Karakeep - Privacy Policy
Effective date: 2026-02-15
In short: we collect the minimum data needed to run your account, store your saved content, and provide features like search and AI tagging. We store primary data in Europe and do not sell personal data.
1. Scope
This page explains what data we collect, how we use it, and when we share it for Karakeep Cloud. Localhost Labs Ltd is the data controller for personal data processed under this policy. Karakeep Cloud is operated by Localhost Labs Ltd (England & Wales, Company No. 16403882).
2. Data We Collect
We collect the following types of data:
- Account information: email address, name, profile image, authentication identifiers.
- Content you provide: links, notes, uploads, and other data you choose to save in the Service. We may process this content — including via third-party artificial intelligence providers — to provide features such as full-text search, automatic tagging, and AI-powered summaries.
- Billing and subscription data: plan status, billing events, and limited payment metadata from payment providers.
- Technical and usage data: logs, device/browser details, IP address, and service events needed to run, secure, and troubleshoot Karakeep.
- Support communications: information you send when contacting support.
3. How We Use Data
We use your data to run and improve Karakeep Cloud, including to:
- create and manage your account;
- store and present your content;
- manage subscriptions and payments;
- detect abuse, fraud, and security incidents;
- monitor reliability and fix issues;
- comply with legal obligations.
4. Legal Bases (EEA/UK)
If you are in the EEA or UK, we rely on the following legal bases:
- Contract: to create and manage your account, store your content, and provide core product features.
- Legitimate interests: to keep the service reliable and secure, prevent abuse, and provide support.
- Legal obligation: to comply with tax, accounting, and lawful requests from authorities.
- Consent (where required): for optional processing where consent is the lawful basis; you can withdraw consent at any time.
Where we rely on legitimate interests, we balance those interests against your rights and freedoms.
5. Sharing and Processors
We use subprocessors to run Karakeep Cloud. They only process data on our instructions and under contractual safeguards. Current key providers include:
- Hetzner (hosting and infrastructure, with primary data storage in Europe).
- Stripe (payments and billing events).
- OpenAI (content processing for features such as automatic tagging and summaries).
We do not voluntarily disclose data to law enforcement. We require valid legal process (such as a court order or warrant) before providing any user data, and we will notify affected users unless legally prohibited from doing so.
We do not sell your personal data. We only access account content when needed to help with support requests, investigate abuse or security issues, or meet legal obligations.
For paid plans, payments are handled by our payment provider (for example, Stripe). We do not store full payment card details on our systems.
6. International Transfers
Karakeep Cloud stores primary data in Europe. Some subprocessors may process data outside your country (including outside the EEA/UK). Where required, we rely on recognised safeguards for cross-border transfers, such as Standard Contractual Clauses (SCCs) or adequacy decisions.
7. Cookies and Similar Technologies
We use essential cookies and similar technologies to keep you signed in, protect against cross-site request forgery, and remember basic preferences. We do not use third-party advertising or tracking cookies. You can adjust cookie settings in your browser, but disabling essential cookies may prevent parts of the Service from working properly.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. These include encryption of data in transit, access controls, and regular security reviews. No system is completely secure, and we cannot guarantee the absolute security of your data.
9. Data Retention and Deletion
We keep personal data only as long as needed to run the Service and meet legal obligations. When you delete your account, we delete your data. Residual copies may remain in encrypted backups for up to 90 days before being purged.
10. Your Rights
Regardless of where you live, we extend the following rights to all Karakeep Cloud users:
- Access: request a copy of the personal data we hold about you.
- Correction: ask us to correct inaccurate or incomplete data.
- Erasure: ask us to delete your personal data.
- Restriction: ask us to restrict certain processing of your data.
- Portability: receive your data in a structured, commonly used format.
- Objection: object to processing based on legitimate interests.
To submit a rights request, email us using the contact details below. We may ask for additional information to verify your identity before handling some requests.
You can submit privacy requests by emailing [email protected] or [email protected]. We respond within timelines required by applicable law.
11. Children
Karakeep Cloud is not intended for children under 16. If you believe a child gave us personal data in violation of this policy, contact us and we will take appropriate action.
12. Browser Extension
The Karakeep browser extension works with your Karakeep account. It includes an optional feature that, when enabled, sends URLs of pages you visit to check whether they already exist in your library. This feature is off by default and requires you to opt in. The data is sent only to Karakeep Cloud and is not shared with third parties. Content is saved to your account only when you explicitly choose to save it.
URLs sent for existence checking are not stored and are not used for analytics or profiling. Only content you explicitly choose to save is added to your account.
13. Self-Hosted Deployments
This policy applies to Karakeep Cloud. If you self-host Karakeep, your data stays entirely on your own infrastructure and we do not collect or have access to any of it. You are responsible for your own data practices and compliance.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be published on this page with an updated effective date. Your continued use of the Service after a revised policy is published constitutes your acceptance of the changes.
15. Contact Us
For privacy questions or requests, contact us at:
Localhost Labs Ltd (England & Wales, Company No. 16403882)
Email: [email protected]
Support: [email protected]