Keeplatch

EN · TR

Legal

Privacy policy

Last updated 18 September 2026. This page is the published HTTPS privacy policy for Keeplatch. It matches the in-app privacy copy. It does not claim a leak-proof score, and it does not claim that all data stays on the device.

This site does not set cookies, does not load third-party fonts or analytics, and does not collect visitor accounts. Opening this page is not a tunnel start.

Who this covers

This policy covers the Keeplatch Android app and this product site. Kayastack publishes the app on Google Play. Purchases are Google Play transactions.

What stays on the device

Network traffic, connection logs, the app inventory, rules, Quick List, runtime status, protection history (kept up to 30 days, 1 MiB, or 1,200 events), diagnostics, and decision logs (kept up to 90 days or 10 MiB) stay on this device.

Connection decisions are kept locally for a period you choose (default 7 days, at most 90 days) or 10 MiB. Protection lifecycle events (whether the firewall was running or interrupted) are kept separately for up to 30 days, 1 MiB, or 1,200 events.

Android backup and device-to-device transfer are both disabled for the application. Settings move to a new device only through the backup file you export yourself.

What a connection log may contain

Logs may include destination IP, port, protocol, and domain names. A domain may be a blocked query that was not resolved, directly observed from DNS, or associated as a probable name from IP correlation. Logged blocked-query and probable-name metadata is not fed back into firewall decisions; probable names are not definitive.

Packet payload and package name are never logged. Packet contents and package names are never written to connection logs. Diagnostics do not collect package name, domain, or destination IP dumps.

What is processed off the device

The Play purchase token and subscription status are processed by Google Play and the verification server. This is not all data staying on the device.

Connection logs, package names, UIDs, IPs, and domain names do not go to that server. The verification server does not keep traffic logs. Advertising ID, approximate location, and precise location are not collected.

Keeplatch needs to see every installed app so each one can have its own Wi-Fi and mobile-data rule. That inventory stays on the device. It is not shipped to third-party SDKs or diagnostics.

This website

These pages are static files. They do not run a visitor tracker. TLS for this hostname is terminated on the host that serves the files. That is not an entitlement log and not a connection log from the firewall.

Access and deletion

To access or delete local data, uninstall the app or export then discard the backup file. The verification server does not keep traffic logs.

Purchases

Purchase disputes and refunds go through Google Play. A refund or revoke ends firewall access.

Changes

If the real data flow changes, this page and the in-app privacy copy are updated together.