Frequently asked questions
216 questions, gathered from every page on this site. Each group links back to the page it came from, where the same answer sits in its full context.
Keepsake — Secure Personal Document Vault
From the home page
Can Keepsake read my documents?
No. Every document is encrypted with AES-256-GCM on your device before it is stored or synced anywhere. The encryption key is derived from your password with Argon2id and never leaves your device. We run no servers that hold your documents — there is nothing for us (or anyone who compromises us) to read.
Where are my documents stored?
On your own devices, and — if you enable sync — in a private app folder of your own Google Drive or OneDrive, or any folder/WebDAV location you choose. They are encrypted before they leave your device, so your cloud provider only ever sees ciphertext.
What happens if I forget my password?
When you create a vault, Keepsake gives you a printable Recovery Kit with a 24-word phrase that can restore access. Keep it somewhere safe (it is always free — safety is never an upsell). Without your password or recovery kit, nobody can decrypt the vault — including us.
What happens if Keepsake shuts down?
Your vault keeps working. The apps run entirely on your devices, licenses are verified offline, and the vault format is documented so your data is never held hostage. Our tagline is literal: the vault works even if we disappear.
Is the free tier actually useful?
Yes — 25 documents per device with full encryption, OCR auto-filing, categories, search and expiry reminders. That is the real set a household has, not a sample of it: both passports, the driving licences, the car, the house, the utilities and the medical papers. Premium adds unlimited documents, sync between devices and the convenience features.
How does OCR work without a server?
The text recognition runs on your device: PurpleOCR on Windows, ML Kit on Android, and WebAssembly OCR in the browser. A shared rules engine then reads the text to suggest the category, expiry date, document number and tags. Nothing is uploaded for processing.
Which platforms are supported?
Windows (desktop app), Android, and any modern browser via the installable web app — which also works offline and covers iPhone/iPad. One vault syncs across all of them through your own cloud.
How do I pay?
Request an upgrade and we send an invoice with bank transfer details (IBAN / Wise). When payment arrives you receive a signed license key by email — paste it into any app; it activates offline. You can get a full refund any time before that key is emailed; once it is sent the sale is final, because an offline key cannot be revoked. The free tier never expires, so you can try Keepsake first.
Agents & resellers
From /agents
How do I get paid?
By bank transfer, on the same schedule you invoice us — monthly is usual. You are paid on keys that were actually issued, which means the customer paid. A request that was invoiced but never settled earns nothing, for either of us.
Do I have to handle money?
No, and it is simpler if you do not. The customer requests an invoice with your code on it, pays us directly, and you are paid your commission. If a customer would rather pay you locally in cash, that is between you and them — tell us and we will invoice you instead.
What if someone forgets to type my code?
Tell us who they are and we will attach it. The field is on the form and pre-fillable with a link (securekeepsake.com/upgrade?agent=YOUR-CODE) — send that link and the code fills itself in.
Do I get customer data?
No. You see nothing about the customer's documents, because we cannot see them either. You get told which of your introductions converted, and that is all there is to know.
Can I resell to my own clients under my own invoice?
Yes. Tell us and we will invoice you at the commission-adjusted price; you charge your client whatever you like. That is the usual arrangement for IT shops and consultants.
What would end the arrangement?
Promising things Keepsake does not do. We publish honest limitations — including the ones our OCR loses on — and an agent selling around them costs us more than the sale is worth. Otherwise, nothing: codes do not expire.
PurpleOCR — document OCR for .NET on Windows
From /purpleocr
Is there a free tier?
There is a 30-day evaluation, which covers development and CI. Shipping — in a product, on a server, or as part of a service — needs a paid licence. There is no free production tier, because the honest alternative to a paid licence is an abandoned side project, not a generous one.
How do I pay for a PurpleOCR licence?
By invoice and bank transfer. Write to hello@securekeepsake.com with the licence you want and your billing details; you get an invoice, and the licence on payment. No card processor is involved.
Is it open source?
No. The source is not published and the package is commercially licensed. It builds on open-source components — Tesseract, OpenCV, ONNX Runtime, PDFium, ZXing — whose licences are listed in the package and unaffected by this one.
Why Windows only?
It depends on GDI+, PDFium and the Windows OpenCV runtime. A cross-platform build is possible but is not something to claim before it has been tested, so it is not offered.
What accuracy should I expect?
On a synthetic ground-truth set across six degradations, 0.6% character error rate against raw Tesseract 5's 19.3%, and 97.7% field accuracy against 77.4%. The optional deep ensemble reaches 0.1% and 99.3% but costs latency. The full table, including the rows we do not win and the run-to-run variance, is on the OCR feature page.
What happens when a new version ships?
A licence is perpetual for the version bought and includes a year of updates. Nothing stops working when the year ends — you simply stay on the last version your licence covers.
The encrypted vault
From /features/vault
Can Keepsake or anyone at the company decrypt my vault?
No. The encryption key is derived from your password on your device. We never see the password, the key, or the ciphertext — vaults are stored on your devices and your own cloud, not on our servers.
What if I lose my password AND the Recovery Kit?
The data is unrecoverable — by anyone. That is the honest cost of real encryption, and it is why the Recovery Kit is printed at setup and free forever.
On-device OCR that files for you
From /features/ocr
Does OCR work offline?
Yes — it is the same engine whether you are online or not. On the web app the OCR module is cached by the service worker after first use.
What file types can Keepsake read?
Photos and scans (JPG/PNG), and PDFs — both text PDFs (read directly) and scanned PDFs (OCR per page).
Can I scan paper documents directly?
Yes — the Android app has a built-in camera scan flow with automatic edge detection and deskew; multiple pages become a single PDF. On Windows and the web, import a photo or scan and the same pipeline takes over. Capture and recognition both happen on your device.
How do I know these accuracy numbers are real?
The whole benchmark is in the source tree and runs with one command — the test set, the ground truth and the scoring are all reproducible. The table above is the exact output; we also publish the methodology in detail on our blog.
Expiry alerts & the Renewal Assistant
From /features/expiry
Which countries have renewal packs today?
Pakistan, United States, United Kingdom, United Arab Emirates and India at launch, each covering the common document types, plus sensible generic checklists for every other country.
Can I add my own reminder dates?
Yes — OCR suggestions are just defaults. Any document can carry a manually set expiry or reminder date.
Sovereign Sync — your cloud, not ours
From /features/sync
Does Keepsake get access to my Google Drive or OneDrive?
No. You authorise the app on your device directly with Google/Microsoft, scoped to a hidden app-only folder. The tokens stay on your device, encrypted inside the vault.
Can I sync without any cloud at all?
Yes — point sync at any folder: a NAS share, a Syncthing folder, even a USB stick you carry between machines.
Travel Mode
Is Travel Mode available on iPhone?
Yes, through the installable web app — the capsule works offline via the service worker, which is exactly the border-crossing scenario it was built for.
Does wiping the capsule affect my vault?
Never. The capsule holds copies. Wipe it, lose the phone, let it expire — your vault at home is untouched.
Secure Send
What does the free tier include?
Three Secure Sends per month, up to 10 MB each — counted locally on your device. Premium removes the monthly cap.
Can Keepsake see what I share?
No. Files are encrypted before upload and the key never reaches us — it travels in the URL fragment, which is not sent in HTTP requests.
Family Vault
From /features/family
When does Family Vault ship?
It is the current top item in development, right behind the launch of the apps themselves. The Family plan price (£29/yr, up to 6 members) is already locked in on the pricing page, alongside Premium at £19/yr and Teams at £79/yr per 10 seats.
Does every family member need their own account?
There are no accounts anywhere in Keepsake. Each member has their own vault password and recovery kit on their own devices; membership is a key exchange, not a signup.
Can a Viewer really not edit a document?
Keepsake's apps offer a viewer no way to add or change anything, and every edit is attributed to whoever made it. But a category key both decrypts and encrypts, so a viewer running a modified build is not stopped by cryptography — only by the app. That is why the permissions table labels each row with what enforces it. If you need a hard guarantee rather than a household convention, do not grant that category.
What is a Deputy, and can they read my documents?
A Deputy holds one share of the 2-of-3 emergency split and no vault keys at all — no family key, no category keys. They cannot open anything today, which is exactly what makes it safe to name somebody years in advance. When the emergency procedure runs, their share plus one other reconstructs the master key.
Why have both an Owner and a Co-owner?
Because a family whose only full member loses their phone is a family locked out of its own documents. A co-owner has the owner's reach — adding members, granting and revoking categories, rotating keys — with one exception: they cannot remove the owner. There is exactly one owner and they cannot be removed by anybody.
Document Notary
From /features/notary
Do I need a crypto wallet or account?
No. Anchoring uses the free public OpenTimestamps calendars, and verification only reads public block data. There is no wallet, no fee and no account anywhere in the flow.
Does this put my document on a blockchain?
No — only a cryptographic fingerprint (SHA-256 hash) is anchored, and it is blinded with a random nonce before submission. The document never leaves your vault, and nothing about its content can be recovered from the hash.
Is anchoring free?
Anchoring is a Premium feature. Verification is free for everyone, forever — including the public /verify page, which anyone can use with any Keepsake .ots receipt.
Getting documents in
From /features/capture
Does the browser extension read my vault?
It cannot. The protocol has no message that reads anything out — it can only offer bytes in, and your vault asks you to confirm each one before saving it.
Is the Keepsake printer a driver I have to trust?
It is Windows' own PDF printer pointed at a folder Keepsake watches. Adding it needs one administrator prompt; removing it takes the printer and its port away completely.
Do phone and PC transfers go through your servers?
No. Pairing is a direct connection over your own network. If your Wi-Fi is down, nothing transfers — there is no cloud fallback, by design.
Can I forward documents to Keepsake by email?
No, and that is deliberate: an address you forward to is a server of ours holding your mail, which is the one thing this product exists to avoid. Two things work instead, both on your own device — save the email as a file and drop it in, or give the app your own mailbox to check, which it signs in to directly and files the attachments from.
Is the mailbox check the same as connecting my Gmail?
No. There is no OAuth prompt, no token held on a server of ours, and nothing of yours reaches us: the app on your machine opens a TLS connection to the one IMAP host you named and to no other. Providers that require an app password issue one for exactly this, and revoking it in their settings ends the access immediately. The web app does not offer it at all, because a browser cannot open that connection and doing it any other way would mean putting a server of ours in the middle.
What does the mailbox check change in my inbox?
It marks a message read once its attachments are filed, and that is the entire list. Nothing is deleted, nothing is moved, and nothing is filed twice — a message it skips stays unread and is considered again next time.
Can Keepsake connect to my Google Drive or Dropbox and import from there?
No, and it is a deliberate refusal rather than a missing feature. A connector means holding a token that keeps standing access to another account of yours alive, and a server of ours in the path. Sync the folder so it is on your disk — which the desktop clients already do — and import the folder. It works offline, it cannot be switched off by anybody else, and it asks you to trust nothing.
What happens to an attachment Keepsake will not take?
It is listed with the reason next to it before anything is saved. Executables, archives and macro-enabled documents are refused by type, and a name dressed up as a document — statement.pdf.exe — is refused by name. Nothing is dropped silently, because an attachment you were never told about is one you believe is filed.
Ask your vault
From /features/ask
Is my document sent to an AI service?
No. Retrieval runs entirely on your device. The optional phrasing step uses a model built into your browser, on your machine — and where there is no such model, the feature simply shows the quoted answer.
Can it make something up?
The answer you see is assembled from fields Keepsake extracted and sentences copied from your documents. When nothing matches, it says so rather than producing a plausible sentence.
Can Claude or ChatGPT use this?
On Windows, yes, without uploading anything: Keepsake ships a local read-only MCP server that your assistant starts on your own machine. You unlock the vault and grant it a scope — one document, one category, the identity documents or everything — and it can then answer from your real documents for half an hour. It opens no network port, it can change nothing, and every question it answers is written into your audit log. <a href="/guides/mcp-server">How to set it up</a>.
What if I call a document something other than what it says?
That is what the synonym groups are for: a bill you call an invoice, a licence you call a permit, a will you call a testament. The groups are one shared file the Windows, Android and web apps all read, so the same words find the same document wherever you ask. Better reach buys no licence to invent, though — whatever is found still has to produce a field or a sentence that actually answers, or you are told it does not.
Does it work in Urdu?
Question words in Urdu are recognised, and the web app's whole primary journey is available in Urdu with a right-to-left layout. Answers are quoted from the document, so they come back in whatever language the document uses.
How to choose a family document vault — 14 criteria
Which criterion matters most?
Who can read your documents. Every other column describes something you can add, work around or migrate away from later; a vendor holding readable copies of your family's identity documents is a decision you cannot un-make once it has been breached.
Why publish the criteria you fail?
Because a comparison table that scores its author fourteen out of fourteen tells a reader nothing they can use, and it is trivially contradicted by anyone who checks. Naming the five gaps makes the other nine believable, and it is the same list we work from internally — the plan behind it is in the repository.
Is a self-hosted option better than any of these?
On privacy and cost, potentially yes; on the thing that actually determines outcomes — whether the household is still using it in three years — usually no. A server is only as private as its last patch, and it stops when you stop.
Do certifications like SOC 2 mean documents are safe?
They mean a company follows documented processes, audited on a schedule. That is genuinely valuable and it is not the same as being unable to read your files. The strongest position is both, which is why an independent audit is on our plan rather than dismissed on our blog.
How often is this scoring updated?
Whenever a competitor ships something that changes a row, and whenever we do. Prices and capabilities here were checked in September 2026; each comparison page carries its own check date.
Keepsake vs Everplans (2026) — Estate Planning vs Daily Document Vault
From /compare/everplans
Can Keepsake do what Everplans deputies do?
Yes, and with stronger custody: the Legacy Kit splits your master key three ways (you, your heir, a printed copy) so any two can open the vault. The difference is that Everplans releases access from their servers, while Keepsake's release needs a human being to hold a share — which is why we added a rehearsal, so you can prove it works while you are alive.
Does Keepsake have Everplans' guidance?
A version of it. The Family File checklist lists the documents a household should hold, why each matters, who issues it and what it costs to replace, per country. Everplans' library is broader and better written on end-of-life topics specifically.
Could I use both?
People do. Everplans for the planning narrative, Keepsake for the documents themselves. Nothing in either prevents it — although anything you put in Everplans is readable by Everplans.
Keepsake vs Prisidio (2026) — Digital Vault Comparison
From /compare/prisidio
Prisidio has Keyholders. Does Keepsake?
Yes, under a different name and a different mechanism. The Legacy Kit splits your master key three ways so that any two shares open the vault, and Family Vault wraps a shared key to each member's public key. The difference is where trust sits: Prisidio's server decides who may read, Keepsake's cryptography decides — nobody can be granted access by a database change.
Is Prisidio encrypted?
Yes, at rest and in transit, like most cloud vaults. That is not the same as zero-knowledge: their systems process your documents, so their staff and anyone who compels them can in principle read them. Keepsake never holds a document at all.
What if I already use Prisidio?
Export from Prisidio and use the folder importer — Keepsake reads a folder of documents, OCRs each one and files them. See the migration guide in the docs.
Keepsake vs IronClad Family (2026) — Digital Vault Comparison
IronClad advertises military-grade encryption. Is Keepsake weaker?
"Military-grade" almost always means AES-256 at rest with the vendor holding the keys, which is what IronClad and most of this category do. Keepsake uses AES-256-GCM with an Argon2id-derived key that never leaves your device — the same cipher, a fundamentally different custody model. The distinction that matters is not the cipher, it is who can decrypt.
Does Keepsake help me write a will?
No, and it does not pretend to. Keepsake stores, reads, files and protects the document; drafting is a job for a solicitor or a wizard like IronClad's. What Keepsake does add is proof — the Document Notary anchors a hash so you can show a will existed, unmodified, on a given date.
What happens to my heirs if Keepsake disappears?
They open the vault exactly as before. Their share of the key, the printed Recovery Kit, and the published vault format are all things they hold — none of them depends on us existing.
Keepsake vs GoodTrust (2026) — Digital Legacy vs Document Vault
From /compare/goodtrust
Can Keepsake replace an estate planner?
No. Keepsake stores and proves; it does not draft. What it adds after drafting is the Document Notary — a hash anchored to a public timestamp, so the version your executor holds can be shown to be the version that existed on that date.
Does Keepsake do anything about my online accounts?
Only indirectly: an account inventory kept as a document in the vault, released through the Legacy Kit. GoodTrust's account-by-account digital legacy work is more developed, and we would rather say so than pretend otherwise.
Is £19 really comparable to $149?
They are not the same purchase, which is the honest answer. GoodTrust's first-year price buys drafted legal documents. Keepsake's buys custody, intelligence and alerts, every year, for every document you own.
Keepsake vs Family Folder (2026) — Family Document Organiser Comparison
Is Family Folder encrypted?
It encrypts in transit and at rest like most cloud services. The difference is who holds the key: theirs is held by them so their systems can process your files, and Keepsake's is derived from your password on your own device, which is why we cannot read a single document even if asked.
Family Folder is free for three members. Why pay for Keepsake?
You may not need to. Keepsake's free tier covers 25 documents per device with the safety features — Recovery Kit included — never paywalled. Premium buys unlimited documents, sync and the intelligence features, at £19 a year.
Can I move from Family Folder to Keepsake?
Yes. Export your documents, drop the folder on Keepsake, and each file is OCR'd, categorised and dated on your machine.
Keepsake vs Tresorit (2026) — Vault vs Encrypted Storage
From /compare/tresorit
Both claim end-to-end encryption. What is different?
The scope. Tresorit encrypts files end-to-end and stores them on its own servers. Keepsake encrypts on your device and then stores the ciphertext in a cloud folder you own — so there is no vendor holding your data at all, and the vault also works with no cloud whatsoever.
Is Keepsake audited like Tresorit?
Not yet, and that is the honest gap. The vault format is published byte-for-byte, the crypto is covered by an automated test suite, and an independent published review is on the plan. Tresorit today has the stronger third-party evidence.
Can I use Keepsake with Tresorit?
Yes. Point Keepsake's sync at a Tresorit folder and you get two independent layers — our on-device encryption inside their end-to-end encrypted store.
Keepsake vs OneDrive Personal Vault (2026) — Comparison
From /compare/onedrive-personal-vault
Can I use Keepsake and OneDrive together?
That is the intended setup for many people. Keepsake's Sovereign Sync writes an encrypted vault into a OneDrive folder you own, so you keep Microsoft's reliability and lose Microsoft's ability to read anything.
Is Personal Vault end-to-end encrypted?
No. It adds a second authentication step and auto-locking on top of OneDrive's ordinary encryption; Microsoft still holds the keys and can decrypt for account recovery, legal process or its own features.
What is the three-file limit exactly?
On the free 5 GB tier and the 100 GB standalone plan, Personal Vault holds at most three files. A Microsoft 365 Personal or Family subscription removes the cap. Keepsake's free tier is 25 documents per device, and Premium is unlimited.
Keepsake vs 1Password (2026) — Password Manager vs Document Vault
From /compare/1password
Is 1Password less secure than Keepsake?
No — its cryptography is excellent and independently audited, which is more than we can currently say. The difference is scope: 1Password protects secrets, Keepsake manages documents. Where we differ architecturally is that your Keepsake ciphertext sits in your own cloud rather than a vendor's.
Should I use both?
Yes, and that is our honest recommendation: passwords and passkeys in 1Password, documents in Keepsake. They overlap only at the edge where people attach a passport scan to a login item.
Does Keepsake store passwords?
No. It stores documents, reads them, files them and watches their dates. A vault that tried to be a password manager as well would be worse at both.
Keepsake vs Google Drive (2026) — Is a Drive Folder Good Enough?
Does Keepsake replace Google Drive?
No — it uses it. Sovereign Sync writes an encrypted vault into a Drive app folder you own, so you keep Google's reliability and remove Google's ability to read anything. OneDrive, WebDAV, a NAS and a USB stick work the same way.
Google already OCRs my documents. Isn't that the same?
It is the same capability with the opposite custody. Google's OCR runs on Google's servers over your plaintext; Keepsake's runs on your device and nothing is uploaded for recognition.
What if I lose my Google account?
With a Drive folder, you lose the documents. With Keepsake, the vault also lives on your devices, the format is published, and the printed Recovery Kit opens it — losing the cloud account costs you sync, not your paperwork.
Keepsake vs VeraCrypt (2026) — Volume Encryption vs Document Vault
From /compare/veracrypt
Is VeraCrypt insecure because XTS is unauthenticated?
No. XTS is the correct mode for encrypting a block device in place, and length-preserving encryption cannot carry an authentication tag — the property is a consequence of the job, not a flaw in the implementation. What it means in practice is that VeraCrypt detects tampering only incidentally. Keepsake's per-document GCM tag turns that into an explicit refusal. It matters most when the container lives in a cloud you do not control.
Can Keepsake open a VeraCrypt container?
Not directly, and it does not need to. Mount the container in VeraCrypt and point Keepsake's folder import at the drive letter — Keepsake reads the files and writes nothing back. We do read Cryptomator vaults directly, because their format is published; VeraCrypt containers are a mount away and that is simpler than an importer.
Is there a VeraCrypt app for Android or iPhone?
There is no official one for either. That is the single biggest practical difference for household paperwork, because the moment you need a policy number is usually the moment you are not at the laptop. Keepsake ships a native Android app and a web app that installs on any phone, both included in the same licence.
Is Keepsake open source like VeraCrypt?
No, and that is a real loss in this comparison rather than something to talk around. What exists instead: the vault format is published byte-for-byte so anyone can write a reader, the build is reproducible from source, and the claim ledger lists what we have not got — including the audit we have not had.
Keepsake vs Cryptomator (2026) — Encrypted Folder vs Document Vault
From /compare/cryptomator
Is Keepsake's encryption better than Cryptomator's?
No. Both use authenticated AES-256 — ours GCM per document, theirs SIV-GCM per file — and both derive the key with a memory-hard KDF. On the cryptography this is a tie, and on open source and independent audit Cryptomator is ahead of us. The argument for Keepsake is about what sits above the encryption: document types, extracted fields, search, expiry reminders, household roles and inheritance.
Can Keepsake open my existing Cryptomator vault?
Yes, on Windows, for vault format 8. Point the importer at the vault directory and give it the vault password; it decrypts the masterkey and the filenames and imports the documents. It never writes to the source vault, it refuses an unrecognised format version rather than guessing, and it names every file it skips. Your vault keeps working in Cryptomator afterwards.
What does Cryptomator cost compared with Keepsake?
Cryptomator is free and unlimited on the desktop, free to read on mobile, and about €29.99 per platform to write from a phone — so roughly €60 for Android and iOS together, one-off. Keepsake is free for 25 documents and £19 a year for Premium, with every platform included in that. On desktop-only they are cheaper; once phones count, we generally are not.
Does Keepsake mount a drive like Cryptomator does?
No, deliberately. A mounted drive is readable by every process running as you while it is unlocked, and we measured that rather than asserting it: a script holding no passphrase walked a mounted Cryptomator vault and read all 7 documents out of it. Keepsake has no filesystem-mount code on any platform, so there is no drive letter to exclude. Two honest limits. Keepsake is not free of plaintext on disk: opening a document in another application writes a temporary file, deleted when the viewer window closes. And the search-indexer half of the story did not survive being measured — a vault mounted over WebDAV contributed nothing at all to the Windows Search index, so we no longer say a mounted vault gets indexed. The measured difference is scope and duration — one document while you look at it, rather than every document for as long as the vault is unlocked.
Keepsake vs Docspell (2026) — Self-Hosted DMS vs Zero-Knowledge Vault
From /compare/docspell
Is self-hosting more private than Keepsake?
Only if you do it well. A self-hosted server is private in principle and only as private as its weakest patch, password and backup in practice. Keepsake's ciphertext is unreadable to us and to the cloud it sits in, without you having to secure anything.
Can I keep both?
Yes — some people run Docspell as a bulk archive and use Keepsake for the documents the household actually reaches for, with expiry dates and family access.
Is Keepsake open source?
Not today. The vault format is published byte-for-byte so anyone can write a reader, and making the crypto core source-available is on the plan — an open format is what protects you from us either way.
Pricing
From /pricing
Why bank transfer instead of card checkout?
Keepsake runs no payment servers and embeds no third-party checkout scripts — the same zero-infrastructure principle that protects your documents. An invoice with IBAN/Wise details is a one-minute transfer in most banking apps, and it keeps prices low.
How quickly do I get my license?
You receive the invoice within one business day of requesting an upgrade, and the license key within one business day of your payment arriving. The key is emailed to you and activates offline — no account needed.
What is a license key, technically?
A short signed text (Ed25519 signature) containing your email, plan and expiry. The apps verify it with an embedded public key, entirely offline. No activation server exists to go down or track you.
What happens when my Premium year ends?
Nothing is locked. You can always read, decrypt and export every document. Premium conveniences (sync, Travel Mode, unlimited documents beyond 25) politely degrade until you renew.
Is there a refund policy?
Full refund any time before we email your license key — just tell us and we return the full amount the way it came. Once the key is sent the sale is final, because an offline license activates on your device and cannot be cancelled or revoked. The free tier never expires, so you can try Keepsake fully before you buy.
Do security features cost extra?
Never. Encryption, the Recovery Kit and audit history are free forever. We only charge for convenience and intelligence — sync, unlimited storage, Travel Mode and the like.
Is there a plan for businesses?
Yes — Keepsake Teams, £79/year per 10 seats. It uses the same zero-knowledge shared-vault mechanics as the Family plan: documents are shared through a cloud folder your firm controls, protected by key possession rather than server permissions, so client files are never readable by us or your cloud provider. Invoiced by bank transfer, which most business accounting actually prefers.
What documents should a family keep? A complete checklist
From /guides/what-documents-to-keep
What is the single most important document to have?
The will, if there is one, and knowledge of where the original is. Everything else can be reconstructed with time and effort. An original will that nobody can find is treated by the courts in England and Wales as though it may have been deliberately destroyed, and the estate is then distributed under the intestacy rules rather than according to the wishes written in it.
Are scans and photographs legally acceptable?
For most everyday purposes, yes — insurers, banks and employers routinely accept a clear scan and many now prefer one. They are not acceptable where the original is itself the legal instrument: a will, a share certificate, a deed to unregistered land, and in many cases a registrar-issued certificate, where an institution will want a certified copy from the registrar rather than your photograph of one.
How do I stop this becoming a huge scanning project?
Do the four-group list first and scan nothing. Most of the value is in knowing what exists and where — a single page listing the documents, their locations and the people to contact is more useful to your family than a hundred scanned utility bills. Scan the identity group next, because those are needed fastest and are hardest to replace, then stop until the next time you handle a document anyway.
Where should the paper originals live?
Somewhere fireproof and waterproof, in a place at least one other person knows about and can open. A home safe rated for documents is adequate for most households. A bank safe deposit box is more secure but has a well-known failure mode: access after a death can require exactly the documents that are inside it. If you use one, keep the will and the death-relevant papers outside it.
Should I keep documents for people who have died?
Keep the death certificate copies, the grant of probate, the final tax records, and anything relating to property that passed to you — six years is a common floor and permanently is safer for property. Personal identity documents can be destroyed once the estate is settled, though many families keep passports and certificates as records. There is no obligation either way.
How to store documents so your family can find them
From /guides/so-your-family-can-find-them
Should I just give my passwords to someone I trust?
A password shared informally has two problems: it goes stale the moment you change it, and it hands somebody live access to your accounts today, which is more than you meant to give. The better shape is a sealed, dated envelope held by an executor or solicitor with instructions not to open it before it is needed — or a split key where no one person can act alone. Both give the same outcome after your death without giving anyone your accounts now.
What about a safe deposit box at a bank?
Excellent for security and awkward for exactly this scenario. In many jurisdictions the box can be sealed on notification of death and opened only with a grant of probate, which is precisely the document your family is trying to obtain and which the will inside would help them get. If you use one, keep the will, the funeral wishes and the index page outside it.
Is a bank or solicitor better than doing it myself?
A solicitor holding the original will and a sealed envelope is a genuinely good arrangement and costs little. What it does not solve is the digital half — nobody is holding your scans for you — and it introduces one new failure mode worth planning around: firms merge, close and retire. Note in your index which firm holds what, and check it is still the same firm when you do the annual review.
How much of this can I do in an afternoon?
The index page, the physical location, and telling one person. That is perhaps 80% of the value and it is genuinely an afternoon. Scanning is the long tail and does not need to be finished to be useful — the identity group alone is worth more than everything else combined.
What if my family is not in the same country?
It raises the stakes on the second route in, because a relative several time zones away cannot open a drawer. Favour arrangements that work remotely: an encrypted copy they can reach online, with the key held by a solicitor or split among people in both countries. And write the index page in the language they read, not the language of the documents.
Is it safe to keep a passport photo on your phone?
From /guides/passport-photo-on-your-phone
Is a photo of a passport as risky as the passport itself?
Less risky for travel, since no border accepts an image, and comparably risky for identity fraud, since many online verification processes do accept one. The practical difference is that a stolen physical passport gets reported and cancelled, which shuts down most of its usefulness, while a leaked image is silent — you often never learn it happened.
Is a password manager a reasonable place for it?
Yes. Mainstream password managers encrypt attachments with the same key material as the passwords and are a considerable improvement on the camera roll. Two things to watch: file size limits on attachments, and the fact that your vault is only as strong as the master password protecting a very high-value target. Neither is a reason not to use one.
What about a photo of my child's passport?
Same reasoning, more caution. A child's identity is attractive to fraudsters precisely because nobody checks a seven-year-old's credit file for a decade, so misuse can run undetected for years. Keep it encrypted, and be particularly careful about school, club and travel-company forms that ask for a copy by email.
Should I blur or redact anything?
For copies you send to a third party, yes — cover what that party does not need. If they only need to confirm nationality and expiry, the passport number can be obscured. Do not redact your own stored copy; the whole point of yours is that it has everything on it when you need to prove something.
Is a photo good enough for an emergency travel document?
It helps and it is not sufficient. Embassies generally want the number, issue date and issuing office, plus separate proof of identity and citizenship, and each has its own process. A copy speeds the paperwork significantly; it does not replace attending in person. Check your own foreign ministry's guidance before you travel, not after.
A document vault that works without an account
From /guides/vault-without-an-account
Is a vault with no account less secure?
Different, not less. You remove an entire class of risk — a company breach, an insider, a subpoena to a provider, an account takeover — and you take on another: your own backup and passphrase discipline. For most people the risks they remove are the ones they cannot influence and the ones they add are the ones they can, which is a favourable trade if you actually do the backups.
Can I still sync between my phone and laptop?
Yes, by putting the encrypted file in cloud storage you already use. Because the file is encrypted before it leaves your device, the provider stores something they cannot read. The one thing to be careful about is editing the vault on two devices at once, which some tools handle gracefully and others resolve by leaving you a conflicted copy — check how yours behaves before you rely on it.
What if I forget the passphrase?
With a genuinely zero-knowledge design, the documents are unrecoverable, and any product telling you otherwise is telling you it holds a key. That is why the recovery arrangements above are not optional extras: write it down and store the paper securely, or split it among people you trust, before you put anything important in.
Do free options exist?
All of the first four categories above have free, open-source options with long histories — VeraCrypt, 7-Zip, KeePass, age, GnuPG, Cryptomator. If your requirement is strictly "encrypted documents, no account, no money", that list already satisfies it, and it is worth being honest that paid tools are competing on convenience, mobile experience and features like expiry tracking rather than on the encryption itself.
How do I know a product really cannot read my files?
Look for a published format specification, an independent audit, or open source — ideally more than one. Absent those you are trusting a claim. A weaker but real signal is whether the product can reset your passphrase: if it can, it can read your files, whatever the marketing says.
What happens to my files if a vault company shuts down?
From /guides/if-the-company-shuts-down
How much notice do companies usually give?
Between 30 and 90 days when the shutdown is planned and funded, which is the common case for an established product. Abandonment and insolvency give no reliable notice at all — in insolvency, the administrator has no obligation to run the service for your convenience, and switching off servers is a cost saving they are expected to make.
Is open source a guarantee?
It is a strong protection and not a guarantee. Published source means somebody can build the software again, and popular projects get forked when maintainers step away. But an abandoned project with no users will not be forked, and source that will not compile against modern libraries is a project, not a solution. Open source plus a local data file is the combination that actually holds.
What about companies that promise perpetual access?
A promise is only as durable as the entity making it, and it is the entity that has failed in this scenario. Escrow arrangements and non-profit foundations are better than a promise because they survive the company, but the check remains the same: does the guarantee still work with the company gone, or does it require someone to honour it?
Does a big company make this safer?
Safer against insolvency, not against discontinuation. Large technology companies close consumer products routinely — often ones with millions of users — and generally do so with a decent export window and a firm date. The risk shifts from "the company dies" to "the product is not strategic any more", which is more predictable but no less final.
What should I do the day I get a shutdown email?
Export immediately, before you read the rest of the email. Export windows get shortened, servers get overloaded near the deadline, and the export you meant to do next week is the one that does not happen. Then open the exported files and check that the metadata came with them, while there is still somebody to ask if it did not.
How to organise documents without a subscription
From /guides/organise-without-a-subscription
Is free software safe enough for identity documents?
The encryption in VeraCrypt, 7-Zip, GnuPG, age and your operating system's built-in tools is the same cipher family that paid products use, and several have been independently audited — which is more than many commercial vaults can say. The risk with free tooling is not the cryptography, it is that you have to operate it correctly and remember to.
How long does setting this up take?
The folders and the naming rule take ten minutes. Filing what you already have takes as long as it takes, and it is worth doing in the wrong order: do the identity group, stop, and let the rest accumulate through the inbox as documents arrive. A weekend spent scanning eleven years of utility bills is how people learn to hate their own system.
What about a Notes app or a spreadsheet as the index?
A spreadsheet is a perfectly good index and better than most software for this, because it is searchable, sortable by expiry date, and readable by anyone in thirty years. One row per document: name, type, person, where the original is, expiry. Keep it outside the encrypted container so somebody can read the map without opening the vault.
Do I need to pay for cloud storage?
Almost certainly not for documents. A thousand scanned pages is a small number of gigabytes, well inside the free tier of every mainstream provider. Where people pay is for photographs and video, which is a different problem — and a good reason to keep documents in their own account or their own encrypted container rather than mixed in.
When is a paid product actually worth it?
When one of the five gaps above is costing you something real: a missed renewal, documents you cannot get at from a phone, or a family who could not reach anything if you were not there. Buying it because your filing is a mess will not help — a paid product applied to an undecided pile produces an expensive undecided pile.
UK document renewal dates and how to track them
Why does my passport show more than ten years of validity?
Because until September 2018 the UK added unexpired months from your previous passport onto the new one, so passports issued before then can show up to ten years and nine months. Those extra months are valid for UK purposes but are generally disregarded by the EU entry rules, which measure from the issue date. If your passport was issued before that change, check the issue date carefully before booking European travel.
Does the three-month rule apply to the whole trip?
For most European destinations, the passport needs to be valid for at least three months after your intended date of departure from the area, not from the country you happen to be in. Other countries set their own margins — six months is a very common requirement across Asia and the Middle East. Check the destination's entry requirements on the FCDO travel advice pages for each trip rather than assuming a single rule.
Can I renew a passport before it expires without losing the remaining time?
Since 2018, no — the unexpired months are not carried over, so renewing early means giving up the time left. That is a real cost, and it has to be weighed against the risk of leaving it late. The usual compromise is to renew roughly three months out, which loses very little and leaves room for the process to go wrong.
What if I have already missed a renewal?
Deal with it in order of consequence, not order of discovery. Anything affecting your right to work, drive, or remain comes first and often has a formal process for a lapse. Insurance is next, because a gap can affect future premiums as well as leaving you exposed. Passports and travel documents can usually just be applied for again. Most lapses are recoverable; the exceptions are in immigration, where doing nothing is by far the worst option.
Is there an official service that tracks all this for me?
No single one. GOV.UK sends reminders for some things — the driving licence photocard, vehicle tax, the MOT if you sign up for the free reminder service — and those are worth enabling, but each is per-document and goes to the contact details that service holds. Anything spanning several documents and several people in a household is currently a job you do yourself.
Pakistan and Gulf document renewals
From /guides/pakistan-and-gulf-renewals
Can I renew a Pakistani passport or NICOP from abroad?
Generally yes, through the Pakistani embassy or consulate, and several missions now support online applications with biometrics either captured at the mission or already on file. What varies enormously is processing time and whether an in-person appointment is needed, so check with your specific mission early rather than assuming the timeline someone quoted you for a different city.
What happens if my Gulf residence permit lapses?
Most Gulf states charge a daily fine for overstaying on an expired permit, and the amounts accumulate quickly. Beyond the money, an expired permit typically suspends the right to work, can freeze banking, and affects dependants whose status is tied to yours. It is usually recoverable by paying and renewing, but it is one of the few document lapses with a running meter, so speed matters more than getting it perfect.
Should I keep expired passports and residence permits?
Yes, and this is the advice most often ignored. Entry and exit stamps in old passports and the dates on old permits are the standard evidence of continuous residence, which is exactly what a citizenship or settlement application in a third country will ask for, sometimes twenty years later. Keep the physical documents and scan every stamped page.
My employer handles my Iqama — do I still need to track it?
Yes. The employer usually carries the legal responsibility and you carry the consequences of a delay, which is not a comfortable division. Track the date independently, ask for written confirmation each cycle, and keep your own copy of the renewed document. This is not distrust; it is that renewals are handled by administrators with many to process and no personal stake in yours.
How do I handle documents when the family is in two countries?
Track every family member's documents in one shared place rather than one per country, and keep encrypted digital copies both people can reach — the failure is almost always that the person who needs the document is not in the same country as the file. Where a document must exist on paper in both places, get a properly attested copy rather than relying on a photograph, because many counters will not accept one.
How to search inside scanned documents, offline
From /guides/search-scanned-documents-offline
Is local OCR as accurate as a cloud service?
On clean, printed, well-lit pages the difference is small enough not to matter — both will read a typed letter or a bill essentially perfectly. Cloud services pull ahead on hard inputs: handwriting, unusual layouts, photographs taken at an angle, and low-resource languages. For a household archive of printed documents, local OCR is not a compromise. For a box of handwritten letters, it is.
Does OCR change the scan itself?
No, and this is the reassuring part. The text layer is added on top of the image, which is left exactly as it was. The page still looks like the scan, prints like the scan, and can be re-OCRed later with better software without any loss. If a tool offers to "clean up" or re-compress the image, that is a separate option and one to be careful with — aggressive compression on a scanned document can turn digits into other digits.
How long does it take?
Roughly a second or two per page on an ordinary laptop, so a hundred-page backlog is a coffee break rather than a project. It parallelises across cores, and it is the kind of job to point at a folder and leave running.
Can I do this on a phone?
Increasingly yes. Both major mobile platforms now recognise text in images on the device, and several free scanning apps produce a searchable PDF directly. The weak point on mobile is not the OCR, it is that phone file management makes a consistent archive harder to maintain — most people scan on the phone and file on a computer.
What about searching inside Word documents and emails?
Those already contain text, so they need no OCR and every desktop search tool reads them. The gap is almost always scans and photographs. Worth checking that your index actually covers the folder they live in, because the default indexed locations on Windows do not include every drive.
Syncing documents between your PC and phone with your own cloud
From /guides/sync-documents-with-your-own-cloud
Does the provider know what my files are called?
It depends on the tool. Cryptomator and gocryptfs encrypt the file names as well as the contents, so the provider sees directories of meaningless names. Some simpler tools encrypt only the contents, which leaves "Mortgage offer.pdf" and "Divorce petition.pdf" perfectly legible in a listing. File names carry a surprising amount, so check this specifically rather than assuming that "encrypted" covers it.
Is this better than the provider's own encryption?
It is a different guarantee. Every mainstream provider encrypts at rest and in transit, which protects you from someone stealing a drive out of a data centre. It does not protect you from the provider itself, from a subpoena served on it, or from someone who gets into your account — because in all three cases the provider can decrypt. Encrypting before upload closes those, at the cost of one more thing to operate and one more key you must not lose.
What happens if I forget the passphrase?
You lose the documents, completely and permanently, and there is no support line that can help. That is the same property that makes the scheme worth using, so it has to be planned for rather than hoped about: write the passphrase down, store it physically somewhere safe, and make sure one other person can find it. There is a guide on exactly that problem — see the related links below.
Will this work with a work account?
Technically usually yes, and it is often a bad idea. Documents in an employer-controlled account can be subject to retention policies, legal holds and administrator access, and the account can be closed the day you leave — with everything in it. Personal documents belong in a personal account.
How much storage do I need?
Less than you expect. A thousand scanned pages at ordinary quality is a few gigabytes, comfortably inside the free tier of every mainstream provider. Encryption adds a negligible amount. If your account is full, it is almost certainly photographs and video doing it, which is one more argument for keeping documents in their own account or their own encrypted folder.
Have Keepsake check your mailbox for documents
Is this the same as connecting my Gmail account?
No. There is no OAuth prompt, no token held on a server of ours, and no account of yours linked to anything of ours — because there is no server of ours in this at all. The app on your machine opens a TLS connection to the one IMAP host you named. Revoking it is done in your mail provider's settings, by deleting the app password, and takes effect immediately.
Can I forward documents to a Keepsake address instead?
There is no such address, and there will not be one on these terms. A forwarding address means a server of ours receiving and holding your mail in a form we can read, which is the single thing this product exists to avoid. The mailbox check is the same job done from the other end.
Does it work in the web app?
No, and it is a deliberate absence rather than an unfinished feature. A browser cannot open a raw connection to a mail server, so a web version would have to route your mailbox credentials and your mail through a server of ours — which is exactly the design we rejected. On iPhone and in the browser, saving the message as a file and importing it does the same job with nothing in the middle.
Will it delete or move my email?
It marks a message read after its attachments are filed. That is the entire list of changes it can make: there is no delete and no expunge command anywhere in the client, which is how that promise stays true rather than being a policy someone could change.
Does it read my emails?
Only the four headers it needs to decide — who sent it, the subject, the date, and whether it has attachments — and then only the attachments themselves. The body is never read into any field of any document, and the test suite plants a marker string in a message body and fails if it appears anywhere in the vault.
What about two-factor authentication?
That is what an app password is for. Your account keeps its second factor for you signing in; the app password works only for mail programs, only for this, and can be revoked on its own.
Let an assistant read your vault, on your machine
From /guides/mcp-server
Does this upload my documents to Claude or OpenAI?
Not to us and not by us. The server runs on your machine and reads your local vault; nothing is sent to any server of ours, and none exists in this path. What your assistant then does with an answer is between you and your assistant — if you ask a cloud assistant a question, the answer it reads travels to that provider the same way anything you type does. That is why the grant is narrow, short and yours to make: the honest control here is deciding what may be read, not pretending the assistant is local when it is not.
Is there a port open on my computer?
No. The launcher talks over standard input and output, and reaches the app over a Windows named pipe addressed by name and account. Nothing listens on a network interface, so nothing on your network or in a browser tab can reach it — which is the failure mode of the usual "just bind to localhost" design.
Can an assistant delete or change a document?
No, and not because we turned it off. There is no such tool on the server at all. Methods that would let a client subscribe, roam your filesystem or borrow your model budget are refused by name before anything looks at a document.
What if my assistant asks for a document I did not grant?
It is told the document is not in this session's scope, and that widening it is your decision to make in the app. The document does not appear in search, in what expires soon, or in an Ask answer either — the scope is a fixed set of documents computed when you granted it, and every tool intersects with it.
Does it work with ChatGPT, Copilot or a local model?
With anything that speaks MCP over stdio and lets you add a local server — Claude Desktop is the common case today, and the protocol is an open standard rather than one vendor's. The configuration is the same block for all of them.
What about Android, the web app or a Mac?
Windows only today, and the omission is a decision rather than a gap. A browser cannot open a pipe to a process, so a web version would mean routing your documents through a server of ours — the one thing this feature exists to avoid. On the phone, the assistant and the vault are not on speaking terms in the same way.
Does the assistant get my file itself?
Never. It can be told what a document says — a capped extract of the recognised text, the dates, the number, the fields — and it cannot be handed the PDF, a page image or a thumbnail. The tool that returns a document says so in its own answer.
Unlock your vault with a passkey or a security key
Is this the same as signing in with a passkey?
No, and the difference is the whole point. Signing in with a passkey proves your identity to a server, which then decides to hand over files it could already read. Here the key produces a secret that unwraps the encryption itself. There is no server to ask and no permission to be granted — if the key is absent, the envelope stays shut.
Can I use a YubiKey with the Windows or Android app?
On Windows, yes: Settings → Vault Security → Add a security key, and the same key that opens the vault in the browser opens it in the app. On Android, not today — the phone unlocks with the hardware it already has, the Keystore gated by fingerprint or face, and that does not travel to another device.
What happens if I lose the key?
You open the vault with your password or your Recovery Kit, exactly as before, and remove the slot the lost key was using. This is why enrolling is refused until one of those exists: the answer to a lost key must never be "your documents are gone".
Does Keepsake see my fingerprint or my face?
No. It receives a fixed-length secret from hardware that has already made its own decision. It never sees the biometric, never sees the private key, and can prove nothing about you beyond that the hardware said yes.
Can one key open two different vaults?
Yes, and neither vault can open the other. The vault id is mixed into the key derivation, so the same physical key produces a different secret for each — which is what lets a household share a key without sharing a vault.
Is the secret stored anywhere?
No. It exists for the moment the prompt is answered and is wiped afterwards. What is stored in the vault file is the credential id — a public handle that lets the browser offer the right key — and an envelope that only the derived secret opens.
Rules: file documents automatically as they arrive
From /guides/workflows
Can a rule delete a document, or move it out of my vault?
No, and not because it is switched off — there is no delete, move, share or export action in the rule engine at all, so there is nothing to switch. The seven actions set a category, add a tag, set a title, append a note, set the issuer, set a reminder lead, or stop the rules below. A rule that gets a document wrong gets a field wrong, and you fix it in seconds.
What happens if two rules disagree?
The later one wins, because rules run in order and the last action to set a field is the one that stands. That is a feature when your general rules sit under your specific ones, and a nuisance when they do not — which is what the stop action is for: a confident rule ends with it and nothing below runs.
Will rules change documents I have already filed?
Only if you ask. The trigger for documents already in the vault is off by default on every rule, and running it is a deliberate act from the rules screen that shows you how many documents would change before anything is written.
Can I use a regular expression?
Yes, on any text field, and it is checked when you save the rule rather than when a document arrives at two in the morning. An expression that runs too long is abandoned rather than allowed to hang the import.
Does this work on my phone or in the browser?
Windows only today, and the omission is a decision rather than a gap. Rules earn their keep on the doors documents arrive through in bulk — a watched folder, a mailbox, a vendor export — and those are all on the desktop. On a phone you import one document at a time while looking at it, which is the case where filing it yourself is genuinely faster than describing it.
What does the app do when a rule fires?
It writes what changed into the document's history, in the same hash-chained audit log that records your logins and imports. "Why is this filed as a bill" always has an answer, and the answer names the rule.
Can I share my rules with someone else?
Export them. You get a small JSON file describing the rules and nothing else — no documents, no paths, no account — which imports on any other copy and is added to the rules already there rather than replacing them.
Import a folder of documents with its metadata
Do I have to write a sidecar at all?
No. A folder with no sidecar imports perfectly well — the file names become the titles and the top-level folder names become categories and tags. The sidecar exists for the case where you already hold better metadata than the file names carry, which is usually because you are leaving a product that had it.
Can I generate the sidecar from another product's export?
That is exactly what it is for. Most products can export a CSV of some kind; renaming its columns to the nine above is a spreadsheet job of a few minutes, and it turns a folder of anonymous files into a filed archive. If the product exports JSON instead, a short script will do it.
What happens to a category Keepsake does not recognise?
The document is filed under Other and your heading is kept as a tag. This is deliberate and it is the rule the whole importer is built on: a document filed under a category the importer invented is a document you cannot find, because you will not think to look for it there. Under Other with your own word attached, it is still one search away.
Is any of this uploaded while it is being read?
No. The import reads a folder on the device you are using, against a vault that is already unlocked there. There is no sign-in to any other service, no OAuth prompt and no server of ours in the path.
Can I run the same import twice?
Yes, and that is the intended way to use it. Every file is matched against what the vault already holds, so a second run of the same folder adds nothing and tells you it added nothing. Add thirty documents to the folder and re-run it, and thirty documents arrive.
Import a Google Drive or OneDrive folder
From /guides/import-from-cloud-storage
Does Keepsake connect to my Google Drive or OneDrive account?
No. There is no sign-in, no OAuth prompt, no access token stored and no Google or Microsoft account involved. Keepsake reads a folder that is already on your disk — which is why the import works with no internet connection and cannot stop working because another company changed its API.
My Drive files are online-only. Will they import?
Not until they are downloaded. An online-only file is a placeholder of a few bytes on disk. Mark the folder as always available offline and let it finish syncing first; the import can only read what is actually there.
Should I delete the cloud copy afterwards?
Not straight away. Keep it until you have used the vault for a while and opened a few documents from it. When you do clean up, the useful step is not deleting — it is checking who that folder was shared with, because sharing is sticky and rarely reviewed.
Can I import a zip file directly?
No, and that is deliberate. An importer that opens archives cannot reliably tell you what it filed or what it refused, and archives are a common way to smuggle something that is not a document. Unpack it and import the folder — one extra step, and every file is then named in the summary.
What about iCloud Drive or Dropbox?
The same, and there is nothing special about any of them here: get the folder onto the disk, import the folder. Because the input is a folder rather than an integration, a service we have never heard of works exactly as well as one we have.
Export your documents from Trustworthy
From /guides/import-from-trustworthy
Will I lose my folder structure?
No. The folder names are the part that survives an export intact, and a folder-tree importer reads them: recognised headings become categories and every heading is kept as a tag, so a folder Keepsake has no category for still leaves the document findable by the word you used.
Will the expiry dates come across?
Not automatically, because they are not in the download — the export is files in folders, not a manifest of fields. Copying them out before you cancel takes most households under half an hour, and a sidecar file turns that spreadsheet into an import rather than a typing session.
Does Keepsake connect to my Trustworthy account?
No, and it deliberately cannot. There is no sign-in, no OAuth prompt, no password of theirs asked for and no server of ours involved. Keepsake reads a folder that is already on your disk. An importer that needed the other company's cooperation would stop working the day they decided it should.
Is Trustworthy a bad product?
No. It is a polished product with a family-oriented feature set and a real business behind it, and if it suits you there is no reason to move. The honest differences are that it is a subscription service holding your documents on their infrastructure, and that its pricing sits well above what most households expect to pay for filing. Our comparison pages say where it beats us.
What if the download is missing documents?
Ask support before cancelling anything — that is the whole reason to check the export while the account still works. Items shared with you by another member, rather than owned by you, are the usual explanation.
Export your documents from Everplans
From /guides/import-from-everplans
Will my planning answers import into a document vault?
No, and be suspicious of anything claiming otherwise. They are structured answers inside another product, not documents. Save them as a PDF and file that PDF like any other document — which is, in practice, the form they need to be in on the day somebody uses them.
What happens to headings like "After I'm Gone" or "Digital Life"?
The documents under them are filed under Other and the heading is kept as a tag. No guessing at a category, because a wrong category is worse than an obvious one: you cannot search for a heading you did not choose.
Does Keepsake sign in to Everplans?
No. There is no connection to Everplans at any point — no sign-in, no OAuth, no credential of theirs, and no server of ours in the path. Keepsake reads a folder already on your disk.
Is Everplans worth keeping?
If you are using the planning side seriously — the wishes, the instructions, the deputies — it does something a document vault does not, and there is a good case for keeping it for that alone. If it has become a place you upload files to, it is an expensive filing cabinet and it is fair to ask what it is for.
What should I do about the people I gave access to?
Tell them before you change anything, and rehearse the new route with at least one of them. Access arrangements fail silently: nobody discovers the plan does not work until the day it is needed, and by then the person who could have fixed it is the reason it is needed.
Export from paperless-ngx, and import the result
From /guides/import-paperless-ngx
Is the export a real backup?
It is a portable copy of your documents and their metadata, which is most of what people mean. It is not a byte-for-byte backup of the paperless-ngx installation — the project documents a separate procedure for that, including the database and the search index. For the purpose of "could I read these files if the software stopped existing", the export is the thing that answers yes.
Do I have to leave paperless-ngx to read the export?
No, and if paperless-ngx suits you, staying is a perfectly good decision — it is one of the few products in this space that genuinely cannot lock you in. Producing an export occasionally is worth doing anyway, and being able to read it somewhere else is the point of it.
What happens to documents whose type Keepsake does not have?
They are filed under Other with the paperless-ngx document type kept as a tag. No guessing: a document filed under an invented category is one you cannot find, because you will not think to look for it there.
Does anything get uploaded during the import?
No. The folder is read on the device you are using, against a vault already unlocked there. Keepsake never connects to a paperless-ngx server and asks for no credential of yours.
What if the manifest names files that are not in the folder?
Each missing file is listed at the end of the import with that reason. A partial export is a thing that happens — a disk filling up mid-run, a copy interrupted — and the useful response is a named list, not silence.
Accessibility Statement
From /legal/accessibility
Is Keepsake accessible?
The web app at app.securekeepsake.com and this website are built to WCAG 2.2 Level AA, and an automated axe-core pass over every screen of the web app runs as part of the test suite — it is green, and the command that proves it is printed at the foot of this page. That pass is a self-assessment, not a third-party audit, and automated testing can only decide part of the standard. The Windows and Android apps are not assessed against WCAG.
Does Keepsake work with a screen reader?
Every control in the web app has a programmatic name, and the automated pass fails the build if one loses it. We have not run user testing with screen-reader users, so we do not claim the experience is good — only that the names, roles and states are there. If you use one and something is wrong, tell us and it is treated as a bug.
Can I use Keepsake entirely from the keyboard?
Yes in the web app. Every control is a real button, link or field rather than a clickable div, and the focus ring is visible on all of them — a dashed "drop a file here" area that only a mouse could reach was the last exception and it became a button in September 2026.
What languages does the Keepsake interface come in?
English, Urdu, Arabic and Hindi. Urdu and Arabic lay the whole interface out right-to-left. All four are the same 196 strings from one catalogue, and the Windows, Android and web test suites each fail if a language is missing a string, gains one English never had, or loses a placeholder.
How do I report an accessibility problem?
Email the address on our imprint page with the screen, what you were using, and what happened. We acknowledge within 3 working days. An accessibility defect is a bug, not a feature request, and it is not a paid-tier matter — the free tier is covered identically.
Vulnerability Disclosure Policy
From /legal/disclosure
How fast will you respond?
We aim to acknowledge a report within 3 working days and to give you an assessment within 10. Keepsake is a small operation, so if you have heard nothing after 5 working days, send the email again rather than assuming it was ignored — it usually means it went to spam.
Do you pay a bounty?
Not at present. We are a one-person company selling £19 licences, and a bounty programme we could not honour would be worse than saying so plainly. What we do offer is credit on the security page for anyone who wants it, a free lifetime licence, and a straight answer about what we fixed and when.
Can I test against the live site?
Yes, within limits: no denial of service, no automated scanning that degrades service for others, no social engineering of the owner or the host, and no accessing another person's account or data. If a proof needs one of those, describe it instead of doing it and we will work out how to demonstrate it safely.
What about the vault format and the apps?
Those are the interesting targets and testing them needs no permission at all — the vault is a local file on your own machine, the format is published, and the desktop, Android and web clients are yours to pull apart. Findings in the cryptography, the key wrapping, the licence verification or the release signing are the most valuable reports we can receive.
Will you take legal action against me?
Not for research conducted under this policy in good faith. We will not pursue or support a claim against anyone who follows it, and if a third party does, we will say publicly that the work was authorised.
Not answered here? The help centre goes deeper, the community is where new questions get asked, and we answer email.