Privacy Policy
Draft. This page has been written by us and has not yet been reviewed by a lawyer. We have tried to describe what the code actually does rather than what a policy usually says. Where we are unsure, we have written that down instead of guessing.
Last updated: 8 August 2026. This version corrects the one dated 12 July 2026, which said lead records describe businesses and not private individuals. That was not true, and the section on lead data explains why.
Momentum Minds LLC, a New Mexico (USA) limited liability company doing business as Findkeep.io, operates Findkeep at leads.momentumminds.net. Contact for anything on this page: privacy@momentumminds.net.
We have two different roles, and they are not the same
Most privacy policies can get away with one. This product cannot, because it holds two kinds of personal data for two different reasons.
- Your account data — we are the controller. Your email address, your password hash, your plan and your usage of the Service. We decide what to collect and why, so the obligations are ours.
- The leads in your pipeline — we are the processor, and you are the controller. You choose who to search for, what to keep, what to write in the notes and how long to keep it. We hold it for you and act on your instructions. Our Data Processing Agreement is the contract for that.
The line between the two is not perfectly clean, and we would rather say so. You decide who to search for and what to do with the result; we decide which fields the search asks Google for, and how long a row lives by default. We treat you as the controller of your pipeline and ourselves as your processor, and confirming that split is one of the questions we have put to counsel.
Account data: what we hold as controller
- Your email address and password hash. The password itself is never stored — only an Argon2 hash of it. Legal basis: performance of our contract with you, Art. 6(1)(b).
- Your account and team. Which account you belong to, whether you are the owner or a member, and any invitations you sent or accepted. Basis: contract.
- Billing. Your Stripe customer id, your plan, your seat count and your subscription status. Payments run entirely on Stripe and we never see card numbers. Basis: contract, and legal obligation (Art. 6(1)(c)) for the records an invoice has to leave behind.
- Usage counters. How many searches your account has run in the current period, so the allowance can be enforced. Basis: contract.
- Your own Google API key, if you add one in Settings. It is encrypted at rest, used only for searches you ask for, and write-only: it is never shown back to you and you can remove it at any time. Basis: contract.
- Abuse-prevention records. To stop password guessing and repeat free trials we keep counter rows keyed on an HMAC of your email address or your IP address — never the address itself. The hash is computed with a secret only our server holds and cannot be turned back into an address. Basis: our legitimate interest in keeping accounts and our Google spend safe, Art. 6(1)(f).
- Server logs. The web server in front of Findkeep keeps ordinary access logs — IP address, time, the URL requested, the browser's user-agent — and the application logs errors. We use them to fix faults and investigate abuse, and nothing else. Basis: legitimate interest. These logs sit with our hosting provider and rotate on their schedule; we are confirming the exact period and will state it here.
We do not profile you, we do not advertise to you, we do not sell anything to anyone, and there is no analytics product anywhere in this application.
Lead data: what we hold as your processor
When you run a search, we ask the Google Places API for businesses matching your query and save each result to your account: the trading name, the phone number, the street address, the town, the business type, a link to the Google Maps listing, Google's own place identifier, and whether the business appears to have a website, only a social page, or nothing. To that we add whatever you record yourself — the pipeline stage, your notes, call outcomes, follow-up dates. Imported CSV rows work the same way. Findkeep does not enrich this data from any other source.
Some of these are people
The previous version of this page said lead records "describe businesses, not private individuals". That was wrong, and it was wrong in an obvious way: a great many Danish businesses are sole traders — a one-person firm trading under a name like NyFarve v/Jensen. A sole trader is a natural person. The trading name identifies them, the business number is often their own mobile, and the business address is sometimes their home. So yes: lead records in Findkeep can be, and frequently are, personal data about identifiable people who never heard of us.
The lawful basis, and the balancing test behind it
Where a lead is a natural person, the basis relied on is legitimate interests, Art. 6(1)(f) — our customer's interest in offering their services to businesses that may want them, and ours in providing the tool. That basis only works if it survives a balancing test, so here is ours, in the three parts it is normally done in.
- Is the purpose legitimate? Business-to-business direct marketing is capable of being a legitimate interest; Recital 47 of the GDPR names direct marketing specifically. The customers using Findkeep are typically selling web design to local trades who often have no website at all.
- Is it necessary? The data collected is limited to what the business itself has published in order to be contacted: trading name, business telephone, business address, and whether a website exists. No email addresses, no personal identifiers, no data from other sources, no scoring, no inference. You cannot make a calling list without a name and a number.
- Does it override the person's interests? This is the part that deserves honesty rather than a conclusion. In favour: the information was published by the business itself, in a business context, precisely so that people would ring it; the volumes are small; there is no profiling and no resale; and a phone call about a website is a low-impact approach. Against: a sole trader's business number is often their personal mobile; they did not give it to us and do not know we hold it; some will experience a cold call as an intrusion; and the record lives for as long as our customer keeps it, which could be years. We think the balance holds for the limited, published, business-contact data described above, provided the safeguards below are real. It would not hold for home addresses, personal email, or anything inferred.
The safeguards we rely on are: this page and the data request page as public notice; an absolute right to object to direct marketing, which we honour without weighing anything against it; a contractual duty on every customer to act on a removal request we forward to them; and a hard limit on what we collect. A fuller written assessment is being prepared for review — this section is a summary of it, not a substitute.
Article 14: what we owe a business we have never met
Article 14 of the GDPR says that when personal data is obtained from somewhere other than the person themselves, they must be told: who holds it, what it is, why, where it came from, how long it is kept, and what they can do about it. That is what this page is. All of it applies to lead records, and the source is always the same one: the Google Places API.
We cannot send that notice to each business individually. In most cases we hold no email address for them at all — only a telephone number — and the records sit in our customers' workspaces rather than ours. Art. 14(5)(b) allows the information to be made publicly available instead where individual notice would involve disproportionate effort, and this page plus the data request page are how we do that. Whether that is sufficient in our particular case is one of the questions we have put to counsel, and we will change this if the answer is no.
If you have found this page because someone called you about your business, the data request page is written for you. In short: you can ask what is held, ask for it to be corrected, ask for it to be erased, and object. An objection to direct marketing under Art. 21(2) is absolute — there is nothing for us to weigh, and we act on it.
Cookies and what is stored in your browser
Findkeep sets one cookie. It is called
findkeep_session, it holds a signed session token and nothing
else, and it carries HttpOnly, Secure and SameSite=Lax. If you tick
"Remember me" it lasts up to 30 days; if you do not, it disappears when you
close the browser. Signing out deletes it.
That cookie is strictly necessary to provide a service you asked for — without it there is no way to stay signed in. Under the ePrivacy rules (in Denmark, cookiebekendtgørelsen) strictly necessary cookies do not require consent, which is why Findkeep shows no cookie consent banner. There are no analytics cookies, no advertising cookies and no third-party cookies, because there is no analytics or advertising code in the product at all. We do count a few things about accounts on our own server — see “Product measurements” in the retention list below — but nothing in your browser reports to us or to anyone else, and no third party is involved.
Three preferences are kept in your browser's localStorage rather than in a cookie: your light/dark theme choice, your board filter, and which pipeline columns you have collapsed. They never leave your browser and are never sent to us. Clearing site data removes them.
If we later switch on the Cloudflare Turnstile anti-bot check, two pages will load a script from Cloudflare: the signup form and the form on the data request page. Both are pages you can reach without signing in, and it appears on none of the pages a customer uses day to day. It is not switched on today, and this page will say so when it is.
Who else touches the data
Google (the Places API), Stripe (payments) and our hosting provider are the three third parties involved today; an email provider is configured but not yet switched on. Each one, what it receives, where it processes and on what legal footing is set out on the sub-processor page, which also explains how we announce changes to that list.
International transfers
Momentum Minds LLC is a US company and Findkeep runs on a server in the United States. So if you are in the EU or the EEA, your account data and your leads are transferred to the United States as soon as you use the product, and Google and Stripe process in the United States too.
For transfers to us, the Data Processing Agreement incorporates the European Commission's Standard Contractual Clauses. For transfers onward to Google and Stripe, we rely on the transfer mechanism in each provider's own data processing terms; the sub-processor page names which. We have not appointed an Art. 27 representative in the EU yet. We are working on it, and until it is done, write to us directly at the address above.
How long we keep things, and the backups
Most of what Findkeep holds is kept until you delete it, because it is the thing you are paying us to keep. Six kinds of record expire on a timer instead, and these six are the whole list. Five of them are cleared by a housekeeping job inside the application that runs every six hours and deletes nothing else; the sixth is the nightly backup rotation.
- The live-activity feed: 7 days. When two people on the same account have the board open, each browser is told what the other changed. Those rows exist so a tab that was asleep can catch up, and they are deleted a week later. They record which lead changed and who changed it, not what was written.
- Team invitations: 7 days after an unaccepted one has expired, and 30 days after an accepted one was used. An invite row is somebody's email address with no remaining purpose once it has expired or been redeemed.
- Search progress logs: 30 days. A search writes a running narration of which towns and trades it covered. Thirty days after it finished, the narration is emptied and only the counts remain — how many results, how many requests were billed — because those are the accounting record behind what you were charged. A search still running is never touched, whatever its age.
- Sign-in rate-limit counters: 1 hour. The rows that slow down password guessing hold a keyed hash of an email address or an IP address and a count, and are swept an hour after their window closes.
- Product measurements: 180 days. We record a small number of milestones about each account — that it signed up, confirmed its email, started a trial, ran its first search, saved its first lead, logged its first call, invited somebody, and the days on which somebody signed in. Each row holds the account, the name of the milestone and the date, and nothing else: no name, no email address, no telephone number, no search you ran and no lead you saved. They are how we tell whether the product works, they are stored on our own server, and they are deleted after 180 days.
- Backups: 14 nights. Described in full below.
Two things are deliberately not on a timer, and it is more honest to name them than to leave the list looking complete:
- Your leads, their history and your account records are kept until you delete them or delete the account. There is no automatic expiry, and a lead you added three years ago is still there. If you are the controller of that pipeline, deciding how long a record should live is your call rather than ours — but it does mean the record of a business you never called is sitting in your account until you remove it.
- An abandoned unverified signup is not deleted. If you signed up, never clicked the verification link and never came back, your email address and the hash of your password are still here. We do not delete them on a timer because the account remains fully recoverable through the password-reset link — completing a reset verifies the address — so a timer would quietly destroy a real account. Write to us and we will remove it.
There is also the correspondence about data requests itself. If you write to us, or use the form on the data request page, what you send — your reply address, the business name and phone number you give us, and your message — is kept in the mailbox that receives it and written to the server's log so that a request is not lost if an email fails to send. We have not yet set a retention period for the server log; that is a setting on the host rather than in this application, and it is on the list of things to fix before this page stops calling itself a draft.
What deleting your account actually removes
This depends on whether you are the owner of the account or a member of somebody else's, because the two do quite different things:
- If you are the owner, deleting the account from Settings removes the whole workspace: your login, every membership, every lead and its call history, every search job, the usage counters, the invitations and the activity feed all go from the live database in one transaction, and any live subscription is cancelled first. Other members keep their logins but lose the workspace.
- If you are a member, deleting your account removes your login and your place on the team, and nothing else. The account, its subscription and every lead stay exactly where they are; the leads and searches you added stay with the account and are reassigned to the owner, and your name is removed from the activity feed rather than the entries being deleted. If you want the pipeline gone, that is the owner's decision, not yours.
A lapsed subscription never causes deletion.
The backups are the honest exception. We take one compressed snapshot of the whole database every night and keep the last 14 of them. A record you deleted therefore continues to exist in backup copies for up to 14 more nights before the last copy holding it is rotated out and destroyed. Those backups are only ever used to recover from a disaster; nobody reads them to answer a question about a customer, and if we ever have to restore from one we re-apply any deletion made since it was taken. Saying "deleted immediately" without this paragraph was not accurate, which is why the paragraph is here.
Five other things outlive account deletion, and you should know about all of them:
- The product measurements about
the account. The milestone rows described under retention above —
that the account signed up, confirmed its email, started a trial, ran its
first search, saved its first lead, logged its first call, invited
somebody, the days somebody signed in, and that it was deleted — are not
removed when the account is. Each row is the account's identifier, the
name of the milestone and the date, and nothing else: no name, no email
address, no telephone number, no search you ran and no lead you saved. We
keep them because the question they exist to answer is whether people stay
or leave, and deleting the rows for everybody who left would leave us
measuring only the customers who are still here. They are still deleted
after 180 days, on the same timer as everything else in
that list, so the last of them is gone six months after the account was.
The account export you can download before
you delete says the same thing, under
omitted, so the two cannot quietly disagree. - A record of anything we changed on
your account by hand. If we ever change something on your account
manually — at your request or to fix a fault on our side: lifting a hold,
correcting a search count, adding a seat — we keep one row recording what
was changed, when, by whom and why. That row includes the email address of
the account it concerned, as an ordinary readable address rather than a
digest, and we keep it after the account is deleted. We keep it because it
is the only record of what we did: if you or a regulator later asks why an
account was changed, the answer has to survive the account. It is not used
for anything else, it is never used to contact you, and it is written only
when a person at Momentum Minds runs a support command — a normal month
produces none at all. The account export you can download before you
delete says the same thing, under
omitted, so the two cannot quietly disagree. - The free-trial ledger. One row stays behind so that the same address cannot take an unlimited number of 14-day trials against our Google spend. It holds an HMAC-SHA256 digest of your email address and the date the trial was used, and nothing else — no address, no name, no payment data. The digest is computed under a secret only our server holds and cannot be turned back into an address by us or by anyone who obtained the table. We are not going to tell you it therefore stops being personal data, because that is a question with more than one respectable answer and it is one of the things we have put to counsel; what we can tell you is exactly what the row contains and why it is there.
- Your customer record at Stripe. We do not delete it
when you delete your account, and that is our decision, not something
Stripe imposes on us. The record holds the email address the account was
billed under, the billing name and billing address you gave Stripe, and a
card fingerprint — a one-way identifier Stripe derives from the card, not
the card number, which never reaches our server at all. It stays for two
reasons. The invoices and charges hanging off it are the only record of
what you paid us, so keeping it is what leaves them
answerable for a chargeback, a refund or a tax enquiry;
and the card fingerprint is the only signal on Stripe's side that stops
one person deleting an account and signing up again for an unlimited run
of free trials against our Google spend. The account export you can
download before you delete says the same thing, under
omitted, so the two cannot quietly disagree. If you want that record erased as well, write to privacy@momentumminds.net and we will treat it as an erasure request in its own right; how much of it can go depends on how old the invoices are and what the accounting rules require, which is one of the questions we have put to counsel. - Stripe's own records. Separately from the record above, Stripe keeps its own account of payments it has processed for as long as its legal and accounting obligations require. That part we could not delete even if we decided to. Deleting your Findkeep account does not erase your payment history at Stripe.
Security
Passwords are hashed with Argon2. Any Google API key you add is encrypted at rest. Everything is served over HTTPS; the session cookie is HttpOnly, Secure and SameSite=Lax; the app sends a Content-Security-Policy and verifies a CSRF header on every state-changing request. The database file itself sits on the server's disk and is not separately encrypted — see the security annex of the DPA for the full list of measures, including what we do not do.
Your rights
If you are a Findkeep customer, you may ask us for access to your personal data, correction, erasure, restriction and portability, and you may object to processing based on legitimate interests. Write to privacy@momentumminds.net and we will answer within one month.
Portability does not need a request. Two exports are built into the product and neither one involves asking us:
- Your leads as CSV — the Export button on the board. Eleven columns, opens in a spreadsheet, re-imports into Findkeep.
- Everything the account holds, as JSON —
/api/account/export.json, linked from Settings. Your leads with their full call history, your team, your invitations, your searches, your usage figures, the activity feed and your own settings, in one machine-readable file. It names the things it deliberately leaves out and why, and it never contains your password hash or any Google API key you have added.
Both stay available when a subscription has lapsed and when an account is on hold, which is deliberate: every message this product sends about a payment problem ends by saying your data is safe and always exportable, and a customer who cannot get their records out is a customer being held by them.
If you are in someone's pipeline rather than a customer, your rights are the same and the route is different — see the data request page.
You can complain to a supervisory authority. In Denmark that is Datatilsynet (datatilsynet.dk); if you are elsewhere in the EU or EEA, it is the authority for your own country.
Changes to this policy
We will update this page when the product changes, and the date at the top says when it last happened. If a change materially affects customers, we will email account owners before it takes effect.