Privacy
Last updated 10 September 2026. KeptShut is operated by Brandistries LLC. Contact: support@keptshut.com.
The short version: we collect your email, the hostnames you ask us to watch, and the findings we produce about them. We do not sell any of it. You can export or delete everything yourself, from your settings page, without emailing anyone.
What we collect
Because you gave it to us: your email address, your name if you enter one, and your password stored only as a bcrypt hash. If you sign in with Google we receive your Google account id, email, name and profile picture, and nothing else.
Because you asked us to watch something: the hostnames and domains you add, the proof-of-ownership records you publish, and the scan results, findings and fix prompts we generate about them.
Because the software runs: your IP address and browser user-agent on sign-in and on form submissions, kept for abuse prevention and rate limiting. Session records. A log of emails we sent you. An audit log of significant actions on your account.
If you connect a provider such as an AI, SMS or cloud account, we store that credential encrypted at rest with libsodium, and we request the narrowest permission that does the job. We never include it in an export. We never display it back to you.
We do not collect: payment card numbers, which go directly to Stripe and never touch our server. There is no advertising, no third-party analytics, and no tracking pixels anywhere on this site.
Why we are allowed to hold it
For your account and the scanning you asked for, because we need it to provide the service you signed up to. For security logs, rate limiting and abuse prevention, because we have a legitimate interest in keeping the service working and not being abused. For billing records, because the law requires us to keep them.
How long we keep it
- Account, sites and findings — until you delete your account.
- Session records — 30 days, then automatically removed.
- Rate-limit records — 2 days.
- Threat-intelligence indicators — IP addresses 30 days, domains 14 days, file hashes 90 days. These are about attackers, not about you.
- Email delivery log and audit log — kept, with your address redacted after deletion.
- Billing records — as long as tax law requires.
Who else sees it
We use a small number of processors, and only these: Hostinger (the server and its database, in the EU), Stripe (payments, so they see your billing details and we do not), Anthropic (we send the text of a finding to rewrite its fix prompt — a finding contains a hostname and a technical description, never your credentials), and Google (only if you choose to sign in with Google).
We do not send your data anywhere else. We will disclose data if a valid legal order compels us, and where we are permitted to tell you, we will.
Your choices, all self-serve
Export: Settings, then Download my data. One JSON file, immediately.
Delete: Settings, then Delete this account. Immediate and permanent.
Correct something: edit it in Settings, or email us.
One thing survives deletion: a record that a deletion happened, holding no personal data beyond the email domain. A security product that can erase its own audit trail on request would be a tool for covering tracks, so we do not build one.
Scanning, and the line we hold
KeptShut runs public checks — the same things any visitor or any search engine already does — against any hostname you add. Anything deeper, meaning anything active, authenticated or probing, runs only after you have proven you control that domain with a DNS record, a meta tag or a file. This is enforced in one shared authorisation check, and every refusal is written to an audit log. You are responsible for only pointing KeptShut at systems you own or are authorised to test.
Cookies
Two, both strictly necessary: a session cookie so you stay signed in, and a CSRF token so forms cannot be forged. No advertising or analytics cookies. Nothing to consent to, because there is nothing optional.
Children
KeptShut is not for anyone under 16. We do not knowingly collect their data.
Changes
If we change this in a way that matters, we will email you before it takes effect.
Questions
Do you sell my data?
No. We do not sell personal information and we do not share it for advertising. There is no advertising on KeptShut.
Can I get my data out?
Yes, immediately and without asking us. Settings, then Download my data. It exports as one JSON file.
Can I delete my account?
Yes, immediately and without asking us. Settings, then Delete this account. It removes your account, workspace, sites, scans, findings, monitors, badges and any connected credentials.
Where is my data stored?
On a single virtual private server in the European Union, operated by Hostinger. It is not replicated to other regions.
Privacy questions: support@keptshut.com. Security reports: security@keptshut.com.