ElseKept has no user account, advertising profile or application telemetry. The app encrypts backup content on your Mac before sending encrypted bytes to storage locations you choose.
What stays on your Mac
The app keeps its backup plans, local catalog, recovery status and configuration on your Mac. Encryption and decryption happen locally. Repository keys, Recovery Kit identities and provider credentials are treated as secrets. Device credentials and OAuth tokens are stored in the macOS Keychain rather than in the backup catalog or app logs.
Files and backup content
ElseKept reads only the locations selected by the user and the supported locations included by a chosen backup preset, subject to macOS permissions. Backup content is encrypted before it leaves the Mac. Encrypted repository data is sent only to the filesystem, iCloud Drive, S3-compatible storage, WebDAV, Google Drive or Dropbox destination that the user configures.
ElseKept does not operate a cloud that receives plaintext backups. The developer cannot browse a user’s backup contents.
Google Drive
ElseKept requests only https://www.googleapis.com/auth/drive.appdata. This allows the app to create and manage encrypted ElseKept objects in Google Drive’s hidden application-data storage. It does not allow ElseKept to browse, read or modify ordinary Drive files. Google access and refresh credentials remain in the local macOS Keychain.
ElseKept’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Dropbox
ElseKept uses Dropbox App Folder access. This limits the app to encrypted objects inside its own dedicated Dropbox folder and does not allow access to unrelated Dropbox files. Dropbox automatically includes read-only access to basic Dropbox account information, specifically the account name, email address and country. ElseKept does not use that information or call Dropbox account-profile APIs. Dropbox access and refresh credentials remain in the local macOS Keychain.
Disconnecting, revoking and deleting provider data
Removing a backup plan from ElseKept removes that plan and its device credentials from the local app, but intentionally leaves encrypted remote backup data and the Recovery Kit intact. Users can revoke ElseKept access at any time from their Google or Dropbox account security settings.
Revocation stops future access but does not itself erase encrypted objects already stored by the provider. Google users can delete ElseKept’s hidden app data from Google Drive’s Manage apps settings. Dropbox users can delete the ElseKept App Folder from Dropbox. For help identifying the correct provider data, contact [email protected].
Application diagnostics
ElseKept does not send application telemetry or automatic crash reports. Activity and errors stay local unless the user deliberately exports diagnostic information or sends it to support. Diagnostic exports are designed to exclude credentials and plaintext filenames where possible, and users should review anything they choose to send.
Website measurement
The website may use Cloudflare Web Analytics for aggregate traffic measurement. It does not use advertising trackers, cross-site profiling or marketing cookies. Cloudflare processes ordinary web request information needed to deliver and protect the site under its own privacy terms.
Purchases and license delivery
Stripe Managed Payments and Link process checkout, payment details, taxes, receipts, refunds, fraud controls and transaction support as the merchant of record under their own privacy terms. ElseKept does not receive or store card details. The commerce service keeps only the Stripe identifiers required to verify a paid purchase or full refund, a keyed one-way value derived from the normalized purchase email, the signed license, issuance time, refund time and delivery state.
The email address supplied at checkout is used in memory to send the license and is not stored in plaintext by ElseKept’s commerce database. A license-recovery request produces the same public response whether or not a purchase exists. Matching requests receive a short-lived, single-use recovery link.
Support email
If a user emails support, the developer receives the address, message and attachments the user voluntarily sends. This information is used only to answer the request, diagnose the reported issue and maintain necessary correspondence. It is not sold, used for advertising or added to a marketing list.
Withdrawal and refund requests
The online withdrawal form sends the submitted purchase email, optional purchase date and optional receipt reference through the same support email system. The requester receives an immediate acknowledgement and ElseKept receives a copy for processing. The form does not add the email address or request details to the commerce database.
Retention and disclosure
The ElseKept app does not transmit an account, activation record, device identifier or telemetry. Minimal commerce records are retained as needed for license recovery, reconciliation, fraud prevention and legal obligations. Support correspondence is retained only as long as reasonably needed for support, security and legal records. Information may be disclosed when required by applicable law or to protect users and the service, but ElseKept does not sell personal information.
Your questions and requests
For privacy questions, access requests or deletion questions concerning information sent directly to the developer, email [email protected]. Purchase requests involving payment records may also need to be handled by Link as merchant of record. Requests concerning data held by Google, Dropbox, Apple, a storage provider or a web host may need to be directed to that provider.
Changes to this policy
Material changes will be published on this page with a revised effective date. Product behavior and public claims will be kept aligned with the released application.