← KeepSpec

Privacy Policy

Last updated 22 September 2026

KeepSpec is operated by KeepSpec, LLC of 30 E. Washington St., Suite 400, Shelbyville, IN 46176 (“we”). This policy describes what the service stores, where it is held, who else processes it and how to have it removed. It is written to be checked against the software rather than to sound reassuring.

Ownership and publishing

The KeepSpec service is operated and billed by KeepSpec, LLC, an Indiana limited liability company. The KeepSpec mobile applications are published on the Apple App Store and Google Play by Tubesock, Inc., under a licensing arrangement with KeepSpec, LLC. Tubesock, Inc. is a registered Indiana assumed business name (d/b/a) of Rob Nolley, Inc., an Indiana corporation; you may therefore see “Rob Nolley, Inc.” listed as the seller on the App Store until Apple’s seller display reflects the Tubesock name. KeepSpec, LLC and Rob Nolley, Inc. share common ownership. Your commercial relationship — including your subscription, billing, and support — is with KeepSpec, LLC.

Who the data belongs to

Almost everything in KeepSpec is entered by a customer about their own operations: plants, production lines, machines, fluids and the readings taken from them. That content belongs to the customer. We hold and process it on their behalf and do not sell it, share it with other customers, or use it to train anything.

We sell no metalworking fluid and have no commercial interest in what any plant is using. That is the product’s reason to exist, and it is a commitment about our business model, not only about our servers.

What we store

AccountName and email address, held by our authentication provider. We never receive or store a password.
OrganizationThe organization name, its subscription tier and status, and each member’s role.
Operational recordsSites, production lines, machines, fluids and their specification ranges.
ChecksFor each reading: the date and time, Brix, pH where recorded, calculated concentration, whether a condition was noted and any free-text note, plus which user recorded it and their display name.
DevicesA push notification token per installed app, so out-of-range alerts can reach the right handset.
BillingA customer and subscription identifier issued by Stripe. Card details are entered directly with Stripe and never reach our systems.
Audit fieldsWho created or last modified a record, and when.

The free-text condition note is the one field where a technician could type something about a person. It is intended for the state of the fluid, and we ask customers to keep it to that.

The KeepSpec product — the mobile app and web console where you log fluid readings — has no analytics, no advertising identifiers, and no third-party tracking. Its screens are not measured, and no session or usage data leaves your device or browser beyond what the app requires to function.

The marketing site at keepspec.com is separate. It uses Google Analytics via Google Tag Manager (measurement ID G-364GTEL6GT) to understand which pages visitors read. This is limited to marketing pages — the product’s app and console include no such measurement. Google Analytics sets cookies on your browser when you visit the marketing site; you can opt out with the Google Analytics Opt-Out Browser Add-On.

Where it is held

The database is hosted in the United States (Ohio). Encrypted backups are replicated between two United States regions. Customers outside the United States, including in Japan and the EEA, should treat use of KeepSpec as a transfer of their data to the United States.

Who else processes it

These are our sub-processors. Each is used for a specific purpose and receives only what that purpose needs.

ClerkAuthentication and organization membership. Holds names, email addresses and credentials.
NeonThe PostgreSQL database.
RailwayHosts the API.
VercelHosts the web console.
SentryReceives exception reports from our backend API when unhandled errors occur. Reports include stack traces and HTTP request metadata (path, method, status code) — never a request body, and never an organization or user identifier. Used to detect and fix bugs in production.
StripeSubscriptions and payment. Holds card details; we do not.
ExpoRelays push notifications to Apple and Google, and delivers app updates to the mobile app (EAS Update). Each update check sends the app’s version, platform and update channel — no account or operational data.
Apple / GoogleDeliver push notifications to devices.
ResendSends operational email to us — for example, that a new organization has signed up.
Microsoft AzureStores encrypted database backups.
GitHubRuns the scheduled backup process.

We will update this list before adding a sub-processor that handles customer content.

How long it is kept

Customer content is kept for as long as the organization exists. A lapsed subscription does not delete anything — the account becomes read-only, and its history stays readable. We think a compliance record you can be locked out of is not a compliance record.

Encrypted backups are taken hourly and kept for seven days, and nightly and kept for approximately thirteen months. Deleted data therefore persists in backups until those age out. We do not delete individual records from historical backups; doing so would compromise their integrity as a recovery mechanism.

Deleting your account

You can delete your own account from the mobile app, under Account. What happens depends on your situation:

  • If colleagues remain in your organization, your login, your profile and your device registrations are deleted. The checks you recorded remain, because each is a statement that a particular machine was measured on a particular date — the record would otherwise acquire gaps. Your name and username are removed from them.
  • If you are the last member, deleting your account also deletes the organization and everything in it, including all recorded history. The app tells you this, with the actual number of sites and checks, before asking you to confirm.

Deletion from the live database is immediate. Backups age out as described above.

Security

Each organization’s data is isolated at the database layer, and every query is filtered by organization by default rather than by remembering to add a condition. Backups are encrypted with AES-256 before leaving our infrastructure, and the credential used to upload them can create backups but cannot read or delete existing ones.

No system is perfectly secure. If we discover a breach affecting customer content, we will contact affected customers directly.

Your rights

Depending on where you live you may have rights to access, correct, export or erase your personal data, and to object to or restrict its processing. Account holders can do most of this in the product; for anything else, write to us and we will respond within 30 days.

Where a customer organization is the controller of the data and we are the processor, we will refer individual requests to that organization.

Children

KeepSpec is a tool for industrial workplaces and is not directed at children.

Changes

If we change this policy materially we will update the date above and notify account administrators by email before the change takes effect.

Contact

hello@keepspec.com — or P.O. Box 26, Shelbyville, IN 46176.