Security
Last updated: 4 July 2026
KeepChats is built so that the amount of your data we could lose is small by design. This page describes how your account and your content are protected, and how to report a problem.
What we hold, and what we do not
- We hold your email address, your plan, and the record of who consented to what.
- We do not hold the contents of your conversations. Exports are written to your own device first; a cloud copy exists only if you switch backup on.
- Writing help runs on the single message in front of you. It does not read the rest of the thread, and nothing is retained once the suggestion is returned.
Account protection
- Passwords are hashed with bcrypt. They are never stored or logged in a readable form, and staff cannot read them.
- Two-factor authentication is available, and security-sensitive events send you an alert by email.
- Passkeys and single sign-on are supported so you can avoid a password entirely.
- API sessions use short-lived access tokens with rotating refresh tokens, so a stolen token has a narrow window of use. On mobile, tokens are held in the device keychain, bound to that device, and readable only while the phone is unlocked.
In transit and at rest
- Every connection to KeepChats uses TLS. Plain HTTP is redirected, never served.
- Stored files are kept on private storage and served only through authenticated, expiring links.
- Personal fields we never need to search on are encrypted at rest.
Deletion
One action in settings removes your account, your consent records, and any cloud copies within 24 hours, and you get written confirmation. There is a short grace period first, so an accidental request can be undone — see Delete your account. Files already exported to your own device are yours and are not touched.
The browser extension
The extension requests only the permissions it needs to read the conversation you are looking at and write the export to your downloads. It talks to no third party. Exported archives are self-contained files on your disk and keep working with KeepChats uninstalled and no network at all.
Reporting a vulnerability
If you believe you have found a security issue, email support@duskel.com with enough detail to reproduce it. Please give us a reasonable chance to fix it before disclosing it publicly. We will confirm receipt, keep you updated, and credit you if you would like to be credited.
Please do not run tests that degrade the service for other people, and do not access, modify, or retain data belonging to anyone but yourself.
Contact
Security questions: support@duskel.com.