Privacy notice
Keelix helps IT teams model the architecture of their identity systems. It is built to hold as little personal data as possible. Keelix stores the shape of your systems (their attributes, mappings, and provisioning plans) and deliberately stores no records about the people inside them. This notice explains what we collect, why, who processes it, and the choices you have.
Who this notice covers
This notice applies to the Keelix application at keelix.app and to everyone who signs in to a Keelix workspace. Keelix is currently in open beta. We will publish an updated notice, with a named operating entity and any added processors, before general availability.
Questions about anything below go to privacy@keelix.app.
What we collect
We collect only what is needed to operate a workspace:
- ·Account identity. Your email address and the identifier issued by our authentication provider when you sign in. Used to authenticate you and to send account and service notices.
- ·Workspace content. The systems, attributes, mappings, provisioning profiles, SCIM plans, playbooks, and schema snapshots you create or import. This is configuration about systems (column names, schema shapes, row counts), not the rows themselves.
- ·Membership records. Which workspaces you belong to and your role in each (owner, admin, editor, or viewer), plus the workspace names you choose.
- ·Activity log. Keelix is event-sourced: each change to a workspace is recorded with the acting user, the affected object, and a timestamp. This is what makes version history and audit replay possible.
- ·Operational logs. Standard server and request logs generated by our hosting and infrastructure providers, used to keep the service running and secure.
What we never collect
These are product commitments, enforced by design, not policy we could quietly change:
- ·Live data from Workday, Entra ID, Okta, NetSuite, or any other identity system. Keelix has no API integrations with identity systems; the only way data enters a workspace is by you typing it or uploading a CSV.
- ·Employee or person records. Keelix models the schema of your systems, never the people in them. There are no employee rosters and no per-person onboarding runs.
- ·Raw CSV rows. When you import a schema, we keep the column names and a row count to detect drift. The underlying rows are not stored.
- ·Anything you did not put into your workspace yourself.
How we use what we collect
- ·To authenticate you and keep your session secure.
- ·To store, render, version, and export your workspace content.
- ·To enforce workspace membership and role-based access.
- ·To operate, monitor, debug, and secure the service.
- ·To send essential account and service notices (for example, security or availability notices).
We do not sell personal data, and we do not use your workspace content to train models or for advertising.
Service providers
Keelix relies on a small number of established providers to run the service. Each processes data only to provide its function to us:
- ·WorkOS: authentication and sign-in. Processes your email and authentication identifiers.
- ·Neon: managed Postgres database. Stores your account record and workspace content.
- ·Vercel: application hosting and request handling.
Some integrations described elsewhere on our site are not yet active during the open beta and therefore process no data today: payments (Stripe) and product analytics are not wired up. When we enable them, we will list them here before they go live.
Cookies
Keelix sets a session cookie through our authentication provider so you stay signed in. It is required for the app to function. We do not run third-party advertising or analytics cookies during the open beta.
Security and isolation
- ·Each workspace is tenant-isolated: every database read is scoped to a single workspace, so your data is never co-mingled with another customer’s.
- ·Traffic to Keelix is served over TLS.
- ·Access to workspace content requires authentication and an appropriate membership role.
- ·The event log gives every workspace an immutable, replayable audit trail of changes.
No system is perfectly secure, but Keelix is designed to minimize the blast radius of any single failure by holding so little sensitive data in the first place.
Retention and deletion
We keep your account and workspace content for as long as your account is active. You can export everything in your workspace at any time, in open formats. When you delete a workspace or close your account, we delete the associated content within 30 days, retaining only what we must to meet legal obligations.
Your choices and rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, or to object to certain processing. Keelix is built to honor these directly: you can export your content and delete your workspace from within the app. For any request you can’t complete yourself, email privacy@keelix.app and we will respond.
Children
Keelix is a tool for workplace IT teams and is not directed to, or intended for, anyone under 16. We do not knowingly collect data from children.
Changes to this notice
We may update this notice as the product evolves, for example when we enable billing or analytics, or name our operating entity at general availability. Material changes will be reflected in the “Last updated” date above, and significant changes will be communicated by account notice.
Contact
Privacy questions and requests: privacy@keelix.app. For terms and contractual matters, see our terms of service.