last updated: february 2026
keep.md does not collect, sell, or share any personal data with third parties. there are no analytics or advertising trackers. keep does use essential authentication cookies so you can sign in and manage your account securely.
when you save a link — via the chrome extension, cli, api, or x bookmark sync — the following data is stored in your keep.md account:
this data is stored in cloudflare d1 (metadata) and cloudflare r2 (content). it is only accessible to you via your authenticated account.
the chrome extension stores your api key locally in the browser's encrypted extension storage. when you save a page, the extension sends the url, title, and extracted markdown to your keep.md account over https. no data is sent to any other server.
if you connect your x (twitter) account, keep.md uses oauth to read your bookmarks. bookmark data (tweet urls, text, and linked page content when available) is stored only in your keep.md account. your x access token is encrypted and stored securely. you can disconnect at any time from the dashboard.
keep.md uses first-party authentication for sign-in, email verification, password reset, and account management. account emails are sent with resend.
paid plans are processed through stripe. keep.md does not store your payment details — stripe handles all payment processing. see stripe's privacy policy.
questions about this policy? reach out at @iannuttall on x.