Last updated: 17 September 2026
This Policy explains how Keply, operated by Keply Ltd ("Keply", "we"), handles personal data. We act as a processor for the customer data you connect (you are the controller), and as a controller for your account and usage data. When we process personal data on your behalf, our Data Processing Addendum governs that processing.
Account data (name, email, organization), data you connect (CRM, billing, mailbox, calendar, product-usage and survey signals, which may include personal data of your customers), AI-derived artifacts (health scores, risk flags, drafts), and product/usage logs. We do not sell personal data.
To provide the Service: normalize your data, compute health scores and risk, draft outreach, and operate Keply under your control. Connected tokens are encrypted at rest and never stored in plaintext. Customer-facing actions default to requiring human approval.
Essential cookies (your sign-in session) are always on and never used for tracking. For product analytics we use PostHog, Microsoft Clarity, and Google Analytics to understand how the site and product are used (pages viewed, clicks, scrolling, and the referrer or campaign code that brought you here), solely to improve Keply. PostHog also records session replays. On our public marketing pages and demo sandbox the replay is unmasked: the sandbox has no sign-in and runs on a book of accounts we made up, so everything on screen there is ours or invented, and we also record the questions you type into the sandbox or into the Contact us bot and the answer you got (never the email address you leave for a reply), so we can see what people want the product to answer and whether it answered them well. On the signed-in product, every word on screen and everything you type is masked in your browser before the replay leaves it, so what we see is layout and clicks, never your customer data. Only one thing you type inside your own workspace reaches these analytics tools: when you ask Keply a question, we record that question and Keply’s answer (the first few hundred characters of each) so we can see what people ask and whether Keply answered well. Those can name your accounts. They are used only to improve Keply and never reach advertising tools. Keply itself keeps one more thing: when it cannot answer a question you asked it, it keeps that question, so we can see what the product is missing and build it. Those stay inside your own workspace and are deleted after 12 months. We do not sell any of this data.
On our public marketing pages only, we also run Meta’s pixel and LinkedIn’s Insight Tag so we can tell which of our own ads brought someone to Keply. These load only after you accept analytics and never run on the signed-in product, but while they are loaded Meta and LinkedIn can connect that page view to your account on their platform. We do not send them anything from your workspace, and we do not sell your data to anyone.
Where the law requires opt-in consent (the EU/EEA, the UK, and other opt-in jurisdictions), a banner asks first and no analytics load until you accept. Elsewhere, analytics run on the basis of our legitimate interest in improving the Service, with this section serving as notice. We honor the Global Privacy Control browser signal everywhere: when your browser sends it, analytics stay off unless you explicitly accept.
. Takes effect immediately and persists on this browser.
To generate scores and drafts, relevant context from your connected data is sent to our AI subprocessor (Anthropic) for inference under commercial terms that prohibit training on your data. Every action Keply takes is recorded in an audit log. See our Subprocessors list for the providers involved.
Two things Keply sends to Anthropic do not come from your connected data. On a schedule, it searches the public web about your accounts and about your own company. And when someone on your team asks Keply to look something up, it sends the question they typed and any web addresses they pasted (up to three, which Keply also reads), capped at three such searches a day for the whole workspace. Both are switched off together by the workspace opt-out at Settings → Permissions, and both are described in full on our Trust page.
When you connect Gmail, Keply requests two scopes. With read access (the gmail.readonly scope), Keply reads your messages solely to detect customer-success signals (sentiment, renewal and contract mentions, payment issues, and engagement risk) and attribute them to the right customer account; it also uses your sent mail to learn your writing voice so drafts sound like you. With create-and-send access (the gmail.compose scope), Keply drafts customer-success emails into your Gmail Drafts for your review and, when you turn on higher autonomy, sends those emails as you so they appear in your Sent folder. Every send is either reviewed by you or governed by an autonomy setting you control; Keply does not send cold or bulk marketing email, and does not modify, label, or delete unrelated mail.
Keply's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is used only to provide and improve these user-facing features; is never used for advertising; is never sold or transferred to third parties except as necessary to provide the Service, comply with law, or as part of a merger or acquisition; and is not read by humans unless you give explicit consent, it is necessary for security or to comply with law, or the data has been aggregated and anonymized.
Keply does not use Google Workspace data, including Gmail content, to develop, improve, or train generalized AI or machine-learning models. Context sent to our AI subprocessor (Anthropic) for inference is processed under commercial terms that prohibit training on your data.
A workspace manager can choose to help Keply learn what works across customers, at Settings → Permissions. It is off unless someone turns it on, we record who turned it on and when, and it can be turned off at any time.
When it is on, we compute aggregate statistics only: churn and expansion rates by industry, segment and size; which kinds of signal preceded a churn and how many days ahead; how often a play drew a reply or saved an account; and the shape of a message that got replies (roughly how long it was, whether it asked a question, whether it offered a time, when it was sent). We do not pool account names, company names, revenue figures, contacts, or the text of any message. We do not pool anything read from Gmail or Google Calendar. We do not pool anything at all from a workspace that has not turned this on.
No statistic is computed or shown until at least five workspaces in an industry have turned it on, with at least twenty events behind the figure and no single workspace contributing more than 40% of them. Below those thresholds nothing is stored and nothing is displayed. The resulting figures are shown only to the workspaces that share; turning the setting off removes that workspace from the next recomputation, and any figure that then falls below the thresholds is deleted.
Because these figures identify no workspace, account or person, we keep them without a fixed retention period. The lawful basis for this processing is your consent, withdrawable at any time by turning the setting off.
We process personal data to perform our contract with you, on the basis of legitimate interests in operating and securing the Service, and on your instructions as processor. We process personal data in line with the EU/UK GDPR and the Israeli Privacy Protection Law. You are responsible for your lawful basis to connect customer data.
Access, rectification, erasure, restriction, portability, and objection. Where we are the processor, we assist the controller in fulfilling data-subject requests; where you are an individual end-user, we route your request to the relevant controller. Contact [email protected]; you may also lodge a complaint with your supervisory authority.
California residents have the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell or share personal information. To exercise rights, contact [email protected]. We will not discriminate against you for exercising them.
We use vetted sub-processors (cloud hosting, database, AI model, integration, and email providers) under data-protection terms. Our current list is published at keply.ai/trust. Keply Ltd is established in Israel, which the European Commission recognises as providing an adequate level of data protection. Where our sub-processors are outside that scope, transfers rely on the safeguards in each provider's data-protection terms.
We retain data for as long as your account is active or as needed to provide the Service, then delete or anonymize it within a defined window after termination. We use encryption in transit and at rest, tenant isolation, and access controls. Our security program is summarized at keply.ai/legal/security. No method is perfectly secure.
Data controller: Keply Ltd. Data protection contact: [email protected]. We will update this Policy as needed and note the date above.