Privacy & Trust

How Keepsake protects your stories

Keepsake exists so families can preserve their memories. That goal only works if you trust us with your stories. This page explains in clear language how we keep your data under your control, and it complements the legal details in our Privacy Policy.

Summary at a glance

  • Projects are private by default. The owner controls family-member access and chooses whether to share an individual current Story through a revocable public link.
  • The owner can create one complete current Project ZIP from Settings, including readable Stories and original family media.
  • We invest in secure hosting, storage, payments, and email infrastructure so your family stories stay safe. We disclose the categories of services involved below.

You stay in control

  • A Project has one owner and may have family members. Only the owner can invite or remove family members.
  • Family members can help with Questions, Answers, Stories, and book content, but they cannot manage membership, public sharing, payment, export, or deletion.
  • Public sharing is off unless the owner explicitly shares a current Story.
  • Anyone with a shared Story or printed QR address can open it without an account and can forward the address. A QR recording is not restricted to people holding the book.
  • Cookie and tracking preferences are available at any time.

Access and export

  • Each Question email includes a private link where you can answer without creating an account.
  • From Settings, the owner can create one current Project ZIP with readable Stories, attribution, original family media, and a machine-readable manifest.
  • If a paid Order generated the current Publication's reader PDF, that PDF is included in the ZIP. Keepsake does not offer a separate PDF backup or export history.

Security that matches the story you are telling

Our technical stack is built on services with strong security track records, and we add our own controls on top.

  • Our hosting and network services provide encrypted connections and network-level attack protection.
  • Stories and attachments are kept in restricted database and object storage. Data is encrypted in transit and at rest, and access is restricted and audited.
  • Payments go through a specialist payment provider, and Keepsake does not store full card numbers.
  • Transactional emails such as prompts and login links are delivered through an email service with email security protocols in place.
  • An error-monitoring service helps us diagnose and respond to technical issues.
  • We use limited product analytics. Optional website analytics and advertising measurement activate only for the category you consent to, and you can withdraw that choice at any time. Product journey events remain limited to named actions and never include family content.
  • Production access is restricted to the operating work needed to support Keepsake.

Transparent support practices

  • Support access is restricted to the diagnosis and recovery work needed to help with your Project.
  • Deleting the whole Project removes retained recordings and stops their printed QR playback. Deliberate Project deletion requires a completed current export and a separate warning and confirmation when printed playback is affected. Editing or deleting a Story alone does not remove recordings retained for an already-paid book. Printed books cannot be recalled.
  • For privacy questions, contact support@makekeepsake.com.

Next steps

Review the formal language in our Privacy Policy. If you want a human conversation about how Keepsake protects your family, email support@makekeepsake.com.