Privacy

Privacy, in plain terms

KeepThisProduct can process product photos, stage private scene previews, open card checkout, and deliver purchased files. The workbench does this without requiring an account. This page explains what leaves your device, what remains local, and how long delivery records stay available.

Product references and generated scenes

When you use the scene workbench, the hero product photo and optional label-detail reference are uploaded to private object storage. They are sent server-to-server to our image engine with the chosen product-scene instructions. Generated full-resolution results remain private; before purchase, the browser receives only a reduced, visibly watermarked preview. If the required image reduction cannot be verified, the preview fails closed instead of returning the full-resolution file.

Job, batch, attempt, authorization-version, and recovery records are stored for up to 30 days. A verified purchase anchors the download expiry to 30 days after fulfillment. Signed links cannot extend that purchase date. Storage lifecycle rules provide the corresponding object cleanup; contact [email protected] if you need help with a current batch. Do not upload confidential product material that you are not comfortable sending to the staging engine.

Payment and email delivery

Card checkout is provided by Stripe through the payment account used for KeepThisProduct. Checkout discloses the literal card-statement descriptor ETP* KEEPPRODUCT. KeepThisProduct sends the selected pack, job and batch identifiers, contract version, source page, and first-touch campaign fields into checkout metadata. The server grants scene places only after a correctly signed paid webhook; a return URL by itself is never treated as payment proof. KeepThisProduct does not receive or store your full card number.

If you enter an email address for recovery, it is stored with the purchased batch for the delivery period. Delivery email uses Maileroo and sends from [email protected] only when the domain-specific sending key is configured. Until that key exists, the address is saved but no message is sent; the private recovery link remains available on screen. The send endpoint is capped at three attempts per batch.

Analytics and abuse controls

We record workbench events such as start viewed, upload started, preview ready, checkout started, and a client purchase confirmation. Verified revenue is recorded separately from the signed payment webhook so browser redirects cannot create money truth. Source-page and first-touch campaign fields help distinguish acquisition paths. We do not sell product photos or use them to build advertising profiles.

To control inference spend and trivial replay, the service records a monthly IP-based free-preview allowance, daily run budget, short-lived reservations, and engine-spend telemetry. The allowance is one successful free preview per IP per calendar month; failed engine calls restore that allowance. Paid work does not stop when the free-run budget is reached.

The listing size checker stays on your device

The separate listing image size checker reads an image entirely within your browser to measure dimensions and draw crop guidance. That checker image is not uploaded, transmitted, or stored and continues to work after the page has loaded even if you disconnect. Using the checker does not create a staging job.

Contact

Questions about product-photo handling, a delivery record, or this page can go to [email protected]. This page was last updated on 13 July 2026.