Privacy Policy
The short version. Keepsake records what you and your family choose to tell it about your loved one's day, plus the questions she asks it, so that it can answer her warmly and accurately. It uses artificial intelligence to do this. Her data is used to run the service for your household — never to advertise, never sold, never used to train third-party AI models.
Keepsake uses AI. Answers spoken by the companion, daily summaries, morning briefings, and the alerts raised to the family are generated by artificial-intelligence models. They can be wrong. Anything important — medication, health, safety — must be verified by a person.
1. Who we are
Keepsake ("we", "us") is operated by [COMPANY LEGAL NAME], [REGISTERED ADDRESS]. We are the data controller for personal data processed through the Keepsake companion device and the family portal. You can reach us at [PRIVACY CONTACT EMAIL].
Keepsake serves two people at once, and this policy speaks about both: the resident — the person living with memory loss who talks to the companion — and the family members and carers who use the family portal on her behalf.
2. What Keepsake is — and is not
Keepsake is a voice companion and a shared family memory. It is not a medical device. It does not diagnose, treat, monitor, or predict any medical condition, and nothing it says is medical advice. It must never be relied on as a safety-monitoring, emergency, or care-replacement system.
3. The data we collect
From the resident's device
- Voice. What she says to the companion is captured by the device microphone and converted to text (see Section 5 on how listening works). The resulting transcript of each question and the companion's answer is kept. Raw audio is processed transiently for recognition and is not stored by Keepsake.
- Interaction records. When questions were asked, whether the companion declined to answer, and which memories it used to answer — kept so the family can see repetition patterns and so the record stays auditable.
From family members and carers
- Account details. Name, relationship to the resident, and email address.
- Care notes. Everything you log about her day — visits, meals, medication given, mood — typed or spoken into the portal.
- Household configuration. The people list (including whether someone has passed away), photographs you upload, the medication schedule, the wake word, listening mode, quiet hours, and portal-access settings.
- Corrections. When you correct an entry, the original is kept, marked superseded, and attributed; the correction is attributed to you.
Created by the system
- AI-generated content. Daily and weekly summaries, inferred facts, morning briefings, gentle-practice questions, and family-facing alerts, each labelled with its provenance and a trust score.
- Agent run logs. A record of every automated agent run — what it did, which tools it used, and whether it succeeded — kept for transparency.
- Technical data. Standard server logs (IP address, timestamps, request metadata) needed to operate and secure the service.
Much of this is health-adjacent and highly sensitive data about a person who may lack capacity to consent. Where consent is the legal basis, we rely on the resident's consent given while she has capacity, or on the authority of her legal representative, together with the legitimate interests of her household in coordinating her care. See Section 9 on your rights.
4. Our use of artificial intelligence
Keepsake is built on AI, and we want that to be unmistakable:
- The companion's spoken answers are generated by a large language model (currently Google's Gemini family), grounded in the memories your household has recorded.
- Background agents run automatically: one reviews the day and raises anything inconsistent to the family, one consolidates the day into summaries overnight, one composes her morning briefing, and one tunes how the companion phrases things. Every run is logged and visible in the portal.
- AI-generated entries are always labelled as such in the portal ("agent", "inferred", "day summary") and carry trust scores so they are never confused with first-hand records from a carer.
- Hard rules are code, not AI: the companion never asserts a visit from someone marked as passed away, and medication questions are answered only from the carer-maintained schedule.
- AI output can be wrong. Language models can misunderstand, omit, or invent. Trust scores and provenance labels exist so a person can always check the record. Do not rely on AI output for medication, health, financial, or safety decisions without human verification.
Your household's data is not used to train our AI providers' models. We send only what is needed to answer a given question or run a given agent, under contracts that prohibit the provider from using it for their own purposes. The only "learning" Keepsake does is within your household: versioned style notes about how the companion speaks, which you can read in the portal.
5. How listening works
- Wake word (default). The device listens locally for one word. Nothing is kept or transmitted until the word is heard.
- Open ear. If the household enables it, the device answers any question without a wake word. This processes more incidental speech; we keep only recognised questions, not ambient audio.
- Tap to talk. Listening is off until a carer taps the screen.
- Quiet hours silence listening on the schedule the household sets.
Speech recognition and speech synthesis may be performed by the device platform's speech services; audio handled by those services is governed by the platform provider's terms. Portal voice features (spoken notes, spoken corrections) work the same way and are attributed to the speaker.
6. What we use data for
- Answering the resident's questions warmly and accurately.
- Keeping the shared family record: the timeline, summaries, and alerts.
- Running the automated agents described in Section 4.
- Operating, securing, and debugging the service.
- Meeting legal obligations.
We do not use personal data for advertising, we do not sell or rent it, and we do not share it with data brokers. There is no third-party advertising or analytics tracking in the product.
7. Who can see what
- The resident hears answers drawn from the household record. She is never shown trust scores, alerts, corrections, or the portal. The portal is reachable from her device only through a spoken phrase followed by a PIN or biometric check.
- Invited family and carers see the full portal: timeline, provenance, trust scores, alerts, practice results, and agent logs. Only people the household invites have access, and they can be removed at any time.
- Service providers. We use Google Cloud (hosting and database, currently in the EU — europe-west1) and Google's AI services (model inference) as processors under data-processing agreements. They may not use the data for their own purposes.
- Authorities — only where the law requires it, and we will challenge overbroad requests.
8. Retention — and why corrections never delete
The household record is deliberately durable: corrections supersederather than erase, so the family can always see what was believed and when it was fixed. Superseded entries stay in the record, marked as such.
- Household records are kept while the household account is active.
- When the account is closed, all household data is deleted within [30/60/90] days, except where law requires longer retention.
- Server logs are kept for [LOG RETENTION PERIOD].
- A household administrator can request deletion of specific entries (Section 9), which removes them from the active record and from backups on the backup cycle.
9. Your rights
Depending on where you live (including under the EU/UK GDPR), the resident and each family member have the right to access, correct, export, restrict, object to, and delete their personal data, and the right to complain to a supervisory authority. For the resident, these rights may be exercised by her legal representative.
- Access and export: ask us at [PRIVACY CONTACT EMAIL]; the timeline is also readable in full in the portal.
- Correction: use the portal's correction flow, or contact us.
- Deletion: contact us; see Section 8 for how deletion interacts with the supersede model.
- Automated decision-making: Keepsake's AI does not make legal or similarly significant decisions about anyone. Alerts are suggestions to a human; a person always decides.
10. Security
- Data in transit is encrypted (TLS); data at rest is encrypted by our cloud provider.
- The resident's device holds one screen only; the portal is protected by a spoken phrase plus PIN or biometric check on her device, and by invited accounts elsewhere.
- Access within our team is limited to what operating the service requires, and production access is logged.
- No system is perfectly secure. If a breach affects your data we will notify you and the relevant authority as the law requires.
11. Children
Keepsake is designed for adult residents and adult family members. It is not directed at children under 16, and we do not knowingly collect their data.
12. International transfers
Data is hosted in the EU. Where a processor handles data outside the EU/UK, we rely on adequacy decisions or standard contractual clauses.
13. Changes to this policy
If we change this policy materially, we will notify the household through the portal and by email before the change takes effect, and keep prior versions available on request.
14. Contact
[COMPANY LEGAL NAME] · [REGISTERED ADDRESS] · [PRIVACY CONTACT EMAIL] · Data protection officer: [DPO NAME/CONTACT, if appointed].