Skip to policy content
Home Legal Privacy Policy

Your privacy, handled with care.

This Privacy Policy describes how KEENL collects, uses, discloses, and safeguards your information when you visit our website, sign up for a Site Credit, build a website with our AI, or work with our human support team. We believe in plain language and short documents — so here’s everything in one place.

Last updated: June 15, 2026 Read time: ~ 12 minutes Jurisdictions: GDPR · CCPA · PIPL support@keenl.com
14 Core sections covering every aspect of your data
30d Average response time for data & privacy requests
0 We never sell or trade your personal data — ever
4 Cookie categories — only essentials run by default
Section 01

Introduction & Scope

KEENL (“we”, “us”, “our”, or the “Company”) operates the website located at keenl.com (the “Site”), the KEENL AI website builder platform (the “Service”), and related subdomains, applications, and tools that link to this Privacy Policy.

This Privacy Policy applies to all visitors, users, prospective customers, Site Credit holders, and anyone who otherwise interacts with KEENL online or offline. It describes the personal information we collect, how we use it, with whom we share it, and the rights you have over your data.

Plain language promise

If anything in this policy is unclear, write to support@keenl.com and a real human on our team will reply within two business days with a clear answer — no legalese, no runaround.

By accessing or using KEENL, you confirm that you have read and understood this Privacy Policy. If you do not agree with its terms, please discontinue use of the Service and contact us so we can address your concerns.

Section 02

Information We Collect

We collect a minimal amount of information — only what we need to build, host, and support your website, and to communicate with you about it. The data we collect falls into three categories.

2.1 · Information you give us directly

  • Account information: name, email address, password (hashed & salted), phone number (optional, only if you request a call-back), and the country you operate in.
  • Billing information: payment method details processed by our PCI-DSS compliant payment processor. We never see or store your full card number, CVV, or bank credentials on KEENL servers.
  • Business information you submit to the AI builder: business name, industry, address, hours, contact details, brand colors, logos, photos, written copy, products, services, and any prompts you provide during the AI generation step.
  • Domain registration data: if we register a domain on your behalf, the registrar requires your name, address, email, and phone number (WHOIS data). This is required by ICANN policy.
  • Support correspondence: emails, chat messages, screen recordings, design briefs, and feedback you share with our design and engineering team.

2.2 · Information we collect automatically

  • Device & log data: IP address, browser type and version, operating system, device identifiers, referring/exit pages, pages visited, and timestamps.
  • Usage analytics: aggregated behavior on our marketing site and dashboard (pages visited, features used, time on page) via privacy-respecting analytics tools.
  • Cookies and similar technologies: as described in detail in Section 04 — Cookies & Tracking .
  • Performance data: for the websites we host on your behalf, aggregated traffic and uptime logs to maintain service quality and diagnose issues.

2.3 · Information from third parties

  • Payment processors: confirmation of successful payments, refunds, and fraud-screening signals.
  • Identity verification providers: when required for high-value transactions or to comply with anti-fraud regulations.
  • Marketing partners: if you arrive at KEENL via an affiliate link, paid ad, or referral, we receive the referring source and any campaign identifier (without revealing your identity to the partner).
What we do NOT collect

We do not collect special categories of data (race, religion, health, sexual orientation, biometric data, government IDs) unless you voluntarily provide it in your website content. We do not buy data from data brokers. We do not track you across unrelated third-party websites for advertising.

Section 03

How We Use Your Data

We process your personal information for the following purposes, on the following legal bases:

Purpose Data used Legal basis
Create and manage your KEENL account Account info, email Contract performance
Generate your website using AI Business inputs, brand assets, prompts Contract performance
Process Site Credit purchases and refunds Billing data, transaction history Contract performance, legal obligation
Register and renew your domain name WHOIS contact data Contract performance, legal obligation
Provide lifetime human support Account, support correspondence, design assets Contract performance, legitimate interest
Detect and prevent fraud, abuse, security incidents IP, device, log data, behavior signals Legitimate interest, legal obligation
Send service announcements (outages, policy updates) Email, account status Contract performance, legitimate interest
Send marketing emails (only with consent) Email, behavioral data Consent (you can opt out anytime)
Improve the platform through aggregated analytics Anonymized usage data Legitimate interest
Comply with tax, accounting, and legal obligations Billing records, transaction history Legal obligation

Under the EU General Data Protection Regulation (GDPR), our “legitimate interests” are always balanced against your fundamental rights, and we perform a documented assessment (LIA) before relying on this basis. You can request a copy of any LIA by emailing support@keenl.com .

Section 04

Cookies & Tracking

Cookies are small text files placed on your device when you visit a website. KEENL uses cookies and similar technologies (local storage, pixels, SDKs) for the purposes described below. You can manage your cookie preferences at any time via our in-app Cookie Preferences panel or your browser settings.

4.1 · Categories of cookies we use

4.2 · Cookies set on the websites we build for you

Websites created on KEENL may use their own cookies depending on the features you enable — for example, an analytics integration, a contact form, an appointment booking widget, or a shopping cart. These cookies are governed by your own privacy policy that you publish on the site, not by this Privacy Policy. You are the controller of any personal data collected through your KEENL site; we act as a processor on your behalf.

4.3 · Do Not Track & Global Privacy Control

KEENL honors the Global Privacy Control (GPC) signal and the “Do Not Track” setting in your browser. When we detect either signal, we automatically opt you out of non-essential cookies and the sale or sharing of personal information (for the purposes of California law).

Section 05

Third-Party Services

To run KEENL reliably, we rely on a small number of carefully selected third-party processors. Each has signed a Data Processing Agreement (DPA) with us that complies with GDPR Article 28 and equivalent standards. Below is the current list — we update this page whenever a change is made.

Provider Purpose Location Data shared
Freemius Payment processing, fraud screening, tax handling EU Name, email, billing address, last 4 digits of card, IP
Cloudflare DNS, CDN, DDoS protection, security Global (edge network) IP, request metadata, TLS fingerprint
Amazon Web Services Website & database hosting, file storage US East / EU West (configurable) Customer site content, account data, uploaded files
OpenAI & Anthropic AI website generation, copy assistance United States Business prompts, generated content (no account identifiers sent)
Resend / Postmark Transactional & marketing email delivery United States / EU Email address, name, message content
Namecheap / Cloudflare Registrar Domain registration & DNS United States WHOIS contact data (name, address, phone, email)
Section 06

Sharing & Disclosure

We do not sell, rent, lease, or trade your personal information to third parties for their own marketing purposes. Full stop. We only share data in the following limited circumstances:

  1. With service providers that process data on our behalf under written agreements (listed in Section 05).
  2. With your consent when you explicitly direct us to share information — for example, when you transfer a Site Credit to another person.
  3. For legal reasons when we believe in good faith that disclosure is necessary to (a) comply with a valid subpoena, court order, or applicable law, (b) detect or prevent fraud, security incidents, or illegal activity, or (c) protect the safety, rights, or property of KEENL, our users, or the public.
  4. In a business transaction if KEENL is acquired, merged, or sells substantially all of its assets. You will receive advance notice by email and on this page.
  5. Aggregated, de-identified data that cannot reasonably be used to identify you — for example, “30% of KEENL sites are in the wellness industry.” This is not personal information.
Our zero-sale commitment

Even though some privacy laws only restrict “selling” in a narrow sense, we extend the same protection to all forms of paid data sharing. The only money that changes hands around your data is the $119 you pay us for a Site Credit — and even then, your data is not part of the transaction.

Section 07

Data Security

We take the security of your data seriously and have implemented technical and organizational measures aligned with SOC 2 and ISO 27001 standards. These include:

  • Encryption in transit: all data is transmitted over TLS 1.3 or higher.
  • Encryption at rest: all databases and file storage are encrypted using AES-256.
  • Password hashing: passwords are hashed with Argon2id and never stored in plaintext.
  • Access control: principle of least privilege, role-based access, mandatory MFA for all staff, and audited access logs.
  • Network security: Web Application Firewall (WAF), DDoS mitigation, IP allow-listing for administrative tasks, and segregated production environments.
  • Backups: encrypted, geographically redundant daily backups with point-in-time recovery, tested quarterly.
  • Vendor management: every third-party processor is vetted for security posture and bound by a DPA.
  • Incident response: a documented breach response plan with notification commitments of 72 hours to authorities and affected users when legally required.
  • Employee training: all KEENL staff complete mandatory privacy and security training upon hire and annually thereafter.

That said, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account password and for any activity on your account.

Section 08

Data Retention

We keep your personal data only as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are:

Data category Retention period Reason
Active account & site content While your account is active + 30 days after deletion Service operation, recovery window
Billing & transaction records 7 years after last transaction Tax, accounting, anti-fraud law
WHOIS / domain contact data Duration of registration + required retention period ICANN policy
Support correspondence 3 years after last contact Continuity of lifetime support
Server logs & security logs 90 days Security investigation window
Analytics data Aggregated: indefinite · Raw: 90 days Product improvement
Marketing email engagement Until you unsubscribe + 30 days Suppression list management
Backups 30 days rolling Disaster recovery

When the retention period expires, we either delete the data irreversibly or anonymize it so it can no longer be associated with you. If immediate deletion is not possible (for example, because the data is stored in an immutable backup), we isolate the data and delete it as soon as the backup cycle permits.

Section 09

Your Rights & Choices

You have meaningful control over your personal information. Depending on where you live, you may have some or all of the following rights:

01

Right to access

Request a copy of the personal data we hold about you, in a portable format.

02

Right to rectification

Ask us to correct any information that is inaccurate or incomplete.

03

Right to deletion

Request that we erase your personal data, subject to legal exceptions.

04

Right to restrict processing

Ask us to pause processing while a complaint is investigated.

05

Right to data portability

Receive your data in a structured, machine-readable format (JSON / CSV).

06

Right to object

Object to processing based on legitimate interest or for direct marketing.

07

Right to opt out of sale

Even though we never sell your data, California residents can formally opt out.

08

Right to withdraw consent

Where processing is consent-based, withdraw it at any time without retaliation.

09

Right to lodge a complaint

File a complaint with your local data protection authority if unsatisfied.

10

Right to non-discrimination

We will never penalize you for exercising your privacy rights.

9.1 · How to exercise your rights

You can exercise most of these rights directly from your account dashboard (Settings → Privacy) or by emailing support@keenl.com . We respond to verified requests within 30 days , free of charge. If your request is complex, we may extend the response time by up to two further months and will inform you of the reason and the new timeline.

Section 10

International Data Transfers

KEENL operates globally. When you use our Service from outside the United States, your data will be transferred to and processed in the United States and the European Union, where our primary infrastructure is located. We protect these transfers using the following safeguards:

  • Standard Contractual Clauses (SCCs): approved by the European Commission in June 2021, integrated into all our Data Processing Agreements.
  • UK International Data Transfer Agreement (IDTA): for transfers from the United Kingdom.
  • Data Privacy Framework (DPF): where applicable, we rely on the EU-US Data Privacy Framework for certified recipients.
  • Regional storage options: enterprise customers can elect to have their site and data hosted exclusively in the EU region.
  • Transparency reports: we publish an annual report on government access requests and publish our policies on responding to such requests.

If you would like a copy of the SCCs or more information about specific transfer mechanisms, contact support@keenl.com .

Section 11

Children’s Privacy

KEENL is a B2B service intended for adults operating legitimate businesses. The Service is not directed to children under the age of 16 (or such higher age as required by local law), and we do not knowingly collect personal information from children.

If you are a parent or guardian and believe your child has provided personal information to KEENL, please contact us at support@keenl.com and we will promptly delete the information. If you operate a KEENL-built website that knowingly collects data from minors (for example, an educational service), you are responsible for obtaining verifiable parental consent under applicable laws such as COPPA, GDPR-K, or PIPL.

Section 12

AI & Automated Decisions

KEENL uses artificial intelligence to generate your website content, suggest layouts, and assist our human support team. We want to be transparent about how this works and the choices we have made.

  • Your input is your data. Any business information, brand assets, or prompts you submit to the AI builder are used solely to generate your website and to refine it through your direct feedback. We do not use your private inputs to train foundation models.
  • No fully automated decisions with legal effect. We do not subject you to any decision based solely on automated processing that produces legal effects concerning you (Article 22 GDPR).
  • Human-in-the-loop. Every KEENL-built site is reviewed and approved by a human (you) before launch. Our support team — not a bot — handles all design and editing requests.
  • Model providers. We use OpenAI and Anthropic as sub-processors. Both providers have committed to not retaining or training on API inputs, and we have entered into zero-data-retention agreements where available.
  • Bias & accuracy. AI-generated copy is a starting draft. We encourage you to review, edit, and approve all content before publishing. KEENL does not guarantee the factual accuracy of AI-generated content.
Section 13

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. The “Last updated” date at the top of this page reflects when the most recent revision took effect.

For material changes — such as a new purpose of processing, a new category of recipient, or a change that affects your rights — we will provide at least 30 days’ advance notice by email and by a prominent in-app banner. We will not reduce your rights under this Privacy Policy without your explicit consent.

Previous versions of this Privacy Policy are archived and available on request.