a browser setting or extension that blocks the request stops these events being recorded at all. And once you are signed in the position changes — those events are tied to your account, so we can find them: email privacy@appkeep.org to have them deleted, or delete your account, which removes them with it (Section 4).
How we protect your data
securityWe take security seriously. Your data is hosted in the EU. Passwords are stored only as strong one-way hashes, never in plain text. Session tokens are stored hashed. Database backups are encrypted. The database is not exposed to the public internet, and access is limited. No system is perfectly secure, but we work to keep your data safe.
Changes to this notice
updatesWe may update this notice as appkeep grows or the law changes. If we make a significant change (for example, who controls your data, a new service provider, or a new purpose), we will update the date at the top and, where appropriate, tell you directly before the change takes effect.
Contact
privacy@appkeep.orgQuestions about this notice or your data: privacy@appkeep.org.
Controller: Rebel Strategy Lab Oy, Finland.