What appkeep holds about you, and the choices you have.
This notice explains what personal data appkeep collects about you, why, what we do with it, and the rights you have over it. We have kept it plain. Where the law needs a precise word, we use it and then explain it.
Last updated 11 July 2026appkeep is operated by Rebel Strategy Lab Oy, a limited company registered in Finland and based in Helsinki. For the data you give appkeep, Rebel Strategy Lab Oy is the data controller: the company that decides what is collected and why.
- ControllerRebel Strategy Lab Oy, Finland
- Business ID (Y-tunnus)3512742-3
- Registered address00600 Helsinki, Finland
- Data-protection contactprivacy@appkeep.org
appkeep currently runs as a product within Rebel Strategy Lab Oy. We intend to move it into its own company in the future. If that changes who controls your data, we will tell you before it happens and explain what it means for you (see Section 8).
We have not appointed a Data Protection Officer. For any question about your data, write to privacy@appkeep.org.
We collect only what we need to run the service and to do the job you came here to do. "Legal basis" is the lawful reason the GDPR allows us to process each kind of data.
| What we collect | Why we collect it | Legal basis (GDPR) |
|---|---|---|
| Account data — your email, a hashed (scrambled) version of your password, whether your email is verified, your country, and your household situation (for example: homeowner, or owner who lives elsewhere) | To create and secure your account, sign you in, and match cost and lifespan data to your country | Performance of a contract (Art. 6(1)(b)) — we need this to provide the service you signed up for |
| Sign-in and session data — a hashed session token, your IP address, and your browser and device description (user-agent) | To keep you signed in, keep your account secure, and protect the service from abuse | Legitimate interests (Art. 6(1)(f)) — keeping your account and the service secure |
| Property data — a name for your property, its country, type, year built, number of storeys, floor area. The street address you type for the Netherlands lookup is used to fetch floor area and year built — it is not stored | To build your home's maintenance profile, work out per-area costs, and act as your home's record (useful when you sell) | Performance of a contract (Art. 6(1)(b)) |
| Component, defect, mandate and plan data — the building components you record, the defects you report, the contractor mandates you generate, and the multi-year maintenance plan appkeep produces for you | To run the maintenance plan, the fix flow, and the mandate calculator: the product itself | Performance of a contract (Art. 6(1)(b)) |
| Contractor contact data — the name, one contact detail (email or phone), and trade of a contractor you brief or keep to reuse. This is data about someone else, which you give us | To let you brief a contractor, keep track of who you are waiting on, and offer a contractor you have used before when a similar job comes up | Legitimate interests (Art. 6(1)(f)) — running the repair job you started; we never contact the contractor ourselves and never share their details |
| Quotes you record — the figures from a contractor's quote you type in against a job: the total, warranty terms, the rate for extra work, whether they visited, what the quote covers, and the contractor's name. The name is data about someone else, which you give us | To lay the quotes for one job side by side against the fair price, so you can pick a contractor on the terms you set | Performance of a contract (Art. 6(1)(b)) for the figures; legitimate interests (Art. 6(1)(f)) for the contractor's name — we never contact them and never share it |
| Waitlist sign-ups — your email, and (if you gave them) your situation, country, and the problem that brought you | To let you know when appkeep opens and send the pre-launch updates you asked for | Consent (Art. 6(1)(a)) — you can withdraw it any time by unsubscribing |
| Newsletter and onboarding emails — your email and your subscription or opt-out preference | To send the emails you opted in to | Consent (Art. 6(1)(a)) — you can withdraw it any time |
Some data you give us is about other people — a contractor you brief. If you are one of them and want to know what we hold or have it removed, email privacy@appkeep.org. We explain this in full in the contractor data notice.
We do not intentionally collect special-category data (such as health or beliefs). Please do not put such information into free-text fields, for example a defect description.
We use a small number of service providers to run appkeep. They process data on our instructions, under contract. We keep the list short on purpose.
| Provider | What they do for us | Where |
|---|---|---|
| Hetzner | Hosting and the PostgreSQL database — this is where your account and property data live | Helsinki, Finland (EU) |
| Resend | Sends our account emails and, if you opted in, the newsletter | EU region |
| Dutch Kadaster / PDOK (BAG public register) | If your home is in the Netherlands, we look up its floor area and year built from this public government register so you do not have to type them in. Your address is sent to the register to do the lookup. This is a public register we query, not a provider acting on our instructions. | Netherlands (EU) |
Every provider we use hosts your data inside the EU. We do not sell your data, and we do not share it with advertisers.
We keep your data only as long as we need it. The security-log ceiling below is fixed and enforced in code; the other periods state our current practice and this notice is updated if they change.
- While your account is active: we keep your account, property, and plan data so the service works.
- When you delete your account: we erase your personal data from the live database. Deletion is self-serve (see Section 5).
- If you start signing up but do not pay: when subscriptions open, signing up creates an account before payment. If you do not complete payment, that account holds only the email, password, and country you entered. We keep it for at most 7 days, then delete it automatically.
- If you joined from the waitlist but never subscribed: your two free months keep working, and your account stays open afterwards. If you have not subscribed by twelve months after the free period ends, we delete the account. We email you a month before, so you can subscribe to keep it, or download a copy first.
- If you joined from the waitlist but never set up your home: the account holds only the email, password, and country you entered. If twelve months pass from the day you created it with no home registered, we delete it. The same warning email arrives a month before, and setting up your home keeps the account — your two free months start then.
- Contractor details you save (someone else's data): the name and one contact detail of a contractor you brief or keep to reuse are deleted automatically once you have not used that contractor for 24 months.
- Security logs (IP address, user-agent, session records): kept for at most 90 days from when they were collected, then automatically deleted.
- Backups: deleted data may remain in our encrypted backups for a short period until those backups rotate out, after which it is gone from the backups too.
- Waitlist emails: kept until you unsubscribe, or until a reasonable wind-down period after launch, then deleted.
- Newsletter subscriptions: if you subscribed to get the guides by email without joining the waitlist, we keep your email and, if you gave it, your country until you unsubscribe. Every guide email carries a one-click unsubscribe, and using it stops the emails.
Under the GDPR you have the following rights over your personal data. They are free to use, and we will respond within one month (we can extend by two further months for complex requests, and will tell you if we do).
- Access — get a copy of the data we hold about you (Art. 15).
- Rectification — correct data that is wrong or incomplete (Art. 16).
- Erasure — have your data deleted, the "right to be forgotten" (Art. 17).
- Restriction — ask us to pause processing in certain cases (Art. 18).
- Portability — get your data in a portable, machine-readable format to take elsewhere (Art. 20).
- Objection — object to processing based on our legitimate interests (Art. 21).
- Withdraw consent — where we rely on your consent (newsletter, waitlist), you can withdraw it at any time, without affecting processing done before you withdrew.
How to exercise them
- Download your data (access and portability): you can export everything appkeep holds about you from within your account ("Download my data"). It comes as a machine-readable JSON file.
- Delete your account (erasure): you can delete your account yourself from within your account ("Delete my account"). This erases your personal data from the live service, subject to the short backup window in Section 4.
- Anything else (rectification, restriction, objection, withdrawing consent, or if the self-serve tools do not cover your situation): email privacy@appkeep.org and we will handle it.
Right to complain. If you think we have handled your data wrongly, you can complain to a data-protection supervisory authority. Because we are established in Finland, our lead authority is:
You can also complain to the supervisory authority in the EU country where you live or work, if that is not Finland. We would appreciate the chance to put things right first, but you do not have to ask us before you complain.
appkeep keeps cookies to a minimum.
- Strictly necessary: when you sign in, appkeep sets one secure session cookie so you stay signed in. This is the only cookie appkeep sets, and it is set only at sign-in; visiting the site sets no cookie. The session cookie is required for the service to work, so it does not need your consent.
- Analytics is first-party and cookieless. To see how the product is used and improve it, we count page paths and basic events on our own servers, in our own database. This measures how the site is used without identifying you, and builds no profile. There is no third-party analytics provider, no session recording, and no analytics or advertising cookie. The only thing kept in your browser is a temporary anonymous id for your current visit; it carries no personal data, sits outside any cookie, and clears when you close the tab.
We do not use third-party advertising or tracking cookies. The lawful basis for this first-party, cookieless analytics is our legitimate interest in understanding how the public site is used.
We take security seriously. Your data is hosted in the EU. Passwords are stored only as strong one-way hashes, never in plain text. Session tokens are stored hashed. Database backups are encrypted. The database is not exposed to the public internet, and access is limited. No system is perfectly secure, but we work to keep your data safe.
We may update this notice as appkeep grows or the law changes. If we make a significant change (for example, who controls your data, a new service provider, or a new purpose), we will update the date at the top and, where appropriate, tell you directly before the change takes effect.
Questions about this notice or your data: privacy@appkeep.org.
Controller: Rebel Strategy Lab Oy, Finland.