Privacy Policy
Last updated: September 2, 2026
Effective: September 2, 2026
This policy explains what data Keepr collects, why we collect it, and the choices you have. It applies to keepr.ru, the Keepr apps, and our on-premises offering unless your organization has a separate agreement.
01What we collect
Account information you give us: your name, email address, and a hashed password. Content you create: time entries, projects, tasks, clients, tags, and workspace settings.
We also collect limited technical data — the IP address and browser your sign-ins and security-relevant actions come from — which your organization's audit log records. Payment details go directly to our payment processor; Keepr never stores card numbers.
02How we use your data
We use your data to run the service: syncing timers across devices, generating reports, sending transactional email (verification, password resets, invitations, digests you have enabled), and providing support.
We do not sell personal data and we do not use your content for advertising.
03Legal bases
We process data to perform our contract with you (running your account and workspaces), for legitimate interests (security and fraud prevention), and with your consent where required — for example, the optional email digests you can switch on in your profile.
04Sharing
We share data only with subprocessors that help us operate Keepr: cloud hosting, email delivery, and payment processing. Each is bound by a data-processing agreement.
Within your organization, owners, admins and workspace managers can see time entries logged in their workspaces — that is the product working as designed. We never reveal activity from one organization to another: even a timer conflict across organizations is reported as a count, never as a name.
05Data retention
Your data stays as long as your account is active. Items you archive — entries, projects, clients, tags, workspaces, members — are retained so historical reports stay correct, and can be restored.
When you ask us to delete your account, we remove your personal data and confirm when it is done. Encrypted backups age out on their own schedule.
06Your rights
You can access, correct, export or delete your data by emailing support@keepr.ru, and you can change your name, email, password, language and timezone yourself in your profile at any time. Depending on where you live, you may also have rights to restrict or object to processing, and to lodge a complaint with a supervisory authority.
07Security
Passwords are stored as argon2 hashes, never in plain text, and password-recovery and email-verification links are single-use and expire. Sessions live in HttpOnly cookies, never in browser storage a script can read, and every state-changing request carries a CSRF token.
Data is encrypted in transit. Access to production systems is role-restricted and logged. Your organization's audit log records sign-ins, permission changes, policy changes and report exports.
08International transfers
Where data leaves the EEA, we rely on Standard Contractual Clauses and equivalent safeguards. On-premises deployments keep all data inside your own infrastructure.
09Contact
Data-protection questions: support@keepr.ru.
Revision history