Effective September 1, 2026 · Keptcase, by Pagani Enterprises LLC
The short version: your collection lives on your phone. Cloud backup is optional and off until you turn it on. We don't run ads, we don't use analytics or tracking, and we never sell your data. Ever.
Everything you put into Keptcase — your movies, music, books, games, ratings, diary entries, notes, values, and cover photos — is stored locally on your device by default. If you never enable Cloud Backup, none of it leaves your phone, and we have no copy of it. Deleting the app deletes this data.
If you turn on Cloud Backup, you sign in with Apple and we store the following so your collection can be restored on a new phone:
Backups are stored with our database provider, Supabase, and are used for exactly one purpose: backing up and restoring your collection. You can erase all cloud data or delete your account entirely from Settings → Cloud Backup at any time — deletion removes your backup, your photos, and your account from our servers.
If you choose to publish a shelf, the items on it, the display name you enter, and any social handles you add become visible to anyone with your shelf's link. Publishing is opt-in per shelf, and you can unpublish at any time, which removes the public page.
When you search for a title, scan a barcode, or fetch a price, the app sends the search text or barcode — never your identity — to metadata providers: TMDB (movies & TV), IGDB (games), Discogs and the iTunes Search API (music), Open Library and MusicBrainz (books & music), and our own service backed by PriceCharting and eBay, which handles both barcode matching and price estimates. Comics are matched against the Grand Comics Database and Metron; the "Where else it's playing" card reads streaming availability from JustWatch through TMDB; and "Ask the film" fetches a plot summary from Wikipedia by title. These requests are how any lookup app works; they're not linked to an account and we don't log them against you. Our lookup service does keep two operational records: a per-barcode note of whether a lookup found anything (no account, no device identity), and a count of requests per network address for a day so that one runaway client cannot exhaust the shared quota for everyone else. The address itself is not stored: it is turned into a one-way daily key (an IPv6 address is first cut to its network half, then hashed with a secret that changes every day), the counters expire with their day, and a log of refusals and provider failures keeps the same key for 14 days and is then deleted. Neither is joined to your collection, your backup or your published shelf.
When you scan a barcode and save the item, Keptcase sends that barcode along with the title, format and edition you kept to a shared catalog, so the next person who scans the same disc gets a match instead of a blank form. It carries a random identifier created by the app on your device — not your name, not your account, and nothing Apple or anyone else can trace back to you. It exists only so one install cannot vote for the same barcode twice. Nothing else about your collection is sent, and none of it is joined to your backup or your published shelf.
If you join the waitlist on keptcase.app, we store the email address you enter and use it only to contact you about access to the app. Ask us to remove it at any time.
Keptcase is not directed at children under 13, and we don't knowingly collect data from them.
If this policy changes, the new version will be posted at this address with an updated effective date. Material changes to what's collected will be called out in the app.
Questions or requests about your data: privacy@paganienterprises.com.