Skip to content
Keystone

Privacy policy

Privacy policy for Keystone

Keystone is built to hold the most important things you have. So you deserve an equally clear answer to what we know about you, why we know it, who we share it with — and what we have deliberately made impossible for ourselves. Here is that answer, plainly.

1. Data controller

Keystone is operated by a Danish company registered in Denmark. The company is the data controller for the personal data processed when you use Keystone. Full registration details will be published here as soon as they are in place.

If you have questions about this policy or about your data, write to [email protected] — a human will answer. For security matters, write to [email protected].

CVR no. to follow at launch

2. What data we process

We process only what it takes to provide Keystone — and most of it you have chosen to add yourself. Here is all of it, group by group:

  • Your account: email address, password (stored as a cryptographic hash — we don't know it), name, phone number, language and time zone. You can optionally add your address, date of birth and CPR number. The CPR number is used solely to confirm a reported death; it is stored encrypted and always shown masked.
  • The contents of your Keystone: the items, documents and notes you add yourself. You decide what goes in, and it may include sensitive information — for example about health in the Medical category. All content is encrypted, and the most sensitive fields can be sealed in your browser before they are sent. Sealed fields we cannot read — that is the whole point.
  • Trusted contacts and invitations: name, email, phone number and relationship for the people you enter yourself. This is data about someone other than you. It is your responsibility to have a good reason to add it — and ours to protect it as well as we protect your own.
  • Payment: your plan, your purchases and your payment history. The card payment itself happens at Stripe — the card number is entered directly with Stripe and never reaches Keystone's servers.
  • Release and death: when a relative or funeral director reports a death, we receive the reporter's name and contact details together with documentation — typically a death certificate and photo ID. See section 4.
  • The family check-up: if you take the quiz, we store your answers and your result. Without an account they are anonymous; create an account afterwards and they are linked to it.
  • Technical data: IP address and browser type at sign-in, your active sessions and the audit log. If you enable push notifications, we store the push address your browser issues.
  • Partner offers: if you say yes to being contacted by a partner, we freeze your name, email and phone number in a snapshot, so you can always see exactly what the partner received — and under which consent.

We do not collect data about you from other sources, and we never buy data about you.

3. Why, and on what legal basis

Every purpose has its legal basis in the General Data Protection Regulation (GDPR). In plain language:

  • Providing Keystone — the account, the contents, the contacts, the payment and the release — is the contract between us (article 6(1)(b)).
  • Sensitive information you choose to store — for example about health — we process because you explicitly ask us to keep it (article 9(2)(a)). The most sensitive fields you can seal, so that not even we can read them.
  • Security — the audit log, sessions and abuse protection — rests on our legitimate interest in looking after your Keystone (article 6(1)(f)).
  • Partner offers happen only with your explicit consent (article 6(1)(a)), which you can withdraw for as long as the referral is open.
  • Bookkeeping records we keep because the Danish Bookkeeping Act requires it (article 6(1)(c)).

We send no newsletters and no marketing email. The emails you receive from Keystone are about your account: receipts, security alerts, invitations, reminders and the release.

4. Deceased persons

Keystone is about what happens when someone dies — so the deceased get their own section. In Denmark, the Data Protection Act protects information about deceased persons for 10 years after death, and we treat it with exactly the same care as everyone else's.

Documentation of a death — the death certificate and the reporter's ID — is handled in strict confidence. It is seen only by Keystone's administrators and used for one thing only: confirming or rejecting the death before a release can begin.

After a release, each trusted contact sees only what the owner chose to share with them — no more, no less. Every single access is written to the audit log.

5. Who we share with

We never sell your data, show no ads, and share nothing to make money from it. What we do share, we share to run Keystone — with processors bound by data-processing agreements, who may only process your data on our instructions:

  • Fly.io — runs the servers Keystone lives on (Frankfurt, EU).
  • Neon — the database where your encrypted data is stored (Frankfurt, EU).
  • Cloudflare R2 — the object storage for your documents (EU data residency).
  • Stripe — handles all payment. Your card number is entered directly with Stripe and is never stored with us (EU/US).
  • Postmark — sends our emails, for example receipts and security alerts (US).
  • Sentry — error monitoring. Receives technical error reports which we have configured to contain no personal data, cookies or IP addresses (US).
  • Apple, Google or Mozilla — only if you enable push notifications: the message is delivered through your browser's push service and never contains the contents of your Keystone.

Beyond that, your trusted contacts see what you choose to share with them. If you say yes to a partner offer, the partner receives your name, email and phone number — never the contents of your Keystone. And we only hand anything to public authorities if the law requires it.

6. Transfers outside the EU

Your data at rest — the database and your documents — lives in Frankfurt and does not leave the EU.

Three of our processors are American: Stripe (payments), Postmark (email) and Sentry (error monitoring). Transfers to them rest on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework and on the EU's standard contractual clauses (SCCs) where relevant.

If you use push notifications, messages are delivered via your browser vendor's push service (Apple, Google or Mozilla), which may process the push address outside the EU on the same basis.

7. How long we keep it

The ground rule is simple: we keep your data for as long as you keep your account — and you decide when it goes.

  • Your account and your Keystone: for as long as the account exists. Items and documents you delete disappear from your Keystone immediately and are removed for good when the account is deleted.
  • If you delete your account, you have a 30-day grace period. After that, the contents of your Keystone, your documents, trusted contacts, invitations, release documentation, sessions and notifications are permanently deleted, and the account is anonymised — name, email, phone number and CPR number are removed.
  • Bookkeeping records — your purchases and subscriptions — are kept for 5 years from the end of the financial year, as the Danish Bookkeeping Act requires. After an account deletion they carry no name or contact details.
  • The audit log technically cannot be edited or deleted — that is your guarantee that no access can be hidden. On account deletion we remove IP addresses and all personal data from the log; what remains is an anonymous skeleton of events.
  • Partner consents: the snapshot of what a partner received is kept as documentation of the consent and the disclosure — including after an account deletion.
  • Data exports: your export archive is automatically deleted from our servers 72 hours after it is built.

8. Your rights

The GDPR gives you a set of rights, and we have built the most important ones straight into Keystone, so you never have to file a request to use them:

  • Access and data portability: under Settings you can download a full export in open formats at any time — with your data, documents, audit log and the sealed fields, including an offline reader.
  • Rectification: you can correct all of your data yourself, directly in the app.
  • Erasure: you can delete individual items and documents immediately — or the whole account with a 30-day grace period.
  • Withdrawing consent: a partner consent can be withdrawn under My referrals for as long as the referral is open.
  • Restriction and objection: you can ask us to restrict processing, or object to processing based on legitimate interest — write to [email protected].

You can always complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark. We would rather hear from you first — we usually find a solution — but the right is yours:

The Danish Data Protection Agency — datatilsynet.dk →

9. Cookies

Keystone uses no tracking cookies, no third-party analytics and no ads. That is also why you see no cookie banner — there is nothing to decline. The cookies we do set are necessary for the service to work:

  • Sign-in: a cookie that remembers you are signed in, and a short-lived cookie while you complete two-factor sign-in.
  • Session: a technical session cookie that, among other things, protects forms against forgery (CSRF).
  • The family check-up: if you take the quiz without an account, a cookie remembers your result for 30 days so it can be linked to a new account.
  • Partner links: if you arrive at Keystone via a partner's page, a cookie remembers the referral for 30 days.

All cookies are our own, signed, and inaccessible to JavaScript on the page. None of them are used to follow you around the web.

10. Security

All traffic to and from Keystone is encrypted (TLS). In the database, your name, phone number, CPR number and the contents of your Keystone are encrypted field by field with AES-256-GCM, and the most sensitive fields can be sealed in your browser before they are sent — those we cannot read, no matter who asks.

On top of that: two-factor sign-in, an audit log that technically cannot be altered, EU hosting — and a release that requires documentation, manual verification and a 72-hour waiting period.

Read the full security story on the Security page →

11. Changes to this policy

We update this policy as the service or the law evolves. Material changes are announced by email or in the app before they take effect — we never change anything important in silence.