Last updated July 30, 2026
KeeperOS holds a detailed picture of your animals and your room. This page explains exactly what KeeperOS LLC collects, why, and what you can do about it.
The short version
We collect the minimum needed to run the service: your email, your timezone, and whatever you choose to record about your animals.
There are no advertising networks, no third party analytics, and no tracking pixels in KeeperOS. We do not sell or rent your data to anyone.
We use a small first-party attribution system to understand which public campaigns lead to accounts. It has no cookie, browser ID, local-storage ID, session replay, fingerprinting, or ad click ID.
Your husbandry records are visible only to you, unless you use a feature that deliberately shares one, like sending a transfer certificate.
You can download a copy of your data yourself at any time, from Export your data, or ask us to delete all of it.
This summary is here to be read. The full text below is what governs.
Your account. An email address, which is required to sign in and to send you confirmations and password resets. A password, which our authentication provider stores hashed. We never see it and cannot recover it for you. Optionally, a display name and a breeder logo image. Your timezone, detected from your browser the first time you sign in, so that a feeding logged at eleven at night lands on the right day. You can change or clear the display name, logo, and timezone in Settings.
What you record. Everything you enter about your collection: animals and their identifiers, names, species and morph, sex, weights and measurements, the rooms, racks, and enclosures you set up, care logs for feeding, water, cleaning, weighing, misting and UV, notes, photos, clutches and incubation readings, sale readiness and asking prices, reminders, and the files you upload through the CSV importer.
Technical records. Our hosting, database, and network providers keep standard server logs that include IP address, browser type, and timestamps. These exist for security, abuse prevention, and debugging. We do not use them to build a profile of you, and we do not run analytics software on top of them.
Limited first-party campaign information. When you arrive through a tagged public link, we may normalize the link's source, medium, campaign, content, partner, and referral code, plus a coarse referrer category such as a known site or "other." The context is signed by our server. We do not keep the full link or referrer URL, search terms, advertising click IDs, IP address, browser fingerprint, cookie, local-storage identifier, or session replay. If you create and confirm an account, one first-touch source record is attached to it; otherwise, public CTA and demo actions are counted only in daily aggregates.
Payment details. Checkout is live for paid plans. Stripe processes card details; they do not touch our servers. We store the Stripe customer and subscription references, plan and access status, and a paid-invoice ledger with invoice reference, amount, currency, and paid date.
No advertising, ever. No selling, renting, or trading your data. No third party analytics or tracking pixels. Our limited first-party attribution does not use cookies, local storage, session replay, fingerprinting, ad click IDs, or raw request URLs. No using your records, photos, or notes to train machine learning models. No sharing your collection with other KeeperOS users unless you take an action that shares it.
To run the service and show you your own records. To sign you in and keep your account secure. To calculate schedules, due dates, and growth charts. To send transactional email, meaning confirmations, password resets, and any reminders you switch on. To answer your support requests. To understand, in aggregate, which public campaigns lead to account creation and product activation. To investigate abuse or a security incident. To meet a legal obligation when one applies.
We do not send marketing email to your account address without asking you first.
KeeperOS runs on infrastructure we do not own, so a small number of service providers necessarily process data on our behalf. Each is bound to use it only to provide their service to us.
Beyond those, we will disclose data only if the law genuinely requires it, and we will tell you unless we are forbidden from doing so. If KeeperOS is ever sold or merged, your records would move with it, and you would get notice and the chance to delete your account first.
Some features exist to move a record to another person, and they do exactly that. When you send an animal to another keeper, a snapshot of that animal's record, including your breeder name and logo if you have set one, is shared with the recipient and becomes their copy. Claim links are single use and we store only a hash of the token, not the link itself.
Anything you type into the public demo account is visible to everyone and is deleted on a nightly reset.
Traffic is encrypted in transit. Passwords are hashed by our authentication provider. Every query is scoped server side to the signed in account, and the database carries row level security policies underneath that as a second barrier, so a mistake in one layer is not automatically a leak.
We will be honest with you: no system is perfectly secure, and KeeperOS is a young product. If we ever discover a breach affecting your data, we will tell you what happened, what was exposed, and what we are doing about it, without waiting to be asked.
We keep your records for as long as your account exists, because that is the point of a husbandry history. Delete an animal or a log inside the app and it is removed from your account immediately, though it may persist in encrypted backups for a short period before those roll off.
When you ask us to delete your account, we remove your records and uploaded files within thirty days, except anything we are legally required to retain. Backup copies age out on their own schedule shortly after. Your account's first-touch attribution record is deleted with the account. Aggregate campaign totals may remain because they no longer identify an account or person.
You can see and edit almost everything from inside the app. For the rest, write to support@keeperos.app from the address on your account and we will help with any of these:
a copy of the data we hold about you; correction of anything wrong; deletion of your account and its contents; or a question about how any of this works. We aim to respond within thirty days, and usually much sooner.
A self serve export has shipped: Export your data downloads your whole collection as one file, on every plan, and that page states plainly what the file does not carry. Photos are the notable omission today. Ask us if you want anything the export does not cover. It should never be hard to leave.
KeeperOS is for adults. You must be at least 18 to hold an account, the service is not directed at children, and we do not knowingly collect information from anyone younger. If you believe a minor has created an account, tell us and we will remove it.
KeeperOS is operated from the United States and your data is stored there. If you use the service from another country, you are asking us to process your information in the United States, where privacy law differs from your own.
If this policy changes we will update the date at the top and post the new version here. If the change is material, meaning it affects what we collect or who we share it with, we will tell you by email or in the app rather than quietly editing the page.
See also the Terms of Service, which cover the rest of the arrangement.
Questions about any of this? Write to support@keeperos.app. A person reads it.