Privacy Policy for Kept
Privacy summary: Kept processes notification history on your Android device. The developer does not receive, upload, sell, or share your notification data. Kept contains no advertising or analytics SDKs and does not operate a backend server.
1. About this policy
This Privacy Policy explains how the Kept Android application (package name com.xapp.waveleap.msgrec), developed by Longdabo, accesses and handles information. Kept helps you keep and search a local history of notifications and identify messages that may have been deleted or recalled.
2. Information Kept accesses and stores
If you voluntarily enable Android notification access, Kept can access and store information contained in notifications received on your device, including:
- the name and package identifier of the app that posted a notification;
- notification titles, message text, expanded text, conversation titles, people fields, and timestamps;
- notification deletion or recall status; and
- your in-app preferences, such as filtering, theme, screenshot protection, and app-lock settings.
If you choose the app-discovery feature in Settings, Kept reads the installed apps visible to it through Android and saves their names and package identifiers locally so you can manage notification filters. You can also import a password-protected ZIP backup you select; its notification records and app names are added to Kept's local database.
Notification content may include personal or sensitive information sent by other apps or people. Kept only processes this content to provide the notification-history, search, filtering, statistics, and deleted-message detection features you choose to use.
3. Permissions and device features
- Notification access: lets Kept read notifications and detect when notifications are removed. You can revoke this access at any time in Android settings.
- Post notifications: lets Kept show optional alerts, including deleted-message alerts.
- Biometric/device authentication: may be used for the optional app lock. Authentication is handled by Android; Kept does not receive or store biometric templates or biometric data.
- Notification listener: Android runs Kept's notification listener after you grant notification access. You can turn off recording in Kept or revoke access in Android settings.
4. Local processing and storage
Kept stores its database and preferences in the app's private storage on your device. The app disables Android cloud backup. On some Android devices, a user-initiated device-to-device transfer may still copy app data to a new device. Kept does not sync data to a developer server and does not remotely collect notification content, device identifiers, IP addresses, usage analytics, crash reports, location, contacts, or advertising data.
5. Sharing and third parties
Kept does not automatically transmit your notification data to the developer, advertisers, analytics providers, data brokers, or other third parties. The app contains no advertising, analytics, or cloud-storage SDKs.
If you choose to export your notification database, Kept creates a password-encrypted ZIP file in its private storage and opens Android's system share sheet. The file is disclosed only to the destination you select. That destination's privacy practices apply after you share the file. Keep the export password secure and share exports only with services or people you trust.
6. Retention and deletion
Notification history remains in Kept's local database until you delete records in the app, clear its storage in Android settings, or uninstall it. The in-app “Clear all data” action removes database records; it does not currently remove preferences or ZIP files created by export. To remove those copies from Kept's private storage, clear the app's storage or uninstall it. Copies you shared with another app or person must be deleted at that destination. You can stop future recording in Kept or revoke notification access in Android settings. Kept does not currently enforce an automatic deletion period. Because the developer does not receive or hold this data, the developer cannot retrieve or delete it remotely.
7. Security
Kept uses Android app-private storage, disables Android cloud backup, and offers optional device authentication and screenshot blocking. User-initiated exports are protected with AES ZIP encryption. No method of storage is completely secure, so you should protect access to your device and exported files.
8. Children's privacy
Kept is a general-audience utility and is not directed to children under 13. The developer does not knowingly collect children's personal information through a server or online service.
9. Your choices and rights
You control the information processed by Kept on your device. You can disable recording, revoke notification access, delete stored data, clear the app's storage, or uninstall the app. Depending on where you live, privacy laws may provide additional rights; however, the developer cannot access data that never leaves your device.
10. International data transfers
Kept does not transmit personal data to the developer or a developer-operated server, so the developer does not perform international transfers of your notification data. Data may move between countries if you use Android's device migration or deliberately export and share a file to a destination in another country.
11. Changes to this policy
This policy may be updated when Kept's features or data practices change. The latest version will remain available at this URL, with the updated date shown at the top.
12. Contact
For privacy questions or requests, contact Longdabo at longdabo@gmail.com. You may also review the policy source through the Kept privacy-policy repository. Do not include notification content or other sensitive information in a public GitHub issue.