Skip to content

Legal Center

Legal & Privacy.

Our commitment to your data privacy and our terms of service. Last updated July 2026.

Privacy Policy

At Keystone IQ, we take your privacy seriously. We collect minimal personal information necessary to provide our services. Your financial data is securely encrypted, and we do not sell your data to third parties.

Data Collection and Usage

When you create an account we collect your basic contact information (name, email, organization name) and your IP address at sign-up. When you upload financial documents, we temporarily process that data to generate insights and ledger entries for your portfolio.

IP Addresses and Approximate Location

We collect your IP address in two situations: when you submit a demo request from this marketing site, and when you create a Keystone IQ account. We use the IP transiently to look up your approximate country, region, and (for demo requests) city via a third-party geolocation provider. This helps us understand where our customers are based.

Demo requests: the IP is sent to our geolocation provider but is not stored — only the derived city/region/country is retained alongside your contact details.

Account registrations: the IP is retained alongside your account for security and abuse-prevention purposes.

Both signup and demo-request geolocation are visible to Keystone IQ operators in our internal support tools. Each lookup is recorded in our operator audit log with a typed reason (see Keystone IQ Operator Access below).

Bug reports & support data

When you submit a bug report through the in-app "Report a Bug" panel, the following may be collected:

  • Screenshots (optional, only if you attach one) — kept in our storage for up to 7 days, then automatically deleted. Viewable by Keystone IQ support staff during that window with a typed audit-logged reason.
  • Recent activity — your last 50 clicks within the app, captured as page names and button labels only. No form contents, input values, or query parameters are included.
  • Device context — viewport size, screen size, browser user-agent, and the page you were on when you submitted.

Bug-report submissions are mirrored to our internal issue tracker (Linear, listed below as a sub-processor) so engineering can follow up. You can request deletion of any individual report by emailing support@keystoneiq.app.

Third-Party Sub-Processors

To operate our service we share limited data with the following sub-processors:

  • Google Cloud Platform — Application hosting, database, and file storage.
  • Google Gemini / Vertex AI — AI-powered document extraction and analysis of uploaded financial documents.
  • Firebase Authentication — User identity and session management (sign-in and account security).
  • SendGrid — Transactional email delivery (account, billing, and portfolio notifications).
  • ipapi.co — IP-to-approximate-location lookup at account sign-up and demo request.
  • RentCast — Property valuation data — only queried when you request an automated valuation.
  • Plaid — Secure, read-only connection to your bank and mortgage accounts to import transactions and balances when you choose to link an account. Keystone IQ can never move money through this connection.
  • Stripe — Payment processing and subscription billing. Keystone IQ never sees or stores your raw card number — Stripe Elements collects payment details directly.
  • Mapbox — Property cover-image rendering and address geocoding for the Properties page.
  • Twilio — Optional SMS delivery for internal admin operational alerts — not customer-facing.
  • PostHog — Pseudonymous product usage analytics (keyed to your account ID, never your name) to help us improve the platform. Form inputs are masked in session replay.
  • Linear — Issue tracking — bug reports and demo requests are mirrored to a private workspace for engineering follow-up.
  • Sentry — Error monitoring — stack traces and request context for uncaught exceptions.
  • Better Stack — Uptime monitoring and the public status page (status.keystoneiq.app) — processes visitor IP addresses of people who view the status page; no customer account data.

Connecting a Bank or Mortgage Account (Plaid)

When you choose to link a bank or mortgage account, you authorize us to share the account information you select with Plaid, our financial-data connection provider, and you authorize Plaid to access, collect, use, and process that information in accordance with Plaid's End User Privacy Policy. Linking is entirely optional, the connection is read-only — Keystone IQ can never move money — and you can disconnect any account at any time from Settings → Connections, which revokes Plaid's access and destroys the stored access token.

The AI Data Promise

When you upload a document, our AI reads it and extracts the numbers — it never keeps a copy of your data to train on. The document itself is stored securely and encrypted at rest, and it's permanently deleted when you delete your account. We never use your private financial data to train public or shared AI models.

Keystone IQ Operator Access

"Operator" refers to a Keystone IQ employee with superadmin permission — engineering and support staff.

Keystone IQ operators have administrative access limited to the metadata required to support your account — organization name, member emails, subscription plan, aggregate usage counts, and property names. They do not see individual transactions, tenant details, or document contents. Every operator access is recorded in an audit log with a typed reason.

Every operator access is recorded in an audit log with a typed reason, viewable by every other operator. We review the access log on a quarterly cadence.

Data Retention & Deletion

We retain your account and financial data for as long as your account is active. If you close your account — or if your subscription lapses and is not renewed — we retain your data for a 30-day grace period so you can reactivate without losing anything, after which it is permanently deleted.

Permanent deletion removes your data across all of our systems, including transactions, properties, tenants, documents in the Document Vault, and any connected bank or mortgage accounts. Access to connected financial institutions (via Plaid) is revoked and the associated access tokens are destroyed.

You may request deletion of your account and data at any time from your account settings or by emailing support@keystoneiq.app. Verified erasure requests under GDPR and CCPA are honored.

This policy is reviewed at least annually and whenever applicable data-protection requirements change.

Your Rights

You can request a copy of your data, correct inaccurate information, or request deletion of your account at any time by contacting us at support@keystoneiq.app.

Right to Know

California residents — and any Keystone IQ user, since we extend this right to everyone — can ask what personal information we've collected, used, and shared, and why. The “Data Collection and Usage” and “Third-Party Sub-Processors” sections above describe exactly what we collect and who we share it with. For a copy of your own data, email support@keystoneiq.app.

Right to Delete

You can request deletion of your account and personal information at any time. See “Data Retention & Deletion” above for how this works — a 30-day grace period, then permanent removal of your data across all of our systems. To start a deletion request, email support@keystoneiq.app.

Right to Opt-Out of Sale or Sharing

Keystone IQ does not sell or share your personal information for cross-context behavioral advertising. There is nothing to opt out of today — if that ever changed, we would update this policy first. Questions about this? Email support@keystoneiq.app.

Right to Non-Discrimination

Exercising any of the rights above will never result in denied service, a different price or rate, or a lower quality of service. If you believe this hasn't been honored, email support@keystoneiq.app.