Legal
Privacy Policy.
Privacy Policy — Keen Labs / Keenoble.
Last updated 2026-08-19
Controller
Keen Andersson Lang (enskild näringsidkare, trading as Keen Labs), registered in Sweden, Landskrona. Registration number on invoices and on request. Contact: support@keenlabs.pro. We are an EU company; GDPR applies to everything below.
What we collect
- Account data — email, name, and sign-in metadata, handled by our authentication provider Clerk.
- Waitlist data— if you request pilot access on this website, we store your email address, your optional answer to “what will you build?”, which page you signed up from, and the timestamp. Nothing else — no IP address, no tracking pixel, no analytics profile. It sits in a Postgres table (Supabase) that is unreadable to the public API by design, it is used only to contact you about pilot access, and asking us to delete it deletes the row. Legal basis: consent (GDPR art. 6.1.a), withdrawable at any time by emailing us.
- Payment data — handled by Stripe. Card numbers never touch our servers; we see subscription status and invoice history only.
- Your content — prompts, conversations, project memory, preview outputs and code files you create. Stored in Postgres (Supabase) behind row-level security scoped to your account.
- Usage telemetry — one row per model call: which model, token counts, cost, latency, success/failure. This is how the routing gets better; it is measurement of the service, not profiling of you.
What we do with it
- Provide the service (contract, GDPR art. 6.1.b): routing your requests, storing your projects and memory, billing.
- Improve routing and reliability (legitimate interest, art. 6.1.f): we analyze cost/latency/quality telemetry. Published findings are always aggregated — never your prompts, never your content.
- Legal obligations (art. 6.1.c): bookkeeping under Swedish law (7 years for accounting records).
We do not sell personal data. We do not run advertising. We do not train our own models on your content.
Where your prompts go
When you send a request, it is routed to one or more third-party model providers or data tools to generate the answer. The receipt on every answer shows which. Providers we route across include Anthropic, OpenAI, Google, Meta (via hosting providers such as Groq), xAI, Perplexity — and providers based outside the EU/EEA including in the United States and China (DeepSeek, Moonshot AI, Alibaba). Transfers rest on the providers' safeguards (EU-US Data Privacy Framework or standard contractual clauses where applicable); providers process prompts under their own API terms. Plainly said: if you do not want a prompt processed by a given country's provider, don't put personal data in prompts.
Subprocessors
Clerk (authentication), Stripe (payments), Supabase (database), Vercel (hosting), the model providers listed above, and live data tools (Tavily, Brave search, market data providers) when a request uses them. The current list is always on keenlabs.pro/security.
Retention
Account data: life of the account + 90 days. Conversations, projects and memory: until you delete them or your account. Telemetry rows: retained as measurements; anything published is aggregated. Bookkeeping records: 7 years (legal requirement).
Your rights
Access, rectification, erasure, restriction, portability, and objection — email support@keenlabs.pro from your account address and we act on it; account deletion removes your content per the retention table above. You can complain to IMY (Integritetsskyddsmyndigheten, imy.se), the Swedish supervisory authority.
Security
Described plainly at keenlabs.pro/security — authentication by Clerk, payments by Stripe, row-level security in Postgres, and no certifications we don't hold.