This page describes what Kept actually stores and why, for the two different kinds of people it holds data about.
Two groups, and only one of them agreed to anything
Kept is a deal tracker for creators doing sponsored content. It holds data about two different kinds of people, and the difference matters:
Creators: people who created a Kept account. They agreed to Kept's use of their data by signing up.
Brand contacts: people who opened a pitch link a creator sent them. They never created a Kept account, never agreed to anything, and cannot opt out of a link a colleague forwarded them.
Below covers each group on its own terms, rather than folding the second into the first.
If you are a creator using Kept
Signing up creates an account tied to your email. From there, Kept stores what you put into it directly:
The deals you track. Brand, fee, currency, deliverables, deadlines, stage, and the notes and log entries you or Kept add as a deal moves.
The brands and research you keep, and the pitches you track in Outreach.
Usage-rights terms and licence windows you record against a deal, and the checks you log against them.
Invoices you generate. Once one is issued, Kept freezes its own figures (the fee, tax, and billing details at that moment) so a document a brand already has never silently changes.
Your profile and billing details. Name, contact details, billing address, and tax information, if you choose to fill them in.
The raw text of any brand email you paste into the deal parser. Kept keeps what you pasted, unedited, on the deal itself, so you can always check what Kept read against what the brand actually wrote.
Deleting a deal deletes its rows, including its logs, its usage-rights checks, and any pitch link and pitch-tracking data tied to it (more on that below).
If you opened a pitch link (you did not sign up for Kept)
The pitch page you opened already tells you: "The sender can see when this was opened." This is the fuller version of that.
A creator using Kept can send a link to a portfolio of work. When you open that link, Kept records:
That the link was opened, and when.
A city-level location for that open.
A device fingerprint, specific to that one link.
Which pieces of the portfolio you clicked.
Whether a video was played, and roughly how far, and which sections of the page you engaged with.
Two things about this are worth stating plainly, because most tracking does the opposite:
The location is city-level only, and your IP address is never stored.Kept reads a city and country that the hosting platform has already resolved before the request reaches Kept's code. It never receives, derives, or keeps the address itself for this purpose.
The device fingerprint is salted per link. If you open pitch links from two different Kept creators, those two events produce two unrelated fingerprint values. Kept has no way to tell, even with full access to its own database, that the same device opened both.
Kept also tries not to record automated opens (a colleague's email scanner prescanning the link, for instance) as if a person had looked. When that check can't tell either way, Kept does not count the open. It would rather miss a real one than invent one.
Retention: this data is deleted with the pitch link it belongs to, and a pitch link is deleted the moment the deal or outreach pitch it belongs to is deleted. There is no separate copy kept anywhere else.
What Kept never does
Kept never sends anything on its own. Nothing leaves without a creator pressing send, nothing is ever scheduled, and there is no Kept address any of it could come from. A creator who connects Gmail sends from their own account: the From header is theirs, the message sits in their Sent folder, and a brand replying replies to them. A creator who does not connect Gmail copies the pitch and sends it from their own inbox, and Kept records only what they tell it happened.
Kept never combines a brand contact's activity across different creators' pitch links into one profile. The per-link salt above is what makes that impossible, not just a policy against doing it.
If you connect Instagram
Connecting Instagram is optional and Kept works without it. If you do connect, you sign in through Facebook, because that is the only way Instagram lets an application read this. Kept then holds:
Your Instagram handle, your follower count, and your number of posts. These fill in your Kept profile so you do not have to type them.
Your Instagram account's ID, which is what Kept has to name in order to ask Instagram anything on your behalf.
An access token. It is stored where only Kept's server can read it, never your browser, and it expires after about sixty days.
When you ask Kept to find the brands you have worked with, the captions of your own recent posts are read and sent to Anthropic to pick out brand names. Those captions are not stored. Only the brands you choose to save are kept, in your own research, exactly as if you had typed them.
Kept never posts, never reads or sends your direct messages, and never touches your advertising. The permissions it asks for are the smallest set that lets it read your own profile and posts.
If you look up another creator, Kept reads their public posts, or public search results about them, to work out which brands they have worked with. It keeps the brand names it found against their handle for seven days, so searching the same creator again is instant. Their posts, captions and follower counts are not stored at any point.
That record belongs to your account, not to Kept generally. Nobody else can see it, it is not sold or shared, it is deleted when you delete your account, and it expires by itself after seven days. If you are a creator who has been looked up this way and you want anything held about you removed, write to hello@keptcreators.com and it will be deleted.
To disconnect, remove Kept from your Instagram or Facebook settings, or write to hello@keptcreators.com. Either way the token is deleted and the handle, follower count and account ID are cleared from your profile. Your deals, pitches and research are untouched, because they are yours and have nothing to do with Instagram.
The deal parser and Anthropic
When a creator pastes a brand email into Kept's parser, that text is sent to Anthropic's API to extract terms. The fee, deliverables, and other details a brand's email states. The pasted text is also stored, unedited, on the deal itself, so the creator can always compare Kept's reading against the source.
Who to contact
Kept is operated by Kept Creators.
For any privacy question, or to ask for your data to be removed, write to hello@keptcreators.com. That includes brand contacts: if a creator sent you a pitch link and you want the record of your visit deleted, that address reaches a person, and you do not need a Kept account to use it.
Kept Creators is a sole trader based in the United Kingdom, and is the data controller for everything described on this page. UK GDPR and the Data Protection Act 2018 apply.
Your rights, and how to use them
Under UK GDPR you can ask for a copy of what is held about you, ask for it to be corrected, or ask for it to be deleted. Email hello@keptcreators.com and it will be answered within a month.
If you are not satisfied with the answer, you can complain to the Information Commissioner's Office at ico.org.uk. You do not need to go through Kept first.
Who else touches this data
Kept runs on other companies' infrastructure. These are the ones that handle data covered by this page, and what each one receives:
Supabase: the database, sign-in, and image storage. Effectively everything described above is stored there.
Vercel: hosting. Requests pass through it, including the ones that record a pitch being opened.
Anthropic: receives the text of a brand email when, and only when, a creator uses the deal parser on it. Nothing else is sent, and it is not sent unless the creator pastes it.
Meta: only if you connect Instagram. Kept asks Meta for your handle, follower count and your own posts. Meta necessarily knows you connected, because you signed in through them. Nothing from Kept is sent to Meta: no deals, no fees, no brands you are pitching, and no pitch you have written.
Stripe: handles subscription payments if and when they are switched on. Card details go to Stripe and never to Kept.
PostHog: product analytics, on their EU servers. It receives which pages are opened and a short list of things that were done, such as “imported 40 rows” or “posted a note”. Once you are signed in those are tied to your account's ID; before that they are counted without any identifier at all. It does not receive your email, any brand name, any fee, or the text of anything you wrote. Clicks and page contents are not recorded, and there is no session replay. Kept sets no analytics cookies. Nothing is written to your device and nothing follows you between visits, which is also why this page has no cookie banner: there is no cookie to ask you about.