Privacy & Trust
How Keepsake protects your stories
Keepsake exists so families can preserve their memories. That goal only works if you trust us with your stories. This page explains in clear language how we keep your data under your control, and it complements the legal details in our Privacy Policy.
Summary at a glance
- Projects are private by default. The owner controls family-member access and chooses whether to share an individual current Story through a revocable public link.
- The owner can create one complete current Project ZIP from Settings, including readable Stories and original family media.
- We invest in secure hosting, storage, payments, and email infrastructure so your family stories stay safe. The vendors we work with appear in the sections below.
You stay in control
- A Project has one owner and may have family members. Only the owner can invite or remove family members.
- Family members can help with ordinary Questions, Memories, Stories, and book content, but they cannot manage membership, public sharing, payment, export, or deletion.
- Public sharing is off unless the owner explicitly shares a current Story.
- Cookie and tracking preferences are available at any time.
Your stories are always accessible
- Questions are sent by outbound email with a private, account-free answer link. Answers are submitted through that link, not by replying to the email.
- From Settings, the owner can create one current Project ZIP with readable Stories, attribution, original family media, and a machine-readable manifest.
- If a paid Order generated the current Publication's reader PDF, that PDF is included in the ZIP. Keepsake does not offer a separate PDF backup or export history.
Security that matches the story you are telling
Our technical stack is built on services with strong security track records, and we add our own controls on top.
- Keepsake runs on Cloudflare, which provides secure connections and network-level attack protection.
- Stories and attachments are stored in Postgres (accessed through Drizzle ORM) and Cloudflare R2 object storage. Data is encrypted in transit and at rest, and access is restricted and audited.
- Payments go through Stripe, so card details never touch Keepsake servers.
- Transactional emails such as prompts and login links are delivered via Resend, with email security protocols in place.
- Error monitoring runs through Sentry, which lets us respond quickly to issues.
- Product analytics run through PostHog, Google Analytics, and Ahrefs. Advertising measurement uses Meta and Reddit. These optional providers activate only for the category you consent to, and you can withdraw that choice at any time.
- Production access is restricted to the operating work needed to support Keepsake.
Transparent support practices
- Support access is restricted to the diagnosis and recovery work needed to help with your Project.
- Deliberate Project deletion requires a completed current export. If deletion affects printed playback, Keepsake shows a separate prominent warning and confirmation.
- For privacy questions, contact support@makekeepsake.com.
Next steps
Review the formal language in our Privacy Policy. If you want a human conversation about how Keepsake protects your family, email support@makekeepsake.com. We keep our own family memories here, so we are committed to keeping yours safe too.