Terms of Service
KEYSTONE PRIVACY

Privacy Policy

This Policy explains what personal data Keystone handles, why it is used, who receives it, how long it is retained, and the choices available to you.

Effective 29 September 2026Version 1.1
Clear responsibilityCustomers control the meetings they choose to process.
Purpose-limited useData is used to operate, secure and support Keystone.
Protected accessPrivate files and user records are access-controlled.
On this page
01Who is responsible02Scope and roles03Personal data we handle04How we receive data05How we use data06Providers and disclosures07Browser storage08Overseas processing09Retention and deletion10How we protect data11Your rights and choices12Data incidents13Children14Policy changes15Contact and complaints

The short version: Keystone stores account, client and meeting records in a private Supabase project, uses selected providers for functions such as transcription and analysis, and gives users controls to review, export and delete available data. Meeting content is sensitive: only upload it with a valid basis and informed participant consent.

01

Who is responsible

Keystone is operated by Tng Shao Bin Jayden in his personal capacity. “Keystone” is the name of the Service and is not a separate incorporated company. References to “we”, “us” and “our” in this Policy mean Tng Shao Bin Jayden as the Service operator.

Tng Shao Bin Jayden is Keystone’s designated Data Protection Officer. Privacy questions and requests may be sent to jcc.keystone@gmail.com.

02

Scope and processing roles

This Policy applies to Keystone’s website, account services, meeting workspace, billing, support, security operations and optional integrations.

For account, billing, security, support and service-administration data, we decide why and how the data is handled. For recordings, transcripts, client records and other content submitted by a customer for the customer’s work, the customer or its organisation normally decides the purpose, and we generally act as a data intermediary processing that content on behalf of the customer. The customer remains responsible for its notices, consents, instructions and responses to the people whose data it uploads.

03

Personal data we handle

Account and profileEmail address, name, occupation or role, agency, onboarding state, authentication identifiers, plan and account preferences.
Client and pipeline recordsClient contact details, relationship notes, protection and wealth notes, next-call details, policy or provider information, premiums, adviser earnings, expected close dates, lost reasons and other notes you enter.
Meeting contentMeeting title and date, participant and speaker details, consent confirmation, audio, transcripts, speaker labels, corrections, analyses, briefs, action items and follow-up status.
Billing and supportSubscription status, checkout and billing references, support messages, export or closure requests, and records needed to resolve disputes or prevent fraud. Complete payment-card details are handled by Stripe rather than stored by Keystone.
ConnectionsConnected account identifiers, permissions, encrypted OAuth access tokens, calendar or meeting records, and the instructions or content needed for an optional action you authorise.
Technical and securityLimited device, browser, request, usage, audit, abuse-prevention and operational-event data. Security controls may use a keyed identifier derived from an IP address instead of retaining the raw address in application records.

We do not need or store your account password in readable form. Please do not send full recordings, transcripts, identity numbers, payment-card details or other sensitive meeting content by ordinary support email.

04

How we receive data

We receive data directly from you when you create an account, upload or record a meeting, enter client information, contact support, purchase a plan, request an export or connect another service. We also receive data from meeting participants whose information you submit, from connected services acting on your instructions, and from infrastructure providers that return authentication, billing, transcription, analysis, delivery or security results.

05

How we use data

  • create, authenticate and administer accounts;
  • store, organise, transcribe and analyse meetings and client workspaces;
  • provide imports, exports, calendars, reminders, billing, support and authorised integrations;
  • secure the Service, prevent abuse, investigate failures and enforce the Terms;
  • comply with legal obligations and resolve disputes; and
  • improve reliability and safety using content-free or aggregated operational information where practicable.

We do not sell or rent personal data, use User Content for targeted advertising, or use User Content to train models that we own. Unless confirmed separately in writing, we do not promise that every AI or transcription provider offers zero retention or excludes submitted content from every provider improvement process; the provider terms and account settings applicable to our use govern those issues.

06

Providers and disclosures

A provider receives data only when its function is used. Optional connected apps do not receive data until you connect or authorise them.

If you use the Client Map, Keystone stores saved visit addresses with your client records. Opening the map sends saved addresses to Google Maps to locate client pins. Previewing or optimizing a route sends the route addresses to Google Maps; opening directions shares the addresses through Google Maps links. These requests omit client names, notes and meeting content. Located coordinates and unsaved routes stay in browser memory, and estimates do not check appointment arrival times.

SupabaseAuthentication, database and private recording storage in Keystone’s project configured for Singapore.
ElevenLabsReceives meeting audio through a short-lived signed link when transcription is requested and returns speaker-separated transcript text.
OpenAIReceives the meeting title, date and speaker-labelled transcript needed to generate structured analysis. Keystone sends store: false with the analysis request, but source code alone cannot prove every aspect of provider-side retention.
Vercel and CloudflareVercel delivers the web application. Cloudflare Turnstile may process request and device signals to protect authentication from automated abuse.
StripeHandles checkout, payment details, subscription billing and related billing identifiers.
Resend and browser push providersReceive the recipient address or delivery subscription and the account, reminder or notification message needed for opted-in communications.
Google-hosted DPO mailboxGoogle receives privacy-request and support email sent to our public contact address. Do not email meeting content or unnecessary sensitive attachments.
Optional integrationsGoogle, Microsoft, Zoom, Notion and a configured MCP service receive the permissions, records, content or instructions needed for actions you approve.

We may also disclose data to professional advisers or authorities when reasonably necessary to comply with law, protect people or the Service, investigate misuse, or establish or defend legal claims. If the Service is reorganised or transferred, data may be disclosed subject to appropriate confidentiality and continued protection.

07

Browser storage

Your browser stores a signed-in session token, a last-activity timestamp, and limited preferences, upload identifiers and pending legal-acceptance information so Keystone can keep you authenticated, sign the account out after eight hours without meaningful activity, resume supported actions and remember settings. These values are not Keystone’s provider secret API keys. Signing out clears the active Keystone session, but browser or device data may remain until removed by the application, browser or user.

08

Overseas processing

The primary Supabase project is configured for Singapore. AI, transcription, payment, email, website-delivery, connected-app and support providers may process data outside Singapore. Singapore’s PDPA may require legally enforceable obligations or another permitted safeguard providing comparable protection. We have not independently verified every provider transfer arrangement, processing country, subprocessor or account setting. Do not treat this Policy as confirmation that Keystone is ready for regulated or location-restricted data; contact the Data Protection Officer for current details.

09

Retention and deletion

  • Raw meeting audio — automatically removed after 30 days.
  • Benchmark and correction cases — automatically removed after 90 days.
  • Meeting records, transcripts and analyses — automatically removed after 5 years unless deleted sooner.
  • Operational events — generally retained for 30 days.
  • Consent and deletion receipts — minimal content-free receipts are retained for 5 years.
  • Legal acceptance and account-closure receipts — version, method, server timestamp and a user identifier are retained without meeting content for 5 years.

No fixed automatic deadline currently applies to every account, client, calendar, integration, billing, support, audit and security record. These records are kept only while needed for the Service or a legitimate legal, accounting, fraud-prevention, dispute-resolution or security purpose, then deleted or anonymised. Disconnected-app credentials are deleted.

Deleting a meeting removes its content from active systems controlled by Keystone. It does not directly send a deletion request to ElevenLabs or OpenAI, and it does not delete copies you sent to optional connected services. Provider-side retention, legal holds and backup or recovery lifecycles may therefore continue to apply. Account closure may also require cancellation of an active paid subscription and retention of limited billing, security or dispute records where justified.

10

How we protect data

Keystone uses authenticated, owner-scoped access controls for user records, private storage for recordings, server-side checks for sensitive provider calls, encryption for stored connected-app tokens, signed billing and meeting webhooks, an MFA-gated in-app platform-administrator route, bounded uploads, and server-held provider credentials. Provider-console MFA remains an operational control that must be verified separately. Application logs are designed to avoid recordings, transcripts, briefs, raw IP addresses and secrets.

No online service is risk-free. You must use a strong unique password, protect your device and email account, sign out of shared devices, limit workspace access, review connected apps and notify us promptly if you suspect unauthorised use. Do not use Keystone as your only copy of records you are legally or professionally required to retain.

11

Your rights and choices

You may use available controls to access, correct, export, delete or update meeting and client records, disconnect optional apps, manage notifications and request account closure. You may also contact us to request access to or correction of personal data we control, withdraw consent, ask a privacy question or make a complaint. Legal exceptions may apply, and we may verify your identity before acting.

Before processing a withdrawal request, we will explain the likely consequences of withdrawing consent. If the requested data is necessary to provide the Service, withdrawal may require disabling features or closing the account. If another Keystone customer uploaded your information, contact that customer first because it controls the relationship and context; we will reasonably assist it with a valid request.

12

Data incidents

We investigate suspected personal-data breaches and take reasonable steps to contain and assess them. If we process affected User Content for a customer, we will notify that customer without undue delay using information reasonably available to us. We will notify the Personal Data Protection Commission, affected individuals or other authorities where we are legally responsible and required to do so.

13

Children

Keystone accounts are intended for people aged 18 or older. Do not knowingly use Keystone to record or process a child’s personal data unless you have a valid legal basis, provide all required notices, obtain legally sufficient permission and apply safeguards appropriate to the child and context.

14

Policy changes

We may update this Policy when Keystone’s features, providers or legal obligations change. We will post the new version and effective date and provide additional notice where a change is material and reasonably practicable. We will seek new consent where required rather than treating this Policy as permission for an incompatible new purpose.

15

Contact and complaints

Service operator: Tng Shao Bin Jayden
Data Protection Officer: Tng Shao Bin Jayden
Email: jcc.keystone@gmail.com

Please include enough information to identify the relevant account or record without emailing sensitive meeting content unnecessarily. We will review privacy complaints and respond within a reasonable time. You may also contact Singapore’s Personal Data Protection Commission about a concern, subject to its applicable process.

Privacy by design. Clarity by default.

© 2026 Keystone