Privacy policy
Who is responsible
To be published: the company operating Twokeep and how to reach it.
What we cannot see
Your photos and videos, their titles, request notes and mood tiles are encrypted on your phones before upload. We store them encrypted and cannot decrypt them. We do not hold a key that would let us, or anyone we hand data to, open them. See the security page for how this works and where it stops.
What we process
Encryption protects media content; it does not mean the service sees nothing about you. To run Twokeep we process necessary account and operational metadata:
- Accounts and pairing: your account, the Apple or Google identity you sign in with, your data region, and which accounts share a vault.
- Devices: your enrolled phone and how strongly its hardware was verified.
- Stored objects: the size, checksum and state of each encrypted file.
- Requests and timing: when viewing requests, approvals and refusals are made.
- Viewing and security events: viewing sessions, playback-started reports, capture incidents, removals and device changes, shown to both members of a vault.
- Billing: subscription state from the App Store or Google Play. Billing data never contains vault content or keys.
- Requests you send us: account deletion requests and reports, with the contact details you give.
We keep this to what the service needs. The purpose and legal basis of each category are to be published.
Where data is stored
Account and vault information is stored in the European Union. Encrypted media is stored either in the EU or in the United States, depending on where the account that created the vault was registered, and does not move after that. Further details, including service providers, are to be published.
How long we keep it
To be published: retention periods for each category, including backups.
Your rights
To be published. You can already ask us to delete your account.
Contact
Questions about privacy: [email protected].