Privacy Policy

Last updated: 27 September 2026

Fjord Studio ("we", "us", "our") values your privacy. This Privacy Policy ("Policy") explains how we collect, use, and protect personal information when you use the KeepTies mobile application ("KeepTies" or "the app").

KeepTies is a personal-relationship CRM that helps you remember to stay in touch with friends and family. You add contacts, log interactions, set reminders, and can request AI-generated suggestions and message drafts.

Name change: KeepTies was called Orbit until September 2026. It is the same app, the same account and the same package name (com.fjordstudio.orbit); only the name changed.

This Policy explains what personal data KeepTies collects, why, who processes it on our behalf, how long we keep it, your rights, and how to contact us. KeepTies is available globally, including in the EU/EEA, so the EU General Data Protection Regulation (GDPR) applies. For users in the EU/EEA, Fjord Studio is the data controller. You can contact us any time at support@keepties.app.


1. Summary (the short version)


2. What data we collect and why

2.1 Account and profile data

Using KeepTies without an account (from version 3.2): you can use the app as a guest. Firebase then gives your installation an anonymous account identifier; no email address, name or password is collected. Everything you add is stored under that identifier exactly as it would be for an account, but it can only be reached from that phone: uninstalling the app or changing phone loses access to it. Guest accounts that hold no people and have not been opened for a week are deleted automatically. AI features, birthday cards and Premium require an account; when you create one, your data stays under the same identifier.

When you create an account, we collect and store:

Why: to create and operate your account, sign you in, show your profile, enforce subscription entitlements, and run app features.
Legal basis (GDPR): performance of our contract with you (Art. 6(1)(b)).

Public @handle: your chosen @handle is stored in a registry that maps the handle to your account identifier and is readable by any signed-in KeepTies user so the app can check whether a handle is available. Do not choose a handle you consider sensitive.

2.2 Contacts and relationship data you create

For each person you add, we store the information you enter:

Why: these are the core features of KeepTies — they let you remember details about people and remind you to reach out.
Legal basis: performance of our contract with you (Art. 6(1)(b)).

Note on sensitive data: free-text notes and life events can contain special-category data (for example health or grief information) about you or the people you add. You decide what to enter. Please only record what you are comfortable storing, and only information you have a lawful basis to keep about others (see Section 3).

2.3 Imported phone contacts (optional, with your permission)

If you choose to import contacts, KeepTies requests the READ_CONTACTS permission and reads, from your device address book, the display name, phone number, and email address of the contacts you select, plus a device contact lookup key. Selected contacts become contact records in KeepTies (name and phone number are saved; the lookup key is stored so the app can recognise the source contact).

Importing is entirely optional — you can use KeepTies by adding contacts manually and never grant this permission.

Why: to let you quickly add people you already know.
Legal basis: your consent (the Android permission prompt), and our legitimate interest in providing import functionality (Art. 6(1)(a)/(f)).

2.4 AI suggestions, drafts and the assistant

When you ask KeepTies to generate a nudge, draft a message or the text of a birthday card, or improve a message you wrote, the request is sent through our secure Google Cloud Function, which forwards a limited payload to our AI providers (OpenAI and/or Anthropic, see Section 4). The payload contains only:

For these requests, the contact's phone number, email, avatar, job, birthday, life events, and relationship type are not sent to the AI providers.

The assistant. When you chat with the in-app assistant, your messages in that conversation are sent the same way, together with a short list of up to 60 of your contacts so it can tell which person you mean. For each contact the list holds only the name and a one-line status: relationship type, days since you were last in touch, your check-in rhythm, whether a check-in is due, and days until their birthday. Notes, phone numbers, emails and other details are not included. The assistant can only propose an action, such as adding a reminder; nothing changes until you confirm it in the app.

Why: to generate the suggestion, draft or answer you requested.
Legal basis: performance of our contract with you (Art. 6(1)(b)).

We store a daily AI-usage counter on your account to enforce free/Premium limits. We do not store your prompts, your contacts' details, or the AI's responses on our servers; the generated text is returned to your device and not saved by our backend. Requests to OpenAI are sent with storage turned off, so they are not kept in OpenAI's request logs either.

2.5 Usage analytics

We use Firebase Analytics (Google Analytics for Firebase) to understand how the app is used. We log events such as: app open, sign-up/sign-in (with method: email or Google), the steps on the way into an account (sign-in screen shown, form sent, a fixed reason when it did not work, such as a wrong password, and whether the email verification code was sent, confirmed or abandoned), whether a saved login was used or a password was saved, sign-out, contact added (with relationship type), interaction logged (with type), AI nudge generated/viewed, paywall shown/dismissed, subscription started (with the plan and whether it began with a free trial), onboarding completed, and contact import started/completed (with a count). The sign-in events carry only fixed words, never your email address or password. The AI nudge events include a contact identifier parameter. Firebase Analytics also automatically collects standard device and usage data, including an app-instance identifier, the Android advertising ID where the device makes it available, app version, device type, and approximate location derived from IP address. KeepTies shows no ads: these identifiers are used only to count and understand usage, never for advertising.

Why: to measure feature usage and improve the app.
Legal basis: our legitimate interest in improving KeepTies (Art. 6(1)(f)).

2.6 Crash diagnostics

We use Firebase Crashlytics to receive automatic crash reports. These include crash stack traces, device model/OS, and a Crashlytics installation identifier. We do not attach your name, email, or user ID to crash reports.

Why: to detect and fix crashes.
Legal basis: our legitimate interest in app stability (Art. 6(1)(f)).

2.7 Subscription / purchase data

If you buy KeepTies Premium, the purchase is handled by Google Play Billing. Google processes your payment; KeepTies only reads the purchase state and a purchase token (used to confirm the purchase on your device) and records your resulting Premium status. So that a purchase can be matched to the right KeepTies account, the app also gives Google Play a one-way scrambled (hashed) version of your account identifier, which Google cannot turn back into your identifier, email or name. It is used only to match the purchase to your account and to help Google Play detect fraud. From version 3.2 the app no longer records your Premium status itself: our server checks the purchase with Google Play (Google Play Developer API) and stores the result on your account, and Google Play notifies our server of renewals, cancellations and refunds. For that purpose we keep the purchase token, the product bought and the expiry date. KeepTies never sees your card or payment details.

Why: to provide and manage your subscription.
Legal basis: performance of our contract with you (Art. 6(1)(b)).

2.8 On-device data (does not leave your device on its own)

Some data is kept locally on your device to run features: a home-screen widget cache (up to 3 contacts' name and status), reminder/notification data (contact name, phone number, reminder/message text) held while reminders are scheduled and shown, and the email address you last used to sign in with a password, so the sign-in screen can fill it in next time. That address stays on the phone when you sign out, and is removed when you delete your account in the app or uninstall the app. Local app data is excluded from Android cloud backup and device-transfer.

2.9 Birthday cards you send

If you send someone a birthday card, the card is published as a link that the recipient can open in a browser without an account and without the app.


3. A note about other people's data (contacts)

KeepTies lets you store information about other people (your friends and family). If you are in the EU/EEA, you remain responsible for the personal data you record about others and for having a lawful basis to do so. Please:

We act as the processor of this data on your behalf for the purpose of operating the app, and as controller for the limited platform-level data described above.


4. Who we share data with (processors and sub-processors)

We do not sell your personal data and do not share it for advertising. We share data only with the service providers ("processors") that power KeepTies:

ProviderRoleWhat it receives
Google Firebase / Google Cloud (Google) Authentication, database, serverless functions, analytics, crash reporting Your account identity and password (Auth); all profile and contact data you create (Cloud Firestore); the AI request relay (Cloud Functions); usage events and automatic device data (Analytics); crash reports (Crashlytics)
OpenAI (GPT) AI generation, primary provider (model: GPT-5.4 nano) At AI-generation time only: the contact's name, days since last contact, up to 5 of your notes, up to 5 recent interaction notes, an optional topic, and (for "improve") your draft message text; for the assistant, your messages and the contact list described in Section 2.4. Sent with storage turned off
Anthropic (Claude) AI generation, automatic fallback (model: Claude Haiku 4.5) The same AI payload as OpenAI, used only when OpenAI is unavailable, so a single AI request may be processed by OpenAI, Anthropic, or both
Google Play Billing (Google) Subscription payments Payment and subscription transaction data (handled entirely by Google Play)
Resend (Resend, Inc.) Transactional email delivery Your email address and the one-time verification code, at the moment we send you an account-verification email (sent from verify@fjordstudio.app). Nothing else about your account or contacts is shared

API keys for Anthropic, OpenAI, and Resend are stored securely in Google Cloud Secret Manager and are never embedded in the app.

We may also disclose data if required by law, to enforce our terms, or to protect the rights, safety, or property of our users or others.


5. International data transfers

KeepTies's AI relay (Cloud Function) runs in the EU (europe-west1). Other Google Firebase services (Firestore, Analytics, Crashlytics) and our AI providers (Anthropic and OpenAI) may process data on servers located outside the EU/EEA, including in the United States. Where data is transferred outside the EU/EEA, it is protected by appropriate safeguards such as the EU Standard Contractual Clauses and/or the providers' participation in recognised transfer frameworks, as offered by Google, Anthropic, and OpenAI in their respective data-processing terms.


6. How long we keep your data


7. Your rights and how to delete your data

Under GDPR (and similar laws) you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and the right to data portability. You can exercise most of these directly in the app:

To make any other privacy request — including access, correction, portability, or full erasure — contact support@keepties.app. We will respond within the timeframes required by law.

If you are in the EU/EEA and believe we have not handled your data properly, you have the right to lodge a complaint with your local data protection supervisory authority.

You can also withdraw the contacts permission at any time in your device's Android settings; this stops further contact imports but does not delete contacts you have already imported.


8. Security

We use Google Firebase's managed infrastructure. Data in transit is encrypted using HTTPS/TLS. Access to your database records is restricted by Firebase Security Rules so that, in normal operation, only you (when signed in) can read or write your own profile and contacts. AI provider keys are held in Google Cloud Secret Manager.

No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.


9. Children's privacy

KeepTies is not directed to children. It is intended for users aged 13 and over. We do not knowingly collect personal data from children under 13. Where your country sets a higher minimum age of digital consent (for example 16 in some EU countries), users below that age should only use KeepTies with the consent of a parent or guardian. If you believe a child under 13 has provided us with personal data, contact us at support@keepties.app and we will delete it.


10. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you in the app. Continued use of KeepTies after an update means you accept the revised policy.


11. Contact us

Fjord Studio
Email: support@keepties.app

Fjord Studio is a trading name of Langsæter Labs (org. no. 937939493, Norway), the data controller for KeepTies.

Last updated: 27 September 2026