Last updated: August 28, 2026

NorthKeep Privacy Policy

Grounded in how NorthKeep actually handles data (see KNOWN-LIMITS.md and SPEC/security-model.md). Not legal advice.

Provider: Silva Peak Labs, LLC d/b/a NorthKeep ("we," "us"), a Massachusetts limited liability company. Contact: [email protected] · Effective date: August 28, 2026

NorthKeep is built on a simple promise: your AI memory lives on your device, encrypted, and we never see its contents (the exceptions are content you deliberately choose to share or send: a scope you share with the optional connector, described below, and the arguments of a tool call you approve, described in "Tools" below). This policy explains the little data that does exist, where it lives, and what we do, and don't, do with it. The statements below describe how NorthKeep works today; if our practices change, we will update this policy and, for material changes, tell you before the change takes effect (see "Changes").

The short version

What we collect

On your device (not sent to us): your memories, their scopes, provenance, your passphrase, and the credentials NorthKeep stores in the macOS Keychain — your AI provider API keys, your Brave Search key (if you enable web search), and any OAuth tokens and client credentials for the remote MCP servers you connect. (NorthKeep runs on macOS today; on a platform without a Keychain, API keys fall back to an environment variable you supply, and remote MCP sign-in is not available at all.) None of this is transmitted to us. There is no account to create to use NorthKeep locally.

If you enable hosted sync, our sync server receives and stores:

If you subscribe to hosted sync, to operate billing we additionally store a mapping between your hashed account identifier and your Stripe customer and subscription IDs, subscription status, and current period end. Your payment card and email are collected and held by Stripe, our payment processor, not by us. Checkout is Stripe-hosted; card data never touches NorthKeep. See Stripe's privacy policy at https://stripe.com/privacy. The honest consequence: while a subscription is active, we can tell which paying customer is associated with which encrypted vault, but never that vault's contents, which remain ciphertext to us.

Website waitlist (optional)

If you submit the waitlist form on northkeep.ai, your email address is delivered to our inbox at [email protected] by Resend, our email delivery provider. We use it only to send NorthKeep updates. It is not added to any marketing list. We delete it on request to the same address. The form sets no cookies and the site has no analytics. See Resend's privacy policy at https://resend.com/legal/privacy-policy.

Shared scopes (optional connector)

Everything above describes hosted sync, where our server only ever holds ciphertext and never a key. The optional connector is different: it is the one place your shared memories are briefly decrypted on our server. It exists so the cloud AI apps you already use (such as Claude or ChatGPT) can reach the memories you choose.

Self-hosting the connector, or simply never sharing a scope, means no shared memory ever transits our server.

What we do not do

Data you send to AI providers you choose

NorthKeep can send text to AI models you connect:

You control which providers you use and can disconnect them at any time.

Tools: web search, web fetch, and MCP servers

NorthKeep can optionally let the model take actions beyond answering from your vault: searching the web, fetching a page, or calling a tool exposed by an MCP server you connect. All of this is off by default. Turning any of it on creates data flows to third parties you choose, described here.

Web search and web fetch

When you enable tools, the model can ask to search the web or fetch a specific page.

MCP servers

You can connect "MCP servers" — programs or services that expose tools to the model, so it can act beyond your vault (for example, reading your email). There are two kinds, with different exposure.

Self-hosting, or simply never turning tools on or connecting a server, means none of the data flows in this section happen.

How we protect the little data we hold

We maintain administrative, technical, and physical safeguards appropriate to the limited data we hold, including encryption of vault data in transit and at rest, the design choices described above (no stored keys, data minimization, ciphertext- only sync), and access controls on our servers. No system is perfectly secure, and we describe the honest limits of our connector design above and in KNOWN-LIMITS.md.

Breach notification. If we discover a security incident that compromises personal data we hold or the shared content on the connector, we will investigate promptly and notify affected users, and any regulators, as and when required by applicable law, for example the Massachusetts data-breach statute (M.G.L. c. 93H), other U.S. state breach-notification laws, and, for users in the EU or UK, the GDPR's 72-hour notification rule, without undue delay.

Data retention and deletion

Your rights

Depending on where you live (for example under GDPR or the CCPA), you may have rights to access, correct, delete, or export the personal data we hold about you. In practice we hold very little: a hashed account identifier, and, only if you subscribe, the Stripe billing mapping described above. To exercise any right, or to ask what we hold, contact [email protected]. We do not sell personal information.

For users in the EU and UK. Where the GDPR (or UK GDPR) applies, Silva Peak Labs, LLC is the data controller for the limited account and billing data described in this policy. Our lawful bases are performance of a contract (to provide the sync and connector features you request) and our legitimate interests in operating, securing, and supporting the Service. You may also have the right to lodge a complaint with your local supervisory authority. If you enable the connector, you remain in control of what content you share, and you can unshare or delete it at any time as described above.

Children

NorthKeep is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data.

Changes

We may update this policy. For material changes, we will post the updated policy at northkeep.ai with a new effective date and, for hosted-service subscribers, give notice by email or in-app before the change takes effect. Continued use of the hosted service after a change takes effect means you accept the revised policy.

Contact

Questions: [email protected].