Privacy Policy
Last updated: [TO FILL: date of publishing]
Keepwarden is a task app with an AI assistant. It is built so that you never have to trust us with your data: we do not run a server that stores it, and we cannot read it. This page says exactly where your data goes, and who can see it.
Who we are
Keepwarden is made by [TO FILL: your name, or the business name if there is one]. Contact: [TO FILL: contact address].
Where your data lives
Your tasks, lists, notes and settings are kept in your own room on Witbitz, the platform Keepwarden runs on. A room is end-to-end encrypted, and its key is kept on your device. Only people you signed in as (your account, and a backup address if you named one) can open it; a link alone opens nothing.
We, the makers of Keepwarden, have no server that stores your data and no copy of your room's key. The app is code that runs on your device.
Your device keeps a copy of your lists so the app opens quickly and works offline. It is removed when you sign out of Keepwarden on that device.
The assistant
When you write to the assistant, your message and the context it needs (your lists, your settings, and — if you connected it — what it read from your calendar) are sent, through Witbitz, to an AI model that writes the answer. Every change the assistant suggests is shown to you as a card, and nothing changes until you approve it.
Which model, and who can see what during a turn, depends on your room:
- A confidential room runs the assistant inside a verified hardware enclave. Your room's key is sealed to that enclave before it leaves your device, and the device refuses to send it if the enclave cannot be verified. The model is an open model running in that enclave.
- A standard room sends the key with each request, and Witbitz's servers hold it for the duration of the request. The model is [TO FILL: the model and its provider, e.g. GPT-5.5 by OpenAI, reached through Witbitz].
Settings → Your room says which kind of room you have.
Google Calendar
Connecting Google Calendar is optional. If you connect it, Keepwarden asks Google for:
calendar.readonly— to see your calendars and their events, so the assistant can tell you what is on your schedule and plan tasks around it.calendar.events— to add or change an event, only after you approve a card that shows exactly what will be written, and to which calendar.
How it is handled. The sign-in with Google is kept by the Witbitz Sentinel, a service that runs inside a verified hardware enclave. The access tokens never reach your device, your room, or us. When the assistant reads your calendar, the Sentinel makes the request and the answer is given to the assistant for that conversation; the full answer is not stored in your room — only a line saying what was read and when. A change you approve is recorded in your room's history, like any other change.
What we never do with Google user data. We do not sell it. We do not use it for advertising. We do not let people read it, except you. We do not use it to develop, improve or train AI or machine-learning models — ours or anyone else's. It is passed on only as needed to provide the feature you asked for: to Witbitz, which runs the connection and the assistant, and to the AI model that answers your request, as described above.
Keepwarden's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting. Settings → Account & connections → Disconnect removes the connection from your room and from the Sentinel. You can also remove Keepwarden's access at any time at myaccount.google.com/permissions.
Siri
If you turn on Siri, what you say to the Shortcut is sent to the Witbitz Sentinel, encrypted to a key that only your device holds, and waits there until your device collects it into your inbox.
Your account
You sign in to Witbitz with your email address and a one-time code. Witbitz uses your address to decide who may open your room. Keepwarden does not send your address anywhere else.
Deleting your data
Signing out removes everything Keepwarden kept on that device. To delete your room itself: [TO FILL: how a user deletes a room and all its data at Witbitz — ask Alon].
Children
Keepwarden is not meant for children under 13, and we do not knowingly collect data from them.
Changes
If this policy changes, the new version will be published here with a new date. A change that affects how Google user data is used will be made only in line with Google's policies.