Feature

Getting documents in

Most vaults are empty because filing is a chore. Keepsake meets documents where they are born — the print dialog, the browser tab, the camera, the download folder.

The problem

A document vault only helps if the documents are actually in it. Yet the statement lives inside a banking site, the confirmation arrives as a web page, the certificate is a paper on the kitchen table, and the download folder is where PDFs go to be forgotten. Every extra step between "I have this" and "it is filed" is where a vault quietly dies.

How Keepsake solves it

🖨️Print to Keepsake (Windows)

A "Keepsake" printer appears in every print dialog. Print a statement or booking from any app and it arrives encrypted, read by OCR and filed — no export, no save-as, no download folder.

🌐Browser clipper (Chrome/Edge)

One click saves the page you are looking at into the web vault: the original file when the tab is a PDF, otherwise a full-page capture. The extension can push documents in, and has no way to read anything out.

📷Camera, folders, and your own Wi-Fi

Scan paper with the phone camera (auto edge-detect and deskew), let a watched folder import scanner output automatically, or pair phone and PC over the local network and move documents straight across.

✉️Saved emails, attachments only

Most policies and bills arrive by email. Save the message as a file, drop it in, and Keepsake files the <strong>attachments</strong> — not the message. The body is never read, stored or indexed, and what may be imported is an allow-list of document and image types, so anything else is refused on screen with the reason beside it.

📬A mailbox Keepsake checks for you

Point it at your own IMAP server — your address, your password, your folder — and the app on your device signs in over TLS, files the <strong>attachments</strong> of new messages and marks them read. Nothing else is touched: no mail is deleted, no message body is read, and there is no address of ours in the path, because the connection is made by your machine to your provider and by nothing in between. You can limit it to named senders, and every message it leaves behind is listed with the reason.

📁A whole folder at once

Moving in from somewhere else, or from a pile in Drive? Point Keepsake at the folder. It recognises a Trustworthy or Everplans download, a paperless-ngx export or a folder with a sidecar list from the folder’s own contents, and files everything with its titles, dates and tags. Nothing is uploaded and no other company is signed in to — the folder on your disk is the whole input.

Under the hood — capture without a middleman

  • The Windows printer is the stock "Microsoft Print to PDF" driver bound to a local port inside Keepsake's data folder — no driver to sign, nothing to break on a Windows update, and nothing leaves the PC.
  • The clipper asks for activeTab, scripting and storage only — no standing access to any site — and hands the bytes to your open vault tab, which encrypts them after you confirm.
  • A page capture stitches viewport screenshots into one image, cropping the final overlapping shot, so a long page does not come out with a repeated band through the middle.
  • LAN pairing uses an ephemeral X25519 handshake per session; the QR the PC shows carries its public key, so the phone pins it and an attacker on the network can break the connection but never sit inside it.
  • A dropped .eml or .msg is parsed on your own machine, and so is a message the mailbox check fetches: the fetched message is written out exactly as a saved one would have been and handed to the same importer, so both arrive by the same code and are refused for the same reasons. The rules for what may be imported live in one file that the Windows app, the phone and the web app all read.
  • The mailbox check is IMAP over TLS on port 993 and nothing else. There is no STARTTLS ladder to fall down, the app refuses any port but 993 before a socket is opened, and it will contact only the one host you configured. The password is held by Windows DPAPI or the Android Keystore — not in the vault, and not in anything that syncs — and after repeated sign-in failures the check stops itself and says so rather than presenting a password your provider may lock the account over.
  • Two things the mailbox check will never do: delete anyone's mail — there is no DELETE and no EXPUNGE anywhere in the client, which is how that stays true — and read a message body into your vault. Only attachments are filed, and each document is stamped with the mailbox, folder, sender and date it arrived from, which records where it came from and claims nothing about whether it is genuine.
  • A folder import decides what it is looking at from the folder itself, and the rules for every source live in one shared file the Windows app, the phone and the web app all read. Three things it will not do: guess an ambiguous date (04/12/2026 is refused rather than read as either), open an archive, or import a file the vault already holds — which is what makes it safe to run the same import again after adding thirty more documents.
  • Every path ends in the same import: encrypted on the device, OCR read, categorised, expiry picked up — however the document arrived.

Trust through specificity: the full crypto design is documented on the security page.

Questions

Does the browser extension read my vault?

It cannot. The protocol has no message that reads anything out — it can only offer bytes in, and your vault asks you to confirm each one before saving it.

Is the Keepsake printer a driver I have to trust?

It is Windows' own PDF printer pointed at a folder Keepsake watches. Adding it needs one administrator prompt; removing it takes the printer and its port away completely.

Do phone and PC transfers go through your servers?

No. Pairing is a direct connection over your own network. If your Wi-Fi is down, nothing transfers — there is no cloud fallback, by design.

Can I forward documents to Keepsake by email?

No, and that is deliberate: an address you forward to is a server of ours holding your mail, which is the one thing this product exists to avoid. Two things work instead, both on your own device — save the email as a file and drop it in, or give the app your own mailbox to check, which it signs in to directly and files the attachments from.

Is the mailbox check the same as connecting my Gmail?

No. There is no OAuth prompt, no token held on a server of ours, and nothing of yours reaches us: the app on your machine opens a TLS connection to the one IMAP host you named and to no other. Providers that require an app password issue one for exactly this, and revoking it in their settings ends the access immediately. The web app does not offer it at all, because a browser cannot open that connection and doing it any other way would mean putting a server of ours in the middle.

What does the mailbox check change in my inbox?

It marks a message read once its attachments are filed, and that is the entire list. Nothing is deleted, nothing is moved, and nothing is filed twice — a message it skips stays unread and is considered again next time.

Can Keepsake connect to my Google Drive or Dropbox and import from there?

No, and it is a deliberate refusal rather than a missing feature. A connector means holding a token that keeps standing access to another account of yours alive, and a server of ours in the path. Sync the folder so it is on your disk — which the desktop clients already do — and import the folder. It works offline, it cannot be switched off by anybody else, and it asks you to trust nothing.

What happens to an attachment Keepsake will not take?

It is listed with the reason next to it before anything is saved. Executables, archives and macro-enabled documents are refused by type, and a name dressed up as a document — statement.pdf.exe — is refused by name. Nothing is dropped silently, because an attachment you were never told about is one you believe is filed.