Skip to main content

    Privacy Policy

    Last updated: September 2026 (rev. 18)

    1. Introduction & Controller Identity

    Welcome to Keypra ("we," "our," or "us"). Keypra is an AI fluency and knowledge management platform for the Human Layer of AI at work. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and the Estonian Personal Data Protection Act.

    Data Controller: Keypra OÜ Sepapaja tn 6, 15551 Tallinn, Estonia Registry code: 17502390

    Data Protection Contact: privacy@keypra.com

    This policy applies to all users of the Keypra platform, including our web application, API services, classroom and training features, and enterprise organisation features.

    2. Data We Collect

    We collect personal data in three categories:

    2.1 Data You Provide DirectlyAccount Data: Email address, display name, and password hash when you register. • Profile Data: Optional biography, avatar, experience level, and role preferences. • Content Data: Documents, prompts, context cards, and other content you create within Keypra. • Communications: Messages sent to our support team or within classroom sessions. • Consent Preferences: Your choices regarding data processing categories (see Section 5). • Organization Data: If you join an organization, your membership role, department, and usage activity within that organization.

    2.2 Content You Create • Documents, prompt libraries, workflow configurations, research canvases, and classroom submissions. • This content is stored to provide the core service and remains under your control. • Research canvases may be made publicly accessible via share links you generate (see Section 5a). • Zero-persistence workflow inputs: Workflow 'Your Context' inputs (pasted text, uploaded files, or fetched URL contents) are processed in-memory only for the duration of a single workflow run. They are never written to our database or object storage and are discarded immediately after the run completes.

    2.3 Data Collected AutomaticallyBehavioral Telemetry (consent-gated): Keystroke timing patterns, active typing duration, pause frequency, revision counts, thinking-to-typing ratios, and session duration. This data is collected to power the Crafting Fluency feature and is only gathered when you have granted "Behavioral Telemetry" consent. • Competence Retention (consent-gated): Periodic retention checks and spaced-repetition challenge data used to measure long-term skill retention. Collected only with "Competence Retention" consent. • Product Analytics (consent-gated): Feature usage events, model selections, execution times, and token consumption. Collected only with "Product Analytics" consent. • Documentation Analytics (consent-gated): Page views within the docs/learning section, referrer data, and session identifiers. Collected only with "Documentation Tracking" consent. • Technical Data (necessary): IP address, browser type, operating system, and device identifiers — collected for security, fraud prevention, and service delivery. IP addresses are retained only as part of the authentication/security log window described in Section 8 ('Authentication & security logs') — see that entry for the current retention period. • Authentication Logs: Login timestamps, IP address, and session metadata, retained for security purposes for the period specified in Section 8.

    2a. Billing & Invoicing Data

    When you purchase a paid plan, top-up, or capacity boost, the data needed to issue a compliant invoice is collected and held by our payment processor — not by Keypra. We have deliberately minimised the buyer information stored in our own database.

    2a.1 Personal purchases If you purchase as an individual, Stripe Checkout collects your name, billing address, and payment card details directly. Keypra retains only your account email and an opaque Stripe customer reference so we can match future invoices to your account. Your payment card number is never seen or stored by Keypra.

    2a.2 Company purchases (B2B) If you choose "Buying as → Company" at checkout, Stripe Checkout collects your legal company name, VAT/Tax identification number (where applicable), and registered billing address directly. Keypra does not store these fields in its own database — only the opaque Stripe customer reference is retained on our side. By proceeding, you represent that you are authorised to act for that legal entity and that the data you provide is accurate.

    2a.3 How this data is protected Because buyer billing data lives only inside Stripe, it is protected by Stripe's PCI-DSS Level 1 controls and Stripe's own GDPR programme. Keypra cannot read, export, or modify it from its own database, which materially reduces the GDPR attack surface compared to mirroring billing PII locally.

    2a.4 How this data is shared Stripe Payments Europe Ltd is the primary recipient of your billing data — they are both our payment processor and the controller-side keeper of the invoicing record on Keypra OÜ's behalf (see Section 6 and our Sub-Processors page). For Estonian statutory bookkeeping, invoice metadata is also shared with our accountant Xolo OÜ. Xolo OÜ is listed as a Sub-Processor on our Sub-Processors page (/legal/sub-processors) and is incorporated by reference into our Terms of Service §8. We do not share billing data with any other third party.

    2a.5 Retention and self-service Invoice records are retained by Stripe and Xolo for 7 years as required by the Estonian Accounting Act §12, even if you delete your Keypra account. You can view, update, or correct your billing details at any time via Settings → Billing → Manage in Stripe, which opens the Stripe Customer Portal. Updates do not affect already-issued invoices, which remain immutable as required by law.

    2a.6 VAT Number Validation Where you provide a business VAT registration number for reverse-charge invoicing (see Terms of Service §5.11), Keypra's payment processor Stripe verifies its validity against the European Commission's VAT Information Exchange System (VIES) on Keypra's behalf, at the time you provide the number and periodically thereafter. The legal basis for this processing is compliance with a legal obligation (Art. 6(1)(c) GDPR) — specifically, Keypra's obligation to apply VAT correctly under Council Directive 2006/112/EC. The VAT number, the verification result, and the check timestamp are logged and retained for 7 years, aligned with the invoice retention period under the Estonian Accounting Act §12 (see Section 8). If a VAT number is found invalid, Keypra may reclassify the account and adjust invoicing as described in Terms of Service §5.11.

    2b. Keypra by Email ("the email channel")

    Keypra can be used entirely by e-mail. You write to ask@in.keypra.com and Rafy, our AI assistant, replies with a prompt review, a persona draft, a lesson, a practice slot, a digest, or a help guide. This section explains that channel in full. It applies in addition to Sections 2, 3, 6 and 6b.

    2b.1 What we receive When you e-mail Keypra we receive whatever your mail client sends: your e-mail address, your display name, the subject line, the message body, any quoted text you leave in the reply, any attachment you choose to add, and the addresses of anyone you place in CC.

    2b.2 What we store, and for how long

    DataPurposeRetention
    Message metadata — hashed sender address, sender domain, subject, detected intent, message length, score, tokens used, delivery status, campaign sourceRouting, abuse prevention, service statistics24 months
    Inbound message bodySo a follow-up reply can continue the same conversation7 days, then hard-deleted
    Copy of the reply we sent you (HTML and text preview)So the message appears in your in-app inbox at /email-inbox30 days, then hard-deleted
    Email project — the prompt text you sent, each revision, scores and score historySo you can keep improving one prompt across several e-mails and open it later in the app30 days from the last activity in that project
    Thread membership and participant records — hashed addresses, consent state, join/leave eventsSo a colleague you invited can take part, and so you can see and remove participantsLife of the thread, then deleted with it
    Guide, nudge, reminder and digest send recordsSo we do not send you the same guide twice24 months

    We store your address as a cryptographic hash wherever we can, together with the domain part in clear text. Hashing is pseudonymisation, not anonymisation — see Section 8a.

    2b.3 Legal basesArt. 6(1)(b) GDPR — performance of a contract / pre-contractual steps: handling the request you actually sent us and replying to it. • Art. 6(1)(f) GDPR — legitimate interests: abuse prevention, per-sender rate limiting, spam and loop protection, and service statistics. Our interest is keeping a free-to-write-to inbox usable and safe; the impact on you is minimal because we keep only metadata for this purpose. • Consent: where you are not yet a Keypra user, we do not enrol you in the channel until you reply "I CONSENT". Cold-outreach messages remain governed by Section 6a and are unchanged by this section.

    2b.4 AI processing of your e-mail The content of your e-mail is processed by the same AI providers, under the same terms, as a prompt typed into the app. See Section 6 for the routing architecture and Section 6b for our commitment that your content is never used to train any model — ours or a provider's. Requests sent by e-mail consume credits exactly as in-app requests do.

    2b.5 E-mail is not a confidential channel E-mail is transported between mail servers with opportunistic encryption at best; Keypra cannot guarantee that a message is encrypted end-to-end before it reaches us. Do not send us, by e-mail, special categories of personal data (Art. 9 GDPR), health or biometric data, legally privileged or professional-secrecy material, or third-party confidential information. Use the signed-in application for anything sensitive. Where a customer operates in §203 StGB professional-secrecy mode, the email channel is outside the assured scope and must be switched off — see /legal/berufsgeheimnis.

    2b.6 Role addresses are refused To avoid processing mail sent to or from shared team mailboxes, Keypra refuses generic role addresses (for example info@, hr@, legal@, support@, no-reply@) as senders and as invited participants. Only individual work addresses can take part.

    2b.7 No tracking in our replies Replies from the email channel carry no open pixel and no click tracking, on any legal basis, regardless of any tracking preference you may have set. See Section 6a.

    2b.8 Your controls Reply STOP to leave the channel, WHO to see who is in a thread, REMOVE <address> to take a colleague out, PAUSE to stop reminders, and HELP or MORE to see everything the channel can do. Signed-in users can read the same conversations at /email-inbox and their email projects at /email-projects.

    2c. Colleagues You Invite Into an Email Thread

    You can bring a colleague into an email conversation by putting them in CC. Because that involves someone else's personal data, the following applies.

    What we do with their address. Keypra sends that person their own consent e-mail explaining what Keypra is and asking them to confirm before anything else happens. Until they confirm, we process only their address and the fact that an invitation is pending, on the basis of Art. 6(1)(f) GDPR (responding to an introduction made by an existing user, and doing so transparently). If they decline, or never reply, the invitation lapses and their address is deleted with the invitation record. If they confirm, they become a participant in that thread on the basis of Art. 6(1)(b).

    What they can see. A confirmed participant sees the thread they joined — the prompt being worked on and the replies from that point onward. They do not gain access to your account, your other threads, or your library.

    Your responsibility. You are responsible for having a lawful reason to introduce that person and to share with them whatever the thread contains. Do not CC anyone into a thread that includes personal data about third parties, client material, or anything your employer's policy would not allow you to forward.

    Managing participants. Reply WHO to list current participants and REMOVE <address> to remove one. Removal ends further delivery to them immediately. Any participant can also reply STOP to remove themselves.

    Shared mailboxes. Role and group addresses are refused, as described in Section 2b.6.

    3. Purposes and Legal Bases for Processing (Art. 6 GDPR)

    We process your personal data based on the following legal grounds:

    Processing ActivityLegal BasisGDPR Article
    Account creation & authenticationPerformance of contractArt. 6(1)(b)
    Document storage & retrievalPerformance of contractArt. 6(1)(b)
    AI-powered prompt executionPerformance of contractArt. 6(1)(b)
    Issuing invoices for paid plansPerformance of contractArt. 6(1)(b)
    Retaining invoice-linked billing data for 7 yearsLegal obligation (Estonian Accounting Act §12)Art. 6(1)(c)
    VAT number verification for reverse-charge invoicingLegal obligationArt. 6(1)(c)
    Behavioral telemetry collectionConsentArt. 6(1)(a)
    Competence retention checksConsentArt. 6(1)(a)
    Product analyticsConsentArt. 6(1)(a)
    Documentation trackingConsentArt. 6(1)(a)
    Marketing communicationsConsentArt. 6(1)(a)
    Organization usage reporting to org adminsPerformance of contractArt. 6(1)(b)
    Security monitoring & fraud preventionLegitimate interestArt. 6(1)(f)
    Legal compliance & record-keepingLegal obligationArt. 6(1)(c)

    Where we rely on consent, you may withdraw it at any time via Settings → Privacy without affecting the lawfulness of processing performed before withdrawal.

    Special Categories of Personal Data (Art. 9 GDPR). Keypra does not knowingly collect or process special-category data — namely data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning sex life or sexual orientation. You agree not to paste or upload such data into prompts, documents, context cards, or any other field. If you nonetheless do so, you act as the sole controller of that content, and Keypra processes it solely as a technical processor for the purpose of returning the requested AI output and storing the document under your account. We do not derive insights from, profile on the basis of, or share such content with any third party beyond the AI processing chain disclosed in Section 6.

    4. How We Use Your Data

    We use the collected data for the following specific purposes:

    Service Delivery: Operating the platform, processing AI requests, storing and retrieving your content, and managing your account. • Competence Assessment: When you opt into Behavioral Telemetry, we analyze your prompt crafting patterns to generate a personal Crafting Fluency score and competence assessments. This constitutes automated profiling (see Section 11). • Competence Retention: When you opt into Competence Retention, we generate periodic retention checks (spaced-repetition challenges) to measure your long-term skill retention and provide learning recommendations. • Product Improvement: Aggregated, anonymized analytics help us identify popular features, performance bottlenecks, and areas for improvement. • Classroom & Training: If you participate in training sessions, we process exercise submissions and session participation data to enable the learning experience. • Organization Administration: If you are a member of an organization, aggregated usage data (documents created, credits consumed, features used) is visible to your organization's administrators for the purpose of license management and ROI reporting (see Section 5a). • Marketing (consent-only): With your explicit consent, we may send product updates, feature announcements, and educational content. You can opt out at any time. • Security: We monitor for unauthorized access, abuse, and technical issues to protect the platform and its users.

    5. Consent and Privacy Controls

    Keypra implements a granular, five-category consent system that gives you fine-grained control over data collection. All five categories are opt-in: data is not collected unless you actively grant consent.

    Consent Categories:

    1. Behavioral Telemetry — Controls collection of keystroke patterns, typing ratios, and session crafting metrics. Required for Crafting Fluency and Verification features.
    2. Competence Retention — Controls collection of spaced-repetition retention check data and long-term skill tracking. Required for Retention Dashboard features.
    3. Product Analytics — Controls collection of feature usage events, model usage statistics, and performance data.
    4. Documentation Tracking — Controls collection of page view analytics within the learning/documentation sections.
    5. Marketing — Controls receipt of promotional communications and product announcements.

    How to Manage Consent: Navigate to Settings → Privacy to view, grant, or revoke any consent category at any time.

    12-Month Renewal Cycle: All consents are subject to a 12-month renewal period. When a consent approaches expiration, you will be prompted to re-confirm your preference. This ensures your choices remain current and intentional.

    Effect of Revocation: When you revoke a consent category, associated features become inaccessible (e.g., revoking Behavioral Telemetry locks the Crafting Fluency dashboard and Verification sidebar). You may also choose to purge all historical data associated with a revoked category.

    Consent Ledger: Every consent change (grant, revoke, renew) is appended to a separate, append-only consent_ledger table with a timestamp. The ledger stores a SHA-256 hash of your user id rather than the id itself, so the record remains demonstrable under GDPR Art. 7(1) even after you delete your account, without being usable to re-identify you. Ledger rows can be inserted only by the system trigger and read only by you (matched via the hash) or a Keypra administrator; nobody — including Keypra staff — can update or delete them. Entries are automatically purged after three years.

    5a. Organization Data Processing & Public Sharing

    Enterprise Organizations

    If you join a Keypra organization (either through an invitation or via a training group promotion), the following additional data processing applies:

    Data Visible to Organization Administrators: • Your display name, email address, and membership role within the organization. • Aggregated usage metrics: number of documents created, credits consumed, AI features used, and active days. • Organization library contributions you have published.

    Legal Basis: Performance of contract (Art. 6(1)(b)) — organization features are part of the enterprise service agreement between Keypra OÜ and your employer or institution. Your employer's organization administrator acts as a joint controller for organization-level usage data.

    Organization Policies: Your organization administrator may enforce policies that restrict certain platform capabilities, including: • Disabling external content sharing. • Requiring approval before publishing to the organization library. • Restricting data export capabilities. • Enforcing Bring-Your-Own-Key (BYOK) AI model configurations.

    Your Rights Within Organizations: • You retain full individual data rights (access, portability, erasure) as described in Section 9. • Leaving an organization removes your membership data; personal content created during membership remains yours. • Organization-level audit logs referencing your activity are retained per the organization's data retention requirements.

    Data Processor Relationship

    When you use Keypra as part of an Enterprise organisation, Keypra OÜ acts as a data processor for your employees' personal data, and your organisation acts as the data controller. Keypra processes this data strictly on your documented instructions, as set out in your Enterprise Agreement and the Data Processing Agreement (DPA) available at /legal/dpa.

    A signed copy of the Keypra Enterprise DPA is available upon written request at enterprise@keypra.com.

    Research Canvas Public Sharing

    Keypra allows you to create publicly accessible links to your Research Canvas content. When you generate a share link: • The shared canvas data (nodes, connections, synthesis results) becomes accessible to anyone with the link, including unauthenticated visitors. • View counts are tracked on shared links for your reference. • Share links have configurable expiry periods (24 hours to 30 days). • You are solely responsible for ensuring shared content does not contain personal data of third parties or confidential information.

    Reporting illegal content on shared canvases (DSA). If you encounter content on a publicly shared Keypra canvas that you believe to be illegal, you may report it under our Digital Services Act notice-and-action procedure at /legal/dsa-report (email legal@keypra.com, subject tag [DSA-REPORT]). The procedure, the information a notice should contain, and the redress available to affected users are described in Section 19 of the Terms of Service (/terms). When you submit a DSA report, Keypra processes the contact details you provide (and any other personal data contained in the notice) on the legal basis of Art. 6(1)(c) GDPR — compliance with a legal obligation under Regulation (EU) 2022/2065. Notice metadata is retained for the duration of handling plus 12 months for audit and statistical reporting, after which it is deleted or anonymised.

    Training Manager Access

    If you are enrolled in a training group, your training manager may access a read-only portal (via a secure access token) to view: • Your training progress and exercise completion rates. • Group-level aggregated performance data. • Training managers access this data without creating a Keypra account; their access is governed by a lightweight data access agreement presented at token activation.

    6. AI Processing and Infrastructure Providers

    Keypra uses third-party service providers to deliver core platform functionality, including infrastructure hosting, authentication, storage, AI processing, payment processing, and transactional email delivery.

    Current provider categories include:

    • Infrastructure and backend hosting services
    • AI model providers used to process prompts and generate responses
    • Payment processing providers
    • Transactional email delivery providers

    AI processing architecture: When you use AI-powered features, your request may be routed through Keypra backend services and an AI routing layer before being sent to the selected AI model provider.

    AI data handling:

    • Keypra does not use your Customer Data to train Keypra's own AI models.
    • Keypra sends only the content reasonably necessary to process your request.
    • Third-party AI providers process prompts and outputs under their own applicable service terms and data-processing commitments.
    • Where a provider states that API customer content is not used for model training by default, Keypra relies on that provider statement.
    • Where a provider offers additional retention controls, those controls apply only if they are available to Keypra and enabled for the relevant production environment.

    Zero-Persistence Workflow Inputs: Certain workflow node types — currently the 'Your Context' node — operate under a zero-persistence model. When you paste text, upload a file, or supply a URL through such a node, Keypra parses the content in an ephemeral edge function (parse-user-context), passes the resulting text into the AI request for that run, and immediately discards it. We log only the size of the input and the source label (filename or URL host), never the content. Parsing libraries (e.g. pdfjs-dist, mammoth) execute inside Keypra's own edge function and are not third-party services receiving the data.

    For a current list of providers and transfer safeguards, see the Sub-Processors page.

    6a. Email Engagement Tracking (Opens & Clicks)

    Keypra sends transactional emails (welcome messages, account notifications, invitations, receipts, security alerts), consent-based communications (weekly digests, feature announcements) and — for prospects who have not yet created an account — a limited amount of B2B outreach via Resend, our email delivery sub-processor. Outbound email from our operations portal (hq.keypra.com) is additionally covered by the outreach-specific notice at hq.keypra.com/privacy, which mirrors the retention and legal-basis rules stated here. Whether we may record when you open an email or click a link inside it depends on which of three legal bases the tracking rests on.

    Three tracking bases (per email, resolved at send time):

    BasisWhen it appliesOpensClicksWithdraw
    Consent — Art. 6(1)(a) GDPR + Art. 5(3) ePrivacyAny email to a signed-in user who has toggled 'Email open & click tracking' on, or a guest who explicitly opted in via the footer link.YesYesSettings → Privacy, or the footer link. Immediate.
    Legitimate interest — Art. 6(1)(f) GDPR (cold-outreach window)B2B prospect emails sent from a template classified as cold outreach (cold-*, outreach-*, prospect-*, campaign-*). Applies for a strict 90 days from the first-ever outreach send to that address, and only for open detection (to measure whether the prospect is reachable and interested). Never applies to click tracking. Never applies once the recipient becomes an account or opts out.YesNoOne-click footer link Manage email tracking preferences. Also closes the 90-day window permanently.
    NoneEverything else — auth/security emails, expired 90-day window, recipient opted out, recipient suppressed, or any missing/errored consent lookup.NoNoNothing to withdraw.

    Legal basis for bounces, deliveries and complaints (no consent required): Contract performance — Art. 6(1)(b) GDPR (necessary to deliver the emails you asked for) combined with legitimate interest — Art. 6(1)(f) GDPR (maintaining sender reputation and email deliverability). These events are recorded at the SMTP layer by our provider; no image or link on your device is involved, so ePrivacy Art. 5(3) does not apply.

    Cold-outreach legitimate-interest details (CNIL Deliberation No. 2026-042 §III.B, Garante Provvedimento No. 284/2026): For B2B outreach we rely on the balancing test in EDPB Guidelines 1/2024 on legitimate interest and the CNIL's 2026 pixel guidance, which accept open-only tracking within a short deliverability window when: (i) the recipient is contacted in a professional capacity, (ii) the sending organisation has a demonstrable interest (list hygiene, bounce management, unsubscribe honouring), (iii) clicks are not tracked, (iv) IP and user-agent are not stored, (v) every email carries a plain-language withdrawal link that does not require an account, and (vi) the window is time-limited. Keypra's window is 90 days from the first send; after that, further tracking requires opt-in consent. Historical opens under this basis are pseudonymised at 90 days and rolled into anonymous aggregate counts at 13 months (see Section 17).

    Auth emails are never tracked. Password resets, magic links, one-time codes and email-change confirmations do not carry an opens/clicks pixel, regardless of any consent granted or any outreach window. Firing a pixel on a security email would leak receipt timing and breach purpose-limitation.

    What is tracked when tracking is on:Email opens — A 1×1 image loads when you open the email and records timestamp + template name + a hash of your email address. Your IP address and user-agent string are never stored (data minimisation, applied to both consented and legitimate-interest opens). • Link clicks (consent only) — Links inside consent-based emails route via Keypra's own track.keypra.com subdomain and record the destination URL and timestamp before redirecting you. Cold-outreach emails do not carry click rewriting.

    Your rights — how to withdraw:In-app: Settings → Privacy → 'Email open & click tracking'. • Without logging in: every Keypra email — outreach included — has a footer link 'Manage email tracking preferences' that takes you to a one-toggle page (/email/tracking?token=…) — no login required. Turning tracking off there also permanently closes any active cold-outreach 90-day window. As required by CNIL 2026-042, withdrawing tracking is as easy as granting it; per Garante 284/2026 you can turn tracking off while keeping the email subscription intact. • Block remote images in your email client (Apple Mail, Gmail, Outlook) as a technical opt-out. • Historical event deletion at privacy@keypra.com or by disabling the toggle in the app (which purges your recorded events, including any legitimate-interest opens).

    Retention: Full detail 0–90 days for consent-based rows; pseudonymised 90 days – 13 months for consent-based rows; anonymous aggregate rollups thereafter. Legitimate-interest cold-outreach opens are hard-deleted at 90 days and only survive as anonymous aggregate counts. The cold-outreach ledger (first-send timestamp + hashed address, no email in clear) is deleted 3 years after the last outreach to that address, aligned with the CNIL's B2B prospection retention guidance.

    Default posture: New accounts default to email-tracking off. Emails sent before you make an active choice — including the welcome email — carry no tracking pixel or click rewrite. The cold-outreach LI window is the only case where opens can be recorded before you have made a consent choice, and never covers clicks.

    Replies from the email channel (Keypra by Email) are never tracked. Messages sent by Rafy in response to your e-mail carry no open pixel and no click rewriting, on any legal basis, irrespective of your tracking preferences. See Section 2b.7.

    6b. No AI Model Training on Your Content

    Keypra does not train, fine-tune, or improve any AI or machine-learning model — its own or anyone else's — on your prompts, outputs, uploaded files, Behavioural Telemetry, or any other Customer Content. This applies across every plan (Free, Learner, Builder, Expert, Enterprise) and every surface (Composer, Practice Lab, Research Canvas, Workflows, Classroom, Skills, BYOK).

    Sub-processor training posture. Where Keypra forwards prompts to a third-party AI provider to fulfil your request, we rely on each provider's enterprise/API terms which state that customer API content is not used to train the provider's models by default. The current posture of each AI sub-processor is recorded in §4b of the Sub-Processors page (/legal/sub-processors), reviewed at least annually, and re-checked promptly when a provider announces a material change.

    Behavioural Telemetry is excluded. Crafting Fluency typing-cadence metrics are computed only to render your own private dashboard and are contractually banned from being used to train models, profile workers, or inform employment decisions. See /compliance/behavioural-telemetry-methodology.

    Aggregated, anonymised improvement signals. We may use aggregated feature-usage statistics (which screens are popular, which errors occur, which models are selected) to improve the Service. These signals never include prompt text, output text, file contents, or any identifier that could re-identify you or your organisation.

    What this commitment means in practice: if you delete your account, no derivative model artefact exists that was built from your content — because no such artefact was ever created.

    6c. Machine-Readable Endpoints and Agent Connectors

    Keypra publishes a small number of machine-readable endpoints so that external AI assistants and agent runtimes can discover and use our public material. This section explains what personal data, if any, is involved.

    6c.1 Public MCP server and Agent Skills catalogue Keypra operates a read-only Model Context Protocol (MCP) server together with a public skills catalogue at /.well-known/agent-skills. These endpoints expose only material we have already published: curriculum lesson metadata and published Skill Forge packages. They expose no account data, no user-generated documents, no context cards, no classroom data, and no organisation data. No login is required and no personal data about you is disclosed through them.

    6c.2 Anonymous prompt analyser tool One MCP tool runs Keypra's prompt analyser without an account. The prompt text supplied by the caller is processed in-memory to produce the response and is not stored in our database or linked to any Keypra account. The calling client's IP address is processed solely to enforce a strict rate limit (2 requests per 24 hours per IP) and to prevent abuse of AI capacity. The legal basis is our legitimate interest in service protection and abuse prevention (Art. 6(1)(f) GDPR); rate-limit records are retained no longer than the abuse-prevention window described in Section 8.

    6c.3 Partner and agent authorisation (OAuth) Where a third-party client or agent connects to Keypra on your behalf, it does so through an OAuth-protected resource advertised at /.well-known/oauth-protected-resource. Access tokens are issued per authorised client, are scope-limited, and expire. A connected client can read or write only the data your own account is permitted to access under our access controls — it never receives credentials, BYOK keys, or data belonging to other users. You can revoke a connected client at any time by writing to privacy@keypra.com, which invalidates its tokens.

    6c.4 What we log For these endpoints we log the request path, timestamp, IP address, and outcome for security and rate-limiting purposes, on the same retention basis as the authentication and security logs described in Section 8. Prompt content submitted through the anonymous tool is not included in those logs.

    7. International Data Transfers

    Keypra OÜ is established in Estonia and its primary application infrastructure is hosted in the European Union.

    Some of our service providers process limited personal data outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, Keypra relies on an appropriate transfer mechanism under the GDPR, including the EU-US Data Privacy Framework where applicable and the European Commission's Standard Contractual Clauses where applicable.

    These providers may include AI model providers, payment processors, email delivery providers, analytics and advertising-measurement providers (including Google Analytics 4 and Google Ads, where Google Ireland Ltd / Google LLC relies on the EU-US Data Privacy Framework), and infrastructure-related service providers used to operate the platform.

    We do not state that all personal data always remains within the EU or the EEA. Instead, Keypra applies contractual, organisational, and technical safeguards designed to protect personal data during cross-border processing, including encryption in transit, encryption at rest, access controls, and audit logging.

    Keypra has carried out a Transfer Impact Assessment (TIA) under the EDPB Recommendations 01/2020 (the post-Schrems II framework) for the US-located sub-processors listed at /legal/sub-processors. The supplementary technical and organisational measures relied on — including TLS 1.2+, AES-256 at rest, pseudonymisation of telemetry, the practice of not attaching end-user identifiers to AI Gateway requests, and the Enterprise BYOK option — are summarised publicly in Section 4a of that page. EEA-based Enterprise customers may request the underlying TIA worksheet via privacy@keypra.com.

    You may request additional information about the transfer safeguards relevant to your data by contacting privacy@keypra.com.

    8. Retention Periods

    We apply the following retention periods, aligned with the principle of storage limitation (Art. 5(1)(e) GDPR):

    Data CategoryRetention PeriodBasis
    Account & profile dataDuration of account + 30 days after deletionContract
    Documents & contentDuration of account + 30 days after deletionContract
    Research canvasesDuration of account + 30 days after deletionContract
    Organization membership dataDuration of membership + 30 days after leaving orgContract
    Org library items published by userDuration of org membership; removed on departureContract
    Dormant free accountsWarning email at 5 months inactive; deletion at 6 months inactive (minimum 30 days after the warning); paid subscribers, org admins, protected roles and accounts under a Legal Hold are exemptStorage limitation (Art. 5(1)(e) GDPR)
    Behavioral telemetry (crafting_sessions)12 months from collection (automated weekly cleanup, Sundays 03:23 UTC)Consent + data minimisation
    Competence retention checks12 months from collection (automated weekly cleanup, Sundays 03:37 UTC)Consent + data minimisation
    Product analytics eventsRetained while consent is active; purged on revocation when you confirm the purge promptConsent
    Documentation analyticsRetained while consent is active; purged on revocation when you confirm the purge promptConsent
    Google Analytics 4 event & user data (aggregate, held by Google)2 months from collection, as configured on the propertyConsent
    Consent ledger records (pseudonymised, hashed user id)Up to 3 years from event (yearly cleanup)Legal obligation (Art. 7(1))
    Pseudonymised audit log entries (post-deletion)Up to 3 years (monthly cleanup)Legal obligation / legitimate interest
    Authentication & security logsRetained by our backend provider (Supabase) for the duration of their default audit window (typically up to 12 months), under their data-processing termsLegitimate interest
    AI request logsNot retained by sub-processors under our API agreementsN/A
    VAT verification log (VAT number, result, timestamp)7 years from checkLegal obligation (EU VAT Directive 2006/112/EC)
    Research Canvas share linksHonoured until the configured expiry (24 hours – 30 days); fully deleted 30 days after expiry (weekly cleanup)Contract

    Account Deletion: When you delete your account, all personal data is permanently removed within 30 days via our hardened deletion protocol, which covers all tables including learning progress, assessment history, retention schedules, organization membership records, org library contributions, competence assessments, research canvases, and organization-level audit trail entries. No orphaned PII remains. Audit-log entries referencing your activity are pseudonymised (your user id replaced with an anonymised reference) and retained for up to three (3) years (Art. 17(3)(b) GDPR), then automatically purged.

    Dormant Free Accounts (Inactivity Deletion). Free accounts that remain inactive for an extended period are removed under our storage-limitation policy. After 5 months of inactivity we send a warning email to the address on file; after 6 months of inactivity, and provided the warning was sent at least 30 days earlier, the account is permanently deleted using the same hardened deletion protocol as a self-initiated deletion. A single sign-in at any point resets the timer. Exemptions: accounts with an active paid subscription, organisation administrators, protected staff roles (admin, moderator, lecturer, content creator, learning admin, compliance steward), and any account placed under a Legal Hold under DPA §8b are excluded from inactivity deletion until the exemption no longer applies. This policy is stricter than the 24-month industry norm and reflects our data-minimisation posture.

    Consent Ledger After Account Deletion: The consent ledger stores a SHA-256 hash of your user id rather than the id itself. When you delete your account, the ledger row remains (pseudonymous) for up to three years so that Keypra can demonstrate lawful processing under Art. 7(1) GDPR; it cannot be used to re-identify you.

    Consent-Based Purge: When you revoke a consent category in Settings → Privacy, the revocation dialog offers a 'Delete historical data' option that, when confirmed, immediately purges the corresponding rows (e.g. crafting sessions for Behavioural Telemetry, analytics events for Product Analytics).

    8a. When Data Stops Being Personal Data

    Whether information is still personal data depends on context, not on labels. Following the European Commission's and the European Data Protection Board's approach to anonymisation, we treat derived data as anonymous only where re-identification is not reasonably possible — for us or for anyone else — taking account of cost, available technology and the time required.

    In practice this means that, before we treat a derived dataset as anonymous, we remove direct and indirect identifiers, report results only at a level of aggregation at which no individual can be singled out, and retain no key or mapping that would allow the result to be reversed. We do not attempt to re-identify such data, and we require the same of our sub-processors.

    Pseudonymised data is not anonymous data. Where your identifiers are replaced rather than removed — for example in audit and security records retained after an erasure request — that data remains personal data and stays protected by this Policy and by your rights under Section 9.

    Analytics measurement data, including data collected through Google Analytics 4 under the Analytics consent category, is treated as personal data under this Policy, notwithstanding the anonymisation safeguards described in Section 10.

    If a derived dataset does not meet the standard above, we treat it as personal data and apply the retention periods in Section 8 and Section 17 to it.

    Hashed e-mail addresses are pseudonymous, not anonymous. The email channel (Section 2b) stores sender and participant addresses as cryptographic hashes. Because the same address always produces the same hash and can therefore be re-identified by us, these records remain personal data and your Section 9 rights apply to them in full.

    9. Data Subject Rights (Art. 15–22 GDPR)

    Under the GDPR, you have the following rights:

    Right of Access (Art. 15): Request a copy of all personal data we hold about you. Use Settings → My Data (/settings/my-data) to view table-level metadata and export your full records as JSON. • Right to Rectification (Art. 16): Correct inaccurate or incomplete personal data via your profile settings. • Right to Erasure (Art. 17): Request deletion of your personal data. You can delete your account in Settings, which triggers our 30-day complete erasure protocol. • Right to Restriction (Art. 18): Request that we restrict processing of your data while a complaint or correction is pending. • Right to Data Portability (Art. 20): Export your data in a structured, machine-readable JSON format via /settings/my-data. • Right to Object (Art. 21): Object to processing based on legitimate interest. You can opt out of telemetry and analytics at any time via Settings → Privacy. • Rights Related to Automated Decision-Making (Art. 22): See Section 11 for details on profiling and your right to human review.

    Audit Logs and the Right to Erasure: When you exercise your right to erasure, Keypra deletes all identifiable personal data within 30 days. Audit log entries referencing your activity may be retained in pseudonymised form — with your personal identifier replaced by an anonymised reference — for up to three (3) years, where retention is necessary for legal compliance or legitimate security audit obligations (Art. 17(3)(b) and (e) GDPR). Keypra will inform you if this applies to your request.

    How to Exercise Your Rights — Service Level (Art. 12(3) GDPR): Most rights can be exercised directly within the Keypra platform (Settings → Privacy, Settings → My Data) and are fulfilled in real time. If the self-service flow fails or your request requires manual handling, contact privacy@keypra.com. The Data Protection contact at Keypra OÜ (Sepapaja tn 6, 15551 Tallinn, Estonia) will:

    Acknowledge receipt within 72 hours (one working day, excluding weekends and Estonian public holidays). • Complete the request within one (1) month of receipt. • Where a request is complex or we have received a high volume of requests, we may extend this period by a further two (2) months (three months total) and will tell you within the first month, with reasons. • If we decline to act, we will tell you why within one month and explain how to lodge a complaint with your supervisory authority (see Section 15) or seek a judicial remedy.

    No Fee: We do not charge a fee for exercising your rights, except in cases of manifestly unfounded or excessive requests.

    Exercising your rights from the email channel. If you use Keypra by Email (Section 2b), you can write to privacy@keypra.com from the same address, or reply STOP in any thread to leave the channel. On an erasure request we delete the thread records tied to your address, any stored inbound message bodies, the archived copies of our replies, your email projects and their revisions, and your participant records in threads you were invited into. Records we must keep for accounting or legal-defence purposes are listed in Section 17.

    10. Cookies and Local Storage

    Keypra uses the following cookies and browser storage mechanisms. Strictly Necessary and Functional technologies are first-party. Keypra also uses named third-party technologies — Google Analytics 4 (Analytics table below) and three advertising technologies (Marketing table below) — which load only after you grant the matching Analytics or Marketing consent (or not at all, if you decline or if a CCPA/GPC opt-out applies; see §16.3). You can manage cookie preferences at any time via the cookie consent banner, the Cookie Policy, or Settings → Privacy.

    Strictly Necessary (no consent required, Art. 5(3) ePrivacy):

    NameStoragePurposeLifetime
    sb-access-token, sb-refresh-tokenCookie (HTTP-only)Authentication session — keeps you signed in across page loadsSession / 7 days (refresh)
    keypra-consent-v2localStorageStores your cookie & telemetry consent choices so they are respected across sessions6 months (then re-prompted)
    sidebar:stateCookieRemembers whether your sidebar is collapsed or expanded7 days
    keypra-themelocalStorageStores your light / dark / system theme preferencePersistent until cleared
    cf_clearance, __cf_bmCookie (Cloudflare)Bot-mitigation challenge token issued by our infrastructure provider30 minutes – 1 year

    Functional — consent-gated (Behavioural Telemetry, Competence Retention, Product Analytics, Documentation Tracking):

    NameStoragePurposeLifetime
    keypra-crafting-session-idsessionStorageGroups typing-cadence events within a single composing session for Crafting FluencyTab session
    keypra-analytics-anon-idlocalStoragePseudonymous identifier used to deduplicate product-analytics events when you have granted Product Analytics consent12 months
    keypra-docs-sessionsessionStorageGroups documentation page views within a single visit when you have granted Documentation Tracking consentTab session

    Analytics — consent-gated, named third-party measurement technology:

    ProviderTechnologyPurposeLifetimeLoads when
    Google (Google Ireland Ltd / Google LLC)Google Analytics 4 (gtag.js, measurement ID G-Y8FE3QV5RG)Aggregate audience measurement — page views, sessions, traffic sources, approximate country/region, and non-identifying product-event counts_ga and _ga_* cookies, 2 yearsOnly after you grant Analytics consent; the script is removed and the _ga / _ga_* cookies are cleared immediately on withdrawal

    Google Analytics 4 is gated behind the Analytics consent category (not Marketing). IP anonymisation is enabled, Google Signals and ads personalisation are switched off on the property, granular location and device data collection is off, and Keypra never sends user IDs, e-mail addresses, prompt content, document content or organisation names to Google Analytics — only page paths, titles and aggregate event counts. Google Analytics event and user data is retained for 2 months on the property before Google deletes it. A read-only Google Cloud service account is used server-side to display these aggregated statistics inside Keypra's internal admin dashboard; it reads reports only and receives no additional personal data.

    Marketing — consent-gated, named third-party advertising technologies:

    ProviderTechnologyPurposeLifetimeLoads when
    Google (Google Ireland Ltd / Google LLC)Google Ads tag (gtag.js, AW-18144700120)Conversion tracking for paid-search and display campaignsad_storage/ad_user_data/ad_personalization cookies up to 13 monthsBase tag loads on every page load under Google Consent Mode v2 (default-denied); ad-storage cookies are only written once you grant Marketing consent
    LinkedIn (LinkedIn Ireland Unlimited Company)LinkedIn Insight Tag (Partner ID 10229937)Conversion tracking and campaign reporting for LinkedIn adsUp to 13 months (li_gc, lidc, bcookie, bscookie, UserMatchHistory, AnalyticsSyncHistory)Only after Marketing consent is granted; the script is removed and its cookies cleared immediately on withdrawal
    X CorpX (Twitter) Pixel (ID rcjxd)Conversion tracking and campaign reporting for X adsUp to 13 months (_twclid, personalization_id, muc_ads)Only after Marketing consent is granted; the script is removed and its cookies cleared immediately on withdrawal
    StripeCheckout fraud-prevention cookies (__stripe_mid, __stripe_sid)Fraud-prevention cookies set by Stripe only on the checkout page when you start a paid purchase1 year / 30 minutesCheckout page only, regardless of Marketing consent (necessary for payment fraud prevention)

    Server-side conversion reporting (X Conversion API). For signups that happen by e-mail — where no browser pixel can see them — Keypra may send X an anonymous conversion event (conversion type and timestamp only, no e-mail address or click ID). For web signups, the stored ad click ID (keypra_twclid, 30 days) is sent only when you granted Marketing consent, and is cleared on withdrawal.

    California residents and any visitor sending the Global Privacy Control (GPC) signal: the Google Analytics 4, Google Ads, LinkedIn Insight, and X Pixel technologies above are hard-disabled regardless of your Analytics- or Marketing-cookie choice — see §16.3. Full vendor detail, data categories, and international-transfer safeguards for these four technologies are published on the Sub-Processors page (§2a).

    One-click unsubscribe tokens. When we send you a transactional or nurture email, a single opaque token is stored server-side in our email_unsubscribe_tokens table to power the RFC 8058 one-click unsubscribe header. No browser cookie is set for this purpose.

    11. Automated Decision-Making and Profiling (Art. 22 GDPR)

    Keypra employs automated profiling in the following feature:

    Crafting Fluency & Competence Scoring When you have granted Behavioral Telemetry consent, Keypra analyzes your prompt crafting behavior — including typing speed, pause patterns, revision frequency, and thinking-to-typing ratios — to generate a personal Crafting Fluency score and competence assessments.

    How it works:

    1. Behavioral metrics are collected during prompt composition sessions.
    2. An AI model evaluates the metrics alongside your prompt content to produce a score and skill assessment.
    3. The results are displayed on your dashboard and used to personalize learning recommendations.

    Significance and consequences: This profiling is used to provide personalized feedback and track your skill development. It does not affect your access to platform features, pricing, or contractual terms. It is used solely for educational and self-improvement purposes.

    Your rights: • You may opt out at any time by revoking Behavioral Telemetry consent in Settings → Privacy. This disables the feature and locks associated UI elements. • You may request human review of any automated assessment by contacting privacy@keypra.com. • You may contest a specific score or assessment result.

    Prompt scores returned by e-mail. The score and feedback Rafy returns in the email channel (Section 2b) are educational feedback on a piece of text you wrote. They are not a decision about you, they produce no legal or similarly significant effect, and they are never used for eligibility, pricing, or employment-related outcomes.

    11a. Statement on Solely-Automated Decisions (Art. 22(1) GDPR)

    Keypra does not subject you to decisions based solely on automated processing — including profiling — which produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22(1) GDPR.

    Why our AI features are not Art. 22(1) decisions. Crafting Fluency scores, Competence Scoring rubric outputs, AI Literacy Index outputs, and Practice Lab grades are diagnostic feedback shown to you, the data subject. They do not gate access to the Service, do not affect pricing, are not shared with employers in identifiable form (see the employer-side classification ban), and cannot be used by Enterprise customers as the basis for hiring, promotion, discipline or any other employment decision (Terms §10a and DPA §8b prohibit this contractually).

    Safeguards we apply anyway (Art. 22(3) safeguards, applied voluntarily). Even though Art. 22(1) is not engaged:

    Right to human intervention. You may request a human reviewer for any AI-graded result by replying to the [CONTEST] row in the result panel or by emailing privacy@keypra.com. We acknowledge within 72 hours and resolve within one month. • Right to express your view. Your message can include the context, intent or constraints that the grader missed; the human reviewer reads it before regrading. • Right to contest the decision. If you disagree with the regrade, you may escalate to the Estonian Data Protection Inspectorate (see Section 15) or seek judicial remedy. • Published methodology. The rubric, pass mark, and assumptions are public at /compliance/competence-methodology, /compliance/fairness-methodology, and /compliance/ali-methodology.

    No Art. 22(4) special-category processing. None of these features rely on special-category data within the meaning of Art. 9(1) GDPR.

    Email channel. The same statement applies to the email channel described in Section 2b: no reply generated there constitutes a solely-automated decision within the meaning of Art. 22(1) GDPR.

    12. Children

    Keypra is not intended for individuals under the age of 16, in accordance with Art. 8 GDPR (age of digital consent). We do not knowingly collect personal data from children under 16.

    If we become aware that we have collected personal data from a child under 16, we will take steps to delete such information promptly. If you believe a child under 16 has provided us with personal data, please contact privacy@keypra.com.

    13. Security

    We implement robust technical and organizational measures to protect your personal data, including:

    Encryption at Rest: All data stored in our database is encrypted using AES-256. • Encryption in Transit: All data transmitted between your browser and our servers is protected by TLS 1.3. • Row-Level Security (RLS): Database access is enforced at the row level, ensuring users can only access their own data. • Access Controls: Role-based access controls limit internal access to personal data on a need-to-know basis. • Audit Logging: All data access and modifications are logged for security monitoring. • Incident Response: We maintain an incident response plan and will notify affected users and the relevant supervisory authority within 72 hours of becoming aware of a personal data breach (Art. 33 GDPR).

    For more details on our security practices, see /security.

    14. Changes to This Policy

    We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or for other operational reasons.

    Notification: • Material changes will be communicated via an in-app notification and/or email to registered users at least 30 days before taking effect. • The "Last updated" date at the top of this page will always reflect the most recent revision.

    Continued Use: Your continued use of Keypra after the effective date of changes constitutes your acknowledgment of the updated policy. If you do not agree with material changes, you may delete your account.

    Record of Processing Activities (Art. 30(2) GDPR): Keypra maintains an internal record of the processing activities carried out on behalf of its controllers and reviews that record whenever processing purposes, sub-processors, or retention periods change. It is made available to a supervisory authority on request.

    Severability: If any provision of this Privacy Policy is found unlawful, void, or unenforceable under applicable law, that provision will be interpreted so far as possible to achieve its original intent, or otherwise severed. The remaining provisions remain in full force and effect.

    15. Contact and Complaints

    If you have questions, concerns, or wish to exercise your data protection rights, please contact us:

    Data Protection Contact: Email: privacy@keypra.com Keypra OÜ Sepapaja tn 6, 15551 Tallinn, Estonia Tallinn, Estonia Registry code: 17502390

    Supervisory Authority: You have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

    Website: https://www.aki.ee/en Email: info@aki.ee Address: Tatari 39, 10134 Tallinn, Estonia

    You may also lodge a complaint with a supervisory authority in the EU Member State of your habitual residence or place of work (Art. 77 GDPR).

    Response Time: We aim to respond to all privacy-related inquiries within 30 days.

    Governing Law: This Privacy Policy is governed by Estonian law and the GDPR.

    15a. Personal Data Breaches (Art. 33–34 GDPR)

    Keypra maintains a documented breach-response procedure designed to meet the timelines set out in Articles 33 and 34 GDPR.

    Detection and triage. Suspected personal-data incidents are triaged by Keypra engineering within hours of detection. The triage record captures the time of detection, the affected systems, the categories of data and approximate number of data subjects involved, and the early containment steps.

    Notification to supervisory authority (Art. 33). Where a personal-data breach is likely to result in a risk to the rights and freedoms of natural persons, Keypra notifies the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where notification is delayed, the notification is accompanied by the reasons for the delay. The notification covers the nature of the breach, categories and approximate number of data subjects, likely consequences, and the measures taken or proposed to address it and to mitigate its effects.

    Notification to affected users (Art. 34). Where a personal-data breach is likely to result in a high risk to the rights and freedoms of natural persons, Keypra notifies the affected users without undue delay. The notification is sent to the email address of record, supplemented by an in-product status banner where appropriate, and uses clear and plain language describing the nature of the breach, the likely consequences, and the measures the user can take to mitigate adverse effects.

    Enterprise customers. Where Keypra processes personal data on behalf of an Enterprise customer (Controller), Keypra notifies that customer without undue delay so the customer can meet its own Art. 33/34 obligations. The corresponding contractual commitment is set out in the Data Processing Agreement at /legal/dpa.

    Recordkeeping (Art. 33(5)). All personal-data breaches — including those that do not trigger notification — are recorded in an internal breach register together with their facts, effects and the remedial action taken. The register is available to the Estonian Data Protection Inspectorate on request.

    Reporting a suspected incident. If you believe you have observed a personal-data incident affecting Keypra, please report it to security@keypra.com with subject tag [SECURITY-INCIDENT]. We will acknowledge within 24 hours.

    16. Jurisdiction-Specific Privacy Notices

    This Section supplements the rest of this Privacy Policy with notices that apply to data subjects located in specific jurisdictions. Where this Section conflicts with another part of the Policy, this Section prevails for users in the relevant jurisdiction. The matching contractual addenda are in Section 18 of the Terms of Service (/terms).

    16.1 United Kingdom

    Your rights mirror those described in Section 9 of this Policy and are governed by the UK GDPR (as retained by the Data Protection Act 2018). The relevant supervisory authority is the UK Information Commissioner's Office (ICO, ico.org.uk) — complain at https://ico.org.uk/make-a-complaint. International transfers out of the UK rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (s.119A DPA 2018). Keypra OÜ has not appointed a UK GDPR Article 27 representative and does not currently target the UK market; UK residents may contact privacy@keypra.com on any data-protection matter.

    16.2 Switzerland

    Your personal data is processed in accordance with the revised Swiss Federal Act on Data Protection (nFADP), in force since 1 September 2023. The relevant supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch). International transfers out of Switzerland rely on the Swiss Addendum to the EU Standard Contractual Clauses, with the FDPIC named as competent authority. Keypra OÜ has not appointed a Swiss representative under Article 14 nFADP; Swiss residents may contact privacy@keypra.com.

    16.3 United States — California (CCPA / CPRA)

    Keypra does not sell personal information for monetary or other valuable consideration, and does not share personal information for cross-context behavioural advertising. To honour this commitment, the Google Analytics 4 tag, Google Ads conversion tag, LinkedIn Insight Tag, and X (Twitter) Pixel described in §10 are disabled at the consent layer for visitors whose IP is geolocated to California and for any browser sending the Global Privacy Control (GPC) signal — meaning ad_storage, ad_user_data, and ad_personalization are denied for Google Ads, and the Google Analytics, LinkedIn and X scripts are not loaded (or are unloaded and their cookies cleared if already loaded), regardless of the user's analytics- or marketing-cookie choice.

    California residents may exercise the rights to know, delete, correct, opt out of sale/sharing, and non-discrimination by contacting privacy@keypra.com. Keypra will respond within 45 days, extendable by a further 45 days upon notice as permitted by Cal. Civ. Code §1798.130(a)(2). You may appeal a denied request within 60 days by replying to Keypra's decision; unresolved appeals may be referred to the California Privacy Protection Agency (CPPA, cppa.ca.gov) or the California Attorney General.

    16.4 United States — Other States

    Keypra extends equivalent rights (access, correction, deletion, portability, opt-out of sale and targeted advertising, right to appeal) to residents of every US state with a comprehensive consumer-privacy statute in force, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, Indiana, Tennessee, New Jersey, Minnesota, Maryland, Rhode Island, New Hampshire, Kentucky, and Nebraska, and any subsequently enacted state law. Requests may be sent to privacy@keypra.com; complaints may be filed with the relevant State Attorney General. The same Global Privacy Control honouring described in §16.3 applies wherever the signal is received.

    16.5 Canada — Quebec (Law 25 / Act 64)

    Keypra processes the personal information of Quebec residents in accordance with Act 64 / Law 25. The designated Privacy Officer under Article 3.1 is Ferenc Szilágyi, Director, Keypra OÜ, reachable at privacy@keypra.com. You have the rights to access, correction, deletion, data portability (Article 27, in force since September 2024), de-indexing or cease dissemination (Article 28.1), and withdraw consent. Automated decision-making transparency under Article 12.1 is addressed in Section 11 of this Policy in respect of Crafting Fluency analytics and Competence Scoring — you may request human review and contest any individual outcome at privacy@keypra.com. Privacy-incident notifications will be made to affected individuals and to the Commission d'accès à l'information (CAI, cai.gouv.qc.ca) as required.

    17. Retention Schedule at a Glance

    This Section consolidates the retention periods disclosed throughout this Policy into a single reviewer-friendly table. Where a row conflicts with a longer narrative passage elsewhere, the narrative passage prevails because it usually carries additional conditions (e.g. consent revocation, enterprise contract).

    Data categoryRetention periodLegal basisDeletion trigger
    Account & profile dataDuration of account + 30 daysArt. 6(1)(b) — contractAccount deletion
    User-created content (documents, prompts, cards, canvases)Duration of account + 30 daysArt. 6(1)(b) — contractAccount deletion or per-item delete
    Organisation membership recordsDuration of membership + 30 daysArt. 6(1)(b) — contractLeaving organisation
    Behavioural telemetry (crafting_sessions)12 months from collectionArt. 6(1)(a) — consentWeekly cron (Sun 03:23 UTC) or consent revoke
    Competence retention checks12 months from collectionArt. 6(1)(a) — consentWeekly cron (Sun 03:37 UTC) or consent revoke
    Product analytics eventsWhile Product-Analytics consent activeArt. 6(1)(a) — consentConsent revoke + confirmed purge
    Documentation analyticsWhile Documentation consent activeArt. 6(1)(a) — consentConsent revoke + confirmed purge
    Email engagement events (email_engagement_events) — tiered0–90 days: full detail (recipient, IP, link, payload). 90 days – 13 months: pseudonymised (raw email, IP, UA, payload removed; only hash, template, event type, link host, day, country kept). >13 months: rolled up into anonymous daily counts in email_engagement_daily; original row deleted. Users with active Marketing consent are exempt from the 90-day pseudonymisation for the duration of their consent.Art. 6(1)(f) — legitimate interest (deliverability + campaign analytics); Art. 5(1)(c)+(e) — data minimisation & storage limitationDaily cron 03:30 UTC (apply_email_engagement_retention) + per-event purge on account deletion
    Email unsubscribe suppression listIndefinite (until you re-subscribe)Art. 6(1)(c) — CAN-SPAM / RFC 8058 obligationManual re-subscribe request
    Authentication & session logsBackend provider default audit window (≤ 12 months)Art. 6(1)(f) — securityBackend retention policy
    Pseudonymised audit log entries (post-deletion)≤ 3 years from eventArt. 17(3)(b)/(e) — legal obligationMonthly cron
    Consent ledger (hashed user id)≤ 3 years from eventArt. 7(1) — accountabilityAnnual cron
    Stripe / Xolo invoice records7 years from invoice dateArt. 6(1)(c) — Estonian Accounting Act §12Statutory expiry
    VAT verification log (VIES check result)7 years from checkArt. 6(1)(c) — legal obligation (EU VAT Directive 2006/112/EC)Aligned with 7-year invoice retention (Estonian Accounting Act §12); periodic cleanup cron
    AI request payloads (prompt + response)Not retained by Keypra; sub-processor short-lived operational logs onlyN/ASub-processor expiry
    Workflow Your Context inputsZero — in-memory, discarded at end of runArt. 5(1)(c) — data minimisationImmediate on run end
    DSA notice metadataHandling duration + 12 monthsArt. 6(1)(c) — DSA Regulation (EU) 2022/206512-month cron
    Legal-acceptance ledger entriesDuration of account + 30 days; pseudonymised retention up to 3 yearsArt. 6(1)(c) — accountabilityAccount deletion + cron
    Research Canvas share linksUntil configured expiry (24 h – 30 d); deleted 30 d after expiryArt. 6(1)(b) — contractWeekly cron
    Manager-portal access tokensUntil token revocation or training-group expiryArt. 6(1)(b) — contractManual revoke / expiry
    BYOK audit eventsRetention disclosed at /docs/byok-architectureArt. 6(1)(f) — securityPer BYOK retention policy
    Email channel — inbound message body7 daysArt. 6(1)(b) — contractScheduled purge
    Email channel — archived copy of our reply (in-app inbox)30 daysArt. 6(1)(b) — contractScheduled purge
    Email projects — prompt text, revisions, scores30 days from last activityArt. 6(1)(b) — contractScheduled purge
    Email channel — thread metadata (hashed address, domain, subject, intent, counters)24 monthsArt. 6(1)(f) — service integrityScheduled purge
    Email channel — thread membership and participant recordsLife of the threadArt. 6(1)(b) — contractDeleted with the thread
    Email channel — guide, nudge, reminder and digest send records24 monthsArt. 6(1)(f) — avoiding duplicate sendsScheduled purge

    All retention periods are reviewed at least annually. Where applicable law sets a longer retention period (e.g. Estonian bookkeeping rules), that longer period applies.

    Email: privacy@keypra.com
    Address: Keypra OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia, Tallinn, Estonia