Last updated: 26 July 2026
Keply is a customer-success tool. It reads the accounts, email, support and usage data you connect, scores which customers are at risk, and drafts the outreach for a person to approve before anything sends.
If a colleague forwarded this to you, it answers the questions a security reviewer asks: what we read, what we keep, where it goes, and how to switch it off. No NDA, no form, no call.
The short version
Keply reads the sources you connect, and you connect them one at a time. These are the permissions verbatim, as they appear on the provider's own consent screen. There is one thing Keply reads that you do not connect — the public web — and it is described immediately below the table rather than buried.
| Source | Permissions requested | What that actually allows |
|---|---|---|
| Gmail / Google | gmail.readonly, gmail.compose, openid, email, profile | Read mail and create drafts. Google's compose scope also permits sending, which is how Keply sends the mail you approve. It cannot delete mail or change settings. |
| Microsoft 365 / Outlook | Mail.Read, Mail.Send, User.Read, offline_access | Read mail and send mail. Mail.Send is full send, not draft-only. It cannot delete mail or read files. |
| Slack (default) | channels:history, channels:read, groups:history, groups:read, mpim:history, mpim:read, im:history, im:read, users:read, users:read.email | Keply connects with a user token, so it reads the conversations the connecting person can already see: their channels, group DMs and 1:1 DMs. It does not read the workspace. By default Keply has no write scope, so it cannot post to Slack. |
| Slack (only if you turn on replies) | chat:write, reminders:write | Keply can only post to Slack if you grant a write scope, by enabling replies and reminders through a separate re-authorization. It never happens on its own. |
| CRM, billing, support, usage | Per-provider API key or OAuth | Read access to the objects Keply scores: accounts, contacts, subscriptions, tickets, usage. Keply asks for read-only keys where the provider offers them. |
Two cells above are worth reading twice. Google's gmail.composepermits sending, not only drafting, which is how Keply sends the mail you approve. Slack's read set covers direct messages, though only those of the person who connects it, and Keply has no write scope there unless you add it.
Keply also searches the public web for business news about your accounts — funding rounds, layoffs, acquisitions, executive changes — because those events move renewal risk before anything shows up in your own data. This runs on a schedule as part of the daily analysis, not because anyone clicked search.
What leaves Keply is the account's company name and website domain, and nothing else: no contact names, no email content, no usage or revenue figures. That text becomes a search query. It goes to Anthropic, whose model runs the search server-side, so Anthropic and its search provider see the company name you asked about. What comes back is stored as a signal with a headline, a one-line summary and the source link, so every finding can be traced to the article it came from.
Two honest limits. This is on for every account — there is no per-account or per-organization switch to turn it off today; if you need one, say so and we will build it. And the companies searched are your customers, so if the mere fact that you are evaluating an account is sensitive, that fact is what leaves. Everything here is public information about companies, not personal data about individuals.
We read the text of the messages you connect. That is how sentiment, tone and risk are scored, and it is sent to Anthropic for inference under commercial terms that prohibit training on your data. We would rather say that plainly than imply we score your relationships without reading them, which would not be true.
We do not open attachments. PDFs and files are never downloaded or parsed. Keply sees the file name only, and flags it in the summary so a person knows to open the message and look. That is a limit in how the product is built, not a setting.
What Keply keeps is the result rather than the message. For each signal from mail or Slack it retains:
Pasted call transcripts work the same way: Keply keeps the summary and the length, not the transcript.
Other things you give Keply are kept as written:
These are the providers Keply sends data to. Each is engaged under data-protection terms, or is being brought under them as we complete our vendor review, and processes personal data only to provide its function. This list forms part of our Data Processing Addendum; we give advance notice by email or in-app before adding or replacing a provider.
| Provider | Purpose | Data | Region |
|---|---|---|---|
| Supabase | Database, authentication, storage, edge functions | All application & customer data | Configured region |
| Cloudflare | Frontend hosting, CDN, TLS, WAF | App delivery; request metadata | Global edge |
| Anthropic | AI model (Claude) for scoring & drafting, no training on your data | Account context and message text sent as prompts | United States |
| Polar | Subscription billing & payments (merchant of record) | Billing contact, subscription & payment metadata | United States / Global |
| Gmail: reads mail as a signal, and sends the mail you approve (when connected) | Email metadata & content; your name and address for sign-in | Global | |
| Microsoft | Outlook/365: reads mail as a signal, and sends the mail you approve (when connected) | Email metadata & content | Global |
| Slack | Reads the conversations you connect as a signal, and posts the messages you approve (when connected) | Message text & metadata from the channels and DMs the connecting user can see; the text of anything Keply posts back | United States / Global |
| Resend | Sends Keply's own email to your team — daily briefings and teammate invitations. Never used for outreach to your customers | Your teammates' email addresses, and the briefing text, which names accounts and their risk | United States |
| PostHog | Product analytics (opt-in where required, notice-based elsewhere) | Usage events, pageviews | United States |
| Microsoft Clarity | Session analytics & replay on our public marketing pages only (opt-in where required, notice-based elsewhere) | Interactions with our marketing pages. It is not enabled on the signed-in product, so it never records your customer data | United States |
| Google Analytics | Web analytics (opt-in where required, notice-based elsewhere) | Pageviews, traffic sources | United States |
The tools you connect as sources only (your CRM, billing, support, usage and survey systems, including Stripe, Pendo and Delighted) are not on this list, because Keply reads from them and sends nothing back. They stay governed by whatever agreement you already hold with each provider, and you can disconnect any of them at any time.
Google, Microsoft and Slack are on the list, and the reason is worth stating: Keply both reads from them and sends through them, so data flows outward. That is the test for this table — not whether you or we set the account up, but whether your data leaves Keply toward it.
An admin in your organization can disconnect any connection from Settings → Connections at any time, without contacting us. That erases the stored credential and stops all syncing immediately.
For Slack and Gmail we also call the provider's own revoke endpoint, so access ends at the source and not just in our copy of it. For Microsoft and for key-based connectors we erase our stored credential, which ends all Keply access. You can also revoke Keply from your own Google, Microsoft or Slack admin console, and that takes effect regardless of anything we do.
You can export your core data yourself, at any time, from Settings → Export: accounts, contacts, signals, health scores and risks, as an Excel workbook or as CSV per entity. It needs no request and no notice period, so leaving Keply does not require our cooperation.
To have your data deleted, email [email protected]. We acknowledge within 5 business days and complete within 30 days, then confirm in writing. That covers accounts, contacts, signals, scores, drafts and stored credentials. Backups age out on their normal cycle. Deletion runs by hand today, by a named person rather than a background job, so the confirmation comes from someone who can answer for it.
If you stop using Keply without asking for deletion, we delete or return your data within 30 to 90 days of termination, as set out in the DPA.
Data is encrypted in transit with TLS and at rest with AES-256. Integration access tokens are encrypted with an application-managed key and are never stored in plain text; API keys are stored only as hashes. Keply is multi-tenant, and organizations are isolated at the database layer by deny-by-default row-level security, so one customer's data is not reachable from another's session.
Keply is governed by an autonomy dial that starts at draft-for-approval, so actions that contact your customers require a human to approve them until you decide otherwise, and every action Keply takes is written to an audit log.
Every change is version-controlled and validated on a staging environment first. The production branch cannot be pushed to directly, including by an administrator: a change lands only through a pull request whose required checks have all passed, among them a full replay of every database migration from scratch. Detail is on the Security page.
Keply does not hold a SOC 2 report. Our controls are self-assessed. Keply has not completed an independent third-party SOC 2 examination, and a SOC 2 report can be issued only by a licensed CPA firm following one. We will update this page if and when one is issued.
What we do have is an information-security program designed and operated to align with the AICPA Trust Services Criteria for Security, Availability and Confidentiality, documented in a control matrix and a written policy set covering information security, incident response including the GDPR 72-hour breach clock, data retention and deletion, access control, vendor risk, and data-subject requests. We share that documentation and complete security questionnaires on request, without an NDA.
For our privacy commitments and the rights available to individuals, see the Privacy Policy. For the contractual terms covering our processing on your behalf, see the Data Processing Addendum.
Forwarding this to your security reviewer?
Paste this:
Subject: Security review, Keply
Hi, we want to use Keply for customer success. It connects to our email, Slack and CRM, and drafts outreach that a person approves before it sends. Their trust page covers what it reads, what it stores, where the data goes, and how to revoke and delete it: keply.ai/trust
Short version: they read message text to score it, under terms that prohibit training on our data, and keep a summary rather than the message. They never open attachments. We can disconnect from settings at any time. Their SOC 2 controls are self-assessed and they do not hold a report yet. Anything blocking?
Security questions and vulnerability reports both go to [email protected]. If you believe you have found a vulnerability, we appreciate responsible disclosure and will acknowledge your report.