Legal & Privacy.

Our commitment to your data privacy and our terms of service. Last updated June 2026.

Privacy Policy

At Keystone IQ, we take your privacy seriously. We collect minimal personal information necessary to provide our services. Your financial data is securely encrypted, and we do not sell your data to third parties.

Data Collection and Usage

When you create an account we collect your basic contact information (name, email, organization name) and your IP address at sign-up. When you upload financial documents, we temporarily process that data to generate insights and ledger entries for your portfolio.

IP Addresses and Approximate Location

We collect your IP address in two situations: when you submit a demo request from this marketing site, and when you create a Keystone IQ account. We use the IP transiently to look up your approximate country, region, and (for demo requests) city via a third-party geolocation provider. This helps us understand where our customers are based.

Demo requests: the IP is sent to our geolocation provider but is not stored — only the derived city/region/country is retained alongside your contact details.

Account registrations: the IP is retained alongside your account for security and abuse-prevention purposes.

Both signup and demo-request geolocation are visible to Keystone IQ operators in our internal support tools. Each lookup is recorded in our operator audit log with a typed reason (see Keystone IQ Operator Access below).

Bug reports & support data

When you submit a bug report through the in-app "Report a Bug" panel, the following may be collected:

  • Screenshots (optional, only if you attach one) — kept in our storage for up to 7 days, then automatically deleted. Viewable by Keystone IQ support staff during that window with a typed audit-logged reason.
  • Recent activity — your last 50 clicks within the app, captured as page names and button labels only. No form contents, input values, or query parameters are included.
  • Device context — viewport size, screen size, browser user-agent, and the page you were on when you submitted.

Bug-report submissions are mirrored to our internal issue tracker (Linear, listed below as a sub-processor) so engineering can follow up. You can request deletion of any individual report by emailing support@keystoneiq.app.

Third-Party Sub-Processors

To operate our service we share limited data with the following sub-processors:

  • Google Cloud Platform — application hosting, database, file storage
  • Google Gemini Enterprise (formerly Vertex AI) — AI document extraction and analysis
  • Firebase Authentication — user identity and session management
  • SendGrid — transactional email delivery
  • ipapi.co — IP-to-approximate-location lookup at sign-up and demo request
  • RentCast — property valuation data (only when you request an AVM)
  • Plaid — secure connection to your bank and mortgage accounts to import transactions and balances when you choose to link an account (see Plaid's End User Privacy Policy)
  • PostHog — anonymized product analytics
  • Linear — issue tracking; bug reports and demo requests are mirrored to a private workspace for engineering follow-up
  • Sentry — error monitoring (stack traces, request context for uncaught exceptions)

The AI Data Promise

Our AI data extraction operates entirely in memory. When you upload a document, it is analyzed in secure temporary memory which is not saved, and the original document is discarded unless you explicitly opt into the Document Vault feature. We never use your private financial data to train public or shared AI models.

Keystone IQ Operator Access

"Operator" refers to a Keystone IQ employee with superadmin permission — engineering and support staff.

Keystone IQ operators have administrative access limited to the metadata required to support your account — org name, member emails, plan state, aggregate usage counts, and property names. They do not see individual transactions, tenant details, or document contents. Every operator access is recorded in an audit log with a typed reason.

Every operator access is recorded in an audit log with a typed reason, viewable by every other operator. We review the access log on a quarterly cadence. Customer-granted just-in-time access (a "support access" toggle in your Settings → Security panel) is on our near-term roadmap and will further restrict operator drill-downs to windows you explicitly open.

Data Retention & Deletion

We retain your account and financial data for as long as your account is active. If you close your account — or if your subscription lapses and is not renewed — we retain your data for a 30-day grace period so you can reactivate without losing anything, after which it is permanently deleted.

Permanent deletion removes your data across all of our systems, including transactions, properties, tenants, documents in the Document Vault, and any connected bank or mortgage accounts. Access to connected financial institutions (via Plaid) is revoked and the associated access tokens are destroyed.

You may request deletion of your account and data at any time from your account settings or by emailing support@keystoneiq.app. Verified erasure requests under GDPR and CCPA are honored.

This policy is reviewed at least annually and whenever applicable data-protection requirements change.

Your Rights

You can request a copy of your data, correct inaccurate information, or request deletion of your account at any time by contacting us at support@keystoneiq.app.