Privacy Policy

Your data, on your terms

This Privacy Policy explains what personal data Keep Moments (‘we’, ‘us’) collects, why we collect it, how long we keep it, and the rights you have over it. It applies to our website, dashboard and every AI travel tool we offer.

Last updated: July 28, 2026

1. Data we collect

  • Account data — first and last name, email address and hashed password created during checkout.
  • Order & billing data — credit package purchased, currency, promotional codes applied, payment method chosen, invoice details.
  • Product usage data — which AI tools you run, the credits spent, timestamps and non-sensitive inputs required for generation.
  • Technical data — IP address, browser, device, language, and diagnostic logs strictly needed to keep the service secure and reliable.
  • Cookies — see our Cookie Policy for the full list and purposes.

2. Why we process your data

  • To create and secure your account and process your credit purchases (contract).
  • To generate AI outputs you explicitly request (contract).
  • To send transactional emails such as invoices, bank details and receipts (contract / legitimate interest).
  • To prevent fraud, abuse and to keep the platform stable (legitimate interest).
  • To comply with tax, accounting and legal obligations (legal obligation).

3. Legal basis

We rely on contract to deliver the service you paid for, legitimate interest to keep it safe, and legal obligation for financial records. We do not process personal data on the basis of legitimate interest where your rights override it.

4. Sharing

We only share personal data with vetted processors that help us run the service: cloud hosting, email delivery, payment processing (once enabled) and AI model providers strictly to fulfil your generation requests. We never sell your data.

5. Storage & retention

  • Account data — kept while your account is active and up to 12 months after deletion.
  • Order and invoice data — kept for the period required by tax law (typically 5–10 years).
  • Product usage logs — kept up to 12 months, then anonymised.

6. Your rights

You have the right to access, correct, export, restrict, object to processing, and delete your personal data. To exercise any of these rights, email [email protected]. You may also lodge a complaint with your local data protection authority.

7. International transfers

Some of our processors operate outside the EU/UK. When personal data leaves these regions we rely on Standard Contractual Clauses or an equivalent lawful transfer mechanism.

8. Security

We encrypt data in transit (TLS 1.2+) and at rest, restrict internal access on a need-to-know basis and continuously monitor for unauthorised activity.

9. Changes to this policy

We may update this Privacy Policy from time to time. Material changes are announced in-product and by email at least 14 days before they take effect.

Questions about this document? Reach us at [email protected].