The short version: Keystone stores account, client and meeting records in a private Supabase project, uses selected providers for functions such as transcription and analysis, and gives users controls to review, export and delete available data. Meeting content is sensitive: only upload it with a valid basis and informed participant consent.
Who is responsible
Keystone is operated by Tng Shao Bin Jayden in his personal capacity. “Keystone” is the name of the Service and is not a separate incorporated company. References to “we”, “us” and “our” in this Policy mean Tng Shao Bin Jayden as the Service operator.
Tng Shao Bin Jayden is Keystone’s designated Data Protection Officer. Privacy questions and requests may be sent to jcc.keystone@gmail.com.
Scope and processing roles
This Policy applies to Keystone’s website, account services, meeting workspace, billing, support, security operations and optional integrations.
For account, billing, security, support and service-administration data, we decide why and how the data is handled. For recordings, transcripts, client records and other content submitted by a customer for the customer’s work, the customer or its organisation normally decides the purpose, and we generally act as a data intermediary processing that content on behalf of the customer. The customer remains responsible for its notices, consents, instructions and responses to the people whose data it uploads.
Personal data we handle
We do not need or store your account password in readable form. Please do not send full recordings, transcripts, identity numbers, payment-card details or other sensitive meeting content by ordinary support email.
How we receive data
We receive data directly from you when you create an account, upload or record a meeting, enter client information, contact support, purchase a plan, request an export or connect another service. We also receive data from meeting participants whose information you submit, from connected services acting on your instructions, and from infrastructure providers that return authentication, billing, transcription, analysis, delivery or security results.
How we use data
- create, authenticate and administer accounts;
- store, organise, transcribe and analyse meetings and client workspaces;
- provide imports, exports, calendars, reminders, billing, support and authorised integrations;
- secure the Service, prevent abuse, investigate failures and enforce the Terms;
- comply with legal obligations and resolve disputes; and
- improve reliability and safety using content-free or aggregated operational information where practicable.
We do not sell or rent personal data, use User Content for targeted advertising, or use User Content to train models that we own. Unless confirmed separately in writing, we do not promise that every AI or transcription provider offers zero retention or excludes submitted content from every provider improvement process; the provider terms and account settings applicable to our use govern those issues.
Providers and disclosures
A provider receives data only when its function is used. Optional connected apps do not receive data until you connect or authorise them.
If you use the Client Map, Keystone stores saved visit addresses with your client records. Opening the map sends saved addresses to Google Maps to locate client pins. Previewing or optimizing a route sends the route addresses to Google Maps; opening directions shares the addresses through Google Maps links. These requests omit client names, notes and meeting content. Located coordinates and unsaved routes stay in browser memory, and estimates do not check appointment arrival times.
store: false with the analysis request, but source code alone cannot prove every aspect of provider-side retention.We may also disclose data to professional advisers or authorities when reasonably necessary to comply with law, protect people or the Service, investigate misuse, or establish or defend legal claims. If the Service is reorganised or transferred, data may be disclosed subject to appropriate confidentiality and continued protection.
Browser storage
Your browser stores a signed-in session token, a last-activity timestamp, and limited preferences, upload identifiers and pending legal-acceptance information so Keystone can keep you authenticated, sign the account out after eight hours without meaningful activity, resume supported actions and remember settings. These values are not Keystone’s provider secret API keys. Signing out clears the active Keystone session, but browser or device data may remain until removed by the application, browser or user.
Overseas processing
The primary Supabase project is configured for Singapore. AI, transcription, payment, email, website-delivery, connected-app and support providers may process data outside Singapore. Singapore’s PDPA may require legally enforceable obligations or another permitted safeguard providing comparable protection. We have not independently verified every provider transfer arrangement, processing country, subprocessor or account setting. Do not treat this Policy as confirmation that Keystone is ready for regulated or location-restricted data; contact the Data Protection Officer for current details.
Retention and deletion
- Raw meeting audio — automatically removed after 30 days.
- Benchmark and correction cases — automatically removed after 90 days.
- Meeting records, transcripts and analyses — automatically removed after 5 years unless deleted sooner.
- Operational events — generally retained for 30 days.
- Consent and deletion receipts — minimal content-free receipts are retained for 5 years.
- Legal acceptance and account-closure receipts — version, method, server timestamp and a user identifier are retained without meeting content for 5 years.
No fixed automatic deadline currently applies to every account, client, calendar, integration, billing, support, audit and security record. These records are kept only while needed for the Service or a legitimate legal, accounting, fraud-prevention, dispute-resolution or security purpose, then deleted or anonymised. Disconnected-app credentials are deleted.
Deleting a meeting removes its content from active systems controlled by Keystone. It does not directly send a deletion request to ElevenLabs or OpenAI, and it does not delete copies you sent to optional connected services. Provider-side retention, legal holds and backup or recovery lifecycles may therefore continue to apply. Account closure may also require cancellation of an active paid subscription and retention of limited billing, security or dispute records where justified.
How we protect data
Keystone uses authenticated, owner-scoped access controls for user records, private storage for recordings, server-side checks for sensitive provider calls, encryption for stored connected-app tokens, signed billing and meeting webhooks, an MFA-gated in-app platform-administrator route, bounded uploads, and server-held provider credentials. Provider-console MFA remains an operational control that must be verified separately. Application logs are designed to avoid recordings, transcripts, briefs, raw IP addresses and secrets.
No online service is risk-free. You must use a strong unique password, protect your device and email account, sign out of shared devices, limit workspace access, review connected apps and notify us promptly if you suspect unauthorised use. Do not use Keystone as your only copy of records you are legally or professionally required to retain.
Your rights and choices
You may use available controls to access, correct, export, delete or update meeting and client records, disconnect optional apps, manage notifications and request account closure. You may also contact us to request access to or correction of personal data we control, withdraw consent, ask a privacy question or make a complaint. Legal exceptions may apply, and we may verify your identity before acting.
Before processing a withdrawal request, we will explain the likely consequences of withdrawing consent. If the requested data is necessary to provide the Service, withdrawal may require disabling features or closing the account. If another Keystone customer uploaded your information, contact that customer first because it controls the relationship and context; we will reasonably assist it with a valid request.
Data incidents
We investigate suspected personal-data breaches and take reasonable steps to contain and assess them. If we process affected User Content for a customer, we will notify that customer without undue delay using information reasonably available to us. We will notify the Personal Data Protection Commission, affected individuals or other authorities where we are legally responsible and required to do so.
Children
Keystone accounts are intended for people aged 18 or older. Do not knowingly use Keystone to record or process a child’s personal data unless you have a valid legal basis, provide all required notices, obtain legally sufficient permission and apply safeguards appropriate to the child and context.
Policy changes
We may update this Policy when Keystone’s features, providers or legal obligations change. We will post the new version and effective date and provide additional notice where a change is material and reasonably practicable. We will seek new consent where required rather than treating this Policy as permission for an incompatible new purpose.
Contact and complaints
Service operator: Tng Shao Bin Jayden
Data Protection Officer: Tng Shao Bin Jayden
Email: jcc.keystone@gmail.com
Please include enough information to identify the relevant account or record without emailing sensitive meeting content unnecessarily. We will review privacy complaints and respond within a reasonable time. You may also contact Singapore’s Personal Data Protection Commission about a concern, subject to its applicable process.