Privacy Policy
Last updated 22 September 2026
KeepSpec is operated by KeepSpec, LLC of 30 E. Washington St., Suite 400, Shelbyville, IN 46176 (“we”). This policy describes what the service stores, where it is held, who else processes it and how to have it removed. It is written to be checked against the software rather than to sound reassuring.
Ownership and publishing
The KeepSpec service is operated and billed by KeepSpec, LLC, an Indiana limited liability company. The KeepSpec mobile applications are published on the Apple App Store and Google Play by Tubesock, Inc., under a licensing arrangement with KeepSpec, LLC. Tubesock, Inc. is a registered Indiana assumed business name (d/b/a) of Rob Nolley, Inc., an Indiana corporation; you may therefore see “Rob Nolley, Inc.” listed as the seller on the App Store until Apple’s seller display reflects the Tubesock name. KeepSpec, LLC and Rob Nolley, Inc. share common ownership. Your commercial relationship — including your subscription, billing, and support — is with KeepSpec, LLC.
Who the data belongs to
Almost everything in KeepSpec is entered by a customer about their own operations: plants, production lines, machines, fluids and the readings taken from them. That content belongs to the customer. We hold and process it on their behalf and do not sell it, share it with other customers, or use it to train anything.
We sell no metalworking fluid and have no commercial interest in what any plant is using. That is the product’s reason to exist, and it is a commitment about our business model, not only about our servers.
What we store
| Account | Name and email address, held by our authentication provider. We never receive or store a password. |
|---|---|
| Organization | The organization name, its subscription tier and status, and each member’s role. |
| Operational records | Sites, production lines, machines, fluids and their specification ranges. |
| Checks | For each reading: the date and time, Brix, pH where recorded, calculated concentration, whether a condition was noted and any free-text note, plus which user recorded it and their display name. |
| Devices | A push notification token per installed app, so out-of-range alerts can reach the right handset. |
| Billing | A customer and subscription identifier issued by Stripe. Card details are entered directly with Stripe and never reach our systems. |
| Audit fields | Who created or last modified a record, and when. |
The free-text condition note is the one field where a technician could type something about a person. It is intended for the state of the fluid, and we ask customers to keep it to that.
The KeepSpec product — the mobile app and web console where you log fluid readings — has no analytics, no advertising identifiers, and no third-party tracking. Its screens are not measured, and no session or usage data leaves your device or browser beyond what the app requires to function.
The marketing site at keepspec.com is separate. It uses Google Analytics via Google Tag Manager (measurement ID G-364GTEL6GT) to understand which pages visitors read. This is limited to marketing pages — the product’s app and console include no such measurement. Google Analytics sets cookies on your browser when you visit the marketing site; you can opt out with the Google Analytics Opt-Out Browser Add-On.
Where it is held
The database is hosted in the United States (Ohio). Encrypted backups are replicated between two United States regions. Customers outside the United States, including in Japan and the EEA, should treat use of KeepSpec as a transfer of their data to the United States.
Who else processes it
These are our sub-processors. Each is used for a specific purpose and receives only what that purpose needs.
| Clerk | Authentication and organization membership. Holds names, email addresses and credentials. |
|---|---|
| Neon | The PostgreSQL database. |
| Railway | Hosts the API. |
| Vercel | Hosts the web console. |
| Sentry | Receives exception reports from our backend API when unhandled errors occur. Reports include stack traces and HTTP request metadata (path, method, status code) — never a request body, and never an organization or user identifier. Used to detect and fix bugs in production. |
| Stripe | Subscriptions and payment. Holds card details; we do not. |
| Expo | Relays push notifications to Apple and Google, and delivers app updates to the mobile app (EAS Update). Each update check sends the app’s version, platform and update channel — no account or operational data. |
| Apple / Google | Deliver push notifications to devices. |
| Resend | Sends operational email to us — for example, that a new organization has signed up. |
| Microsoft Azure | Stores encrypted database backups. |
| GitHub | Runs the scheduled backup process. |
We will update this list before adding a sub-processor that handles customer content.
How long it is kept
Customer content is kept for as long as the organization exists. A lapsed subscription does not delete anything — the account becomes read-only, and its history stays readable. We think a compliance record you can be locked out of is not a compliance record.
Encrypted backups are taken hourly and kept for seven days, and nightly and kept for approximately thirteen months. Deleted data therefore persists in backups until those age out. We do not delete individual records from historical backups; doing so would compromise their integrity as a recovery mechanism.
Deleting your account
You can delete your own account from the mobile app, under Account. What happens depends on your situation:
- If colleagues remain in your organization, your login, your profile and your device registrations are deleted. The checks you recorded remain, because each is a statement that a particular machine was measured on a particular date — the record would otherwise acquire gaps. Your name and username are removed from them.
- If you are the last member, deleting your account also deletes the organization and everything in it, including all recorded history. The app tells you this, with the actual number of sites and checks, before asking you to confirm.
Deletion from the live database is immediate. Backups age out as described above.
Security
Each organization’s data is isolated at the database layer, and every query is filtered by organization by default rather than by remembering to add a condition. Backups are encrypted with AES-256 before leaving our infrastructure, and the credential used to upload them can create backups but cannot read or delete existing ones.
No system is perfectly secure. If we discover a breach affecting customer content, we will contact affected customers directly.
Your rights
Depending on where you live you may have rights to access, correct, export or erase your personal data, and to object to or restrict its processing. Account holders can do most of this in the product; for anything else, write to us and we will respond within 30 days.
Where a customer organization is the controller of the data and we are the processor, we will refer individual requests to that organization.
Children
KeepSpec is a tool for industrial workplaces and is not directed at children.
Changes
If we change this policy materially we will update the date above and notify account administrators by email before the change takes effect.
Contact
hello@keepspec.com — or P.O. Box 26, Shelbyville, IN 46176.