Privacy notice
keel is a household personal-finance app operated by Six Figure Startups Ltd ("we", "us"). This notice explains what personal data we collect, why, who we share it with, and the rights you have over it. It is written to meet our obligations under the UK GDPR and the Data Protection Act 2018.
Last updated: 25 June 2026.
Who is the controller
Six Figure Startups Ltd is the data controller for the personal data described here. For any data-protection question or to exercise your rights, contact us at support@keel-finance.co.
What data we collect
- Who you are — your name and email address (managed through our authentication provider), and the household you belong to.
- Your finances — the bank and card transactions you import (by CSV upload or, in future, Open Banking), including the merchant, amount, date and any running balance; your account names, balances, debts and credit limits; and credit-report data if you choose to upload a credit report.
- What you tell us — budgets and goals you set (including any free-text "why" you write), notes you add to transactions, and messages you send to the in-app coach.
- What we derive — your financial-health score, spending categories, coaching insights, and benchmark comparisons against anonymised national data.
- How you use keel — basic, privacy-respecting product analytics (no financial detail attached) to understand which features work.
- If you join our waitlist — just your email address, so we can let you know when access opens. You can ask us to remove it at any time (see "Your rights").
Why we use it, and our lawful basis
| What we do | Lawful basis |
|---|---|
| Run your account and deliver the service (importing, categorising, reporting, scoring, coaching) | Performance of our contract with you |
| Product analytics to improve keel | Legitimate interests (improving the product), using privacy-respecting, no-financial-detail events |
| Holding your email on the beta waitlist to tell you when access opens | Consent (given when you join the waitlist; withdraw any time) |
| Keeping records we're legally required to keep | Legal obligation |
Special category data
keel does not intend to process "special category" data (such as data revealing health, religious beliefs, political opinions or sex life), and we do not build any feature that infers it. However, your own bank data can contain merchants — a pharmacy, a clinic, a place of worship — from which such information could be inferred. We cannot exclude these from a bank feed you import, so we handle all transaction data with that in mind: we minimise what we store, we never surface coaching insights about sensitive merchants, and we hold our AI processor to no-retention, no-training terms. You can read our full position in our internal special-category record (available on request).
Who we share it with
We use a small number of trusted service providers ("processors") who act only on our instructions:
- Neon — secure database hosting (stores your keel data).
- Vercel — application hosting.
- Clerk — sign-in and account security.
- Anthropic — the AI that categorises your transactions, powers the coach, and reads uploaded credit reports. It receives transaction and (if you upload one) credit-report data under no-retention, no-training terms.
- PostHog (EU) — product analytics and error monitoring, with AI content redacted.
- Upstash — secure session and rate-limiting storage.
Some of these providers are based outside the UK/EU. Where that is the case, the transfer is protected by an approved safeguard (the UK International Data Transfer Agreement or Standard Contractual Clauses). We do not sell your data, and we do not share it for advertising.
How long we keep it
We keep your data while your household is active. Specific items are deleted on a schedule — for example, uploaded credit reports are removed six months after their report date, and AI coach debug logs after 90 days. Waitlist emails are kept for up to 12 months if access hasn't opened to you by then. If you delete your account we erase your data (see your rights below). Dormant accounts are removed after a period of inactivity. Our full retention schedule is maintained internally and available on request.
Your rights
You have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data ("right to be forgotten") — you can delete your account from Settings, which removes your keel data and your sign-in identity.
- Portability — receive your data in a machine-readable format.
- Object to or restrict certain processing.
To exercise any right, contact support@keel-finance.co. We respond within one month.
Complaints
If you're unhappy with how we handle your data, please contact us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling their helpline.
Changes to this notice
We'll update this notice as keel evolves and change the "last updated" date above. Material changes will be brought to your attention in the app.