MOMENTS WORTH THE SECOND LOOK.

Privacy in for keeps

Your album starts privately on your phone. Signing in starts private backup. You choose what to share with someone, show others or make into a physical gift.

On your phone

Unfinished pairs and saved keeps can stay in the app’s local album. You can create locally as a guest.

When you choose Save or Share, the app creates an export for Photos or the system share sheet. Choosing a share destination does not make your private album public.

In the rework, deleting a keep removes its app-owned files, removes its backup copy when connected, stops its links and takes its shown copy off Ideas. A copy already saved to Photos or sent to another app is separate. Removing for keeps from your phone can also remove keeps that were never backed up.

Your account

Sign-in uses your email address and a six-digit email code. You do not create a for keeps password in the current app.

You can create an account and sign in without giving your birthday. If you later choose Show others or cash out earnings, for keeps asks for your full birthday to check that you are 18 or older. It is stored privately, separately from your public copies. Once recorded, it cannot be changed in the app.

Your account can include a name, account identifier, preferences, order history and support requests. Information supplied for checkout is used in that separate ordering flow. The rework has no public profile. Your own face stays on your phone.

Supabase provides the account and private storage service. The email delivery service sends the sign-in and verification messages you request.

Age information

Your private birthday is used to check age requirements. It is not shown with a keep or returned to public or reviewer views. A birthday below the app's minimum age of 13 is refused. Signing up without a birthday does not prove that someone is old enough for an age-restricted action.

When Ideas' made-by-others examples are enabled, people can view, report and block them without an account or a birthday. Choosing Show others and cashing out earnings require an account whose private birthday shows 18 or older.

Where the iPhone age-range check is available, Apple can share an age range before Show others, rather than a birthday. It is an additional check, not proof of identity; an under-18 range stops that action. This integration still needs confirmation on the released app and a physical iPhone.

Private backup when you sign in

The rework starts private backup each time you sign in, without a separate choice screen. It asks before merging two sets of keeps. A backup includes the two original photos and creation details such as caption, format, sequence, mode and timestamps, and each keep's date, names and note. It also includes who a keep is from and for, its occasion, a day you set it aside for, whether it came from a link, and the people you add and their dates. Until you sign in, these stay on your phone. Successful backup and restore still need verification in the released app.

Private backups are available to their account owner. They are separate from keeps you choose to show others and are not sent for public-sharing checks simply because you backed them up.

People and dates

You can give the people in your keeps a name (what you call them), a relationship such as Grandma, Lola, Ninong or Partner, and their dates: a birthday, an anniversary, a monthsary, a day they leave, come home or come home for good, a baptism, the first day of school, and dates you name yourself. A yearly date needs only a month and a day; the year is optional. You can also choose what each person celebrates. Birthdays, Christmas and anniversaries are on unless you turn them off. Eid, Chinese New Year and a year-end thanksgiving are only ever on when you tick them. Mother's Day and Father's Day show for a mother or a father by their relationship, and for anyone else only when you turn them on. for keeps never guesses anyone's faith, background or region from a name, a face or a place.

These details are kept on this phone and, when private backup is on, in your private backup with your keeps, so they come back when you restore on a new phone. Only you can see them; they are never public or used for ads. for keeps uses them on this phone to show dates that are coming up, when to order so a card arrives in time, which ideas to show and, if you turn on reminders, when to remind you. Without an account, they stay on this phone only.

You can mark someone as In memory, with the day they died if you want to add it. Each remembrance day stays off until the family turns it on: the anniversary of their death, their birthday, the 40th day, Undas, and Mother's or Father's Day. Like every other detail, this stays on this phone and in your private backup when it is on. It is never public, and a memorial card's link never offers Make your own.

Reminders are optional and stay off until you say yes. Your phone schedules them two weeks before and on the day for yearly days, and on the day only for monthly days. Remembrance reminders are only for days the family turns on. There are no reminders for observances. Nothing is sent to us or to anyone else to schedule these reminders. A surprise homecoming never appears in one; remembrance and leaving or homecoming reminders use quiet words without a name. You can change the reminder choices in the app or turn notifications off in your phone's Settings.

Each person can have a face: a drawn doodle that for keeps makes, a photo you take or choose, or a doodle drawn from that photo. With private backup, each person's face goes with their details: the doodle you picked and, for a photo, the circle and the whole photo it was cut from, so it comes back, circle and all, on a new phone. These photos are stored privately under your account, with no names in their file names. Only you can see them. They are never public, used for ads or used to recognise anyone. As a guest, they stay on this phone only. Your own face is separate: it stays on this phone, is not backed up and is not uploaded as a public avatar.

To draw a doodle from a photo, for keeps reads the face in the circle on this phone. The photo and what is read from it (where the eyes, nose, mouth and hair are) are not sent anywhere for this, and what is read is never kept: only the drawing's settings are. For a person you add, the whole photo stays on this phone and in private backup so you can move the circle later. It is removed when you change or remove that face, and from backup when that change syncs. Your own face stays only on this phone. for keeps does not use the photo to guess anyone's age, gender or identity. On Android, Google's ML Kit reads the face inside the app: it does not send the photo, but it may send Google information about the device and how the feature performed.

You can delete any date with its X, or remove a person entirely; their keeps stay, and the change reaches your backup the next time it runs. Deleting your account deletes the people in its backup, with their photos; removing its phone copies also removes them, and their photos, from this phone.

When you send a keep as a link, for keeps uploads the two card faces and the words, names and date you choose to Carry One's storage. Anyone with the link can see them once it opens. We do not list the page for browsing and ask search engines not to index it. It shows no price or account details. The default link lasts 90 days; switching it off or deleting the account ends access sooner. File removal follows the cleanup rules below. Someone who received the link may already have saved a copy. A link can stay sealed until a day and hour you choose; until then its page shows an envelope and the day.

If you add a voice message of up to 30 seconds, OpenAI transcribes the recording and checks its words. An approved recording stays in private storage and plays only when someone with the available link taps play. A recording rejected by the automatic check is left off and is not retained. If the check needs a person or cannot finish, we keep the recording privately, with a transcript if one is available, for an authorised reviewer. It is not playable from the gift page while held. A reviewer can include it or leave it off; either decision clears the retained transcript. Leaving it off removes the recording, with failed removals retried. Held and approved recordings otherwise end with the link.

When someone sends you a link and you tap Keep it, the app saves its photos, words and the sender's name as a keep on this phone, and in your private backup when it is on. Nothing is sent back, and the sender is not told.

If you ask us to take something down at forkeeps.carryone-creations.com/report, we keep the link, your reason and message, and your email if you give one, to review the request and reply. A reported link is hidden while we review it. If the account that sent it is deleted first, the link is removed and we close the request as taken down. The request record does not contain your internet address. It becomes due for deletion 365 days after we close it.

Birthday videos and greetings

When you make a birthday video with Made together, you send a link and people record short video greetings in their browser. They do not need the app or an account. A greeting includes its video and sound, the name the person types and an optional line. Each greeting is checked automatically. A transcript of its sound, its name and line, and still frames go to OpenAI. If it passes, the transcript is cleared and the checking files are removed through cleanup. Held or uncertain greetings stay private for an authorised reviewer. You choose which approved greetings go into the video and can remove greetings or stop a phone from sending more.

The birthday person gets the video from a link, and may save and share it. Anyone with the gift's link can watch it. The page is not listed or searchable. If she chooses, she can record her reaction while she watches (the picture only, no sound) and a thank-you. Nothing of hers is uploaded until she taps Add it to the video. Each is checked the same way, and she can remove it. You are never told whether she opened or watched it.

To limit abuse and let you block a phone, we keep a scrambled form of each sender's internet address (a salted hash) and a random id their browser makes. We never keep the address itself. The recording page keeps that id, and the code that lets a sender remove their greeting, in the browser's own storage. It uses no cookies. If the browser's data is cleared, the person who made the link can still remove the greeting, or anyone can report it.

A chip-in gift can also include photos and short lines. OpenAI checks these, and the organiser picks which approved contributions go into the gift. The draft retention periods below cover both kinds of gift. Material that must be preserved by law is held separately and never shown publicly.

Keep it on a disc. The organiser can order a disc through Make it real. Its NFC tag and printed QR code open the video's watch link. The headline, day and From name go with the Shopify order to the production desk; Shopify checkout takes the delivery address. Anyone who taps or scans the disc can watch the available video. A paid disc extends the finished video's keep to 10 years; starting production can extend that end date again. The video can remain after the organiser deletes their account, without the From name. This does not keep every separate uploaded clip for 10 years. Removal and reporting controls still apply; cancellation and refund rules are in the retention draft below.

If you are under 18, ask a parent or guardian before recording. Anyone can report a greeting or a gift from its page. Carry One's proposed review target is 24 hours; staffing and escalation arrangements must be confirmed before release.

Gift draw

Everyone who joins a gift draw gives a name and, if they want, a short wish line. The draw keeps who each person is giving to. Each person can see their own assignment; the organiser's view shows the people who joined and their wish lines, not everyone else's assignments or whether they sent anything. Joining needs no account, address or contact details. Join and member codes are kept by the service in scrambled form; your browser or the organiser's app keeps the code needed to return to your place. The draw and its member records follow the deletion periods below.

Keeps you choose to show others

When Show others is enabled and you choose it, for keeps creates a separate public pair from the selected photos for Ideas' made-by-others examples. The submission can include captions, creation details and the creator name associated with the submission. It does not make your private album public or upload your phone's own-face photo.

Every post needs its own tick confirming that everyone in the photo is OK with it being public. Letting Carry One feature a post in its own posts is a separate choice, off unless you tick it.

Before a submitted version is shown, OpenAI checks its public copies and text. It does not receive your private originals or album for this. Flagged or uncertain submissions remain private for Carry One's review. Only an approved version can be shown. Shown to others in your account is your private list of approved and pending submissions.

Before your first submission you agree to the sharing rules: no nudity or sexual content, hate, bullying, threats or violence, nothing that puts a child at risk, no spam or scams, and nothing you do not have permission to share. Carry One can remove a keep and ban an account that breaks these rules.

A ban hides that account's shared keeps and private links and restricts its actions. It is separate from deletion. If sign-in is blocked and you want your account deleted, contact Carry One for help. We retain private records of moderation and takedown decisions; their unresolved retention limits are listed below.

Your sharing controls

You can report or block a creator's shown keep without an account. Blocking hides that creator's examples for you. You can also stop showing your own keep. A report preserves private evidence of the shown pair and its details so Carry One can review it even if it is later removed.

To limit abusive reporting, the service uses scrambled, keyed versions of a random reporting code and a trusted internet address. It does not store the raw address in the report records. The 24-hour limit records are cleared when later reports are processed; a report keeps its scrambled reporting code. Carry One's proposed review target is 24 hours, with an appeal route and staffing still to be confirmed.

Removing a post from for keeps cannot retrieve copies that someone has already saved or shared outside the app.

Orders and rewards

A physical order uses the selected photos (two for a flip card, one for a keychain), the text you choose to engrave on a wooden keychain, and the creation and delivery details needed to make and deliver it. That can include:

Starting checkout does not show your photos in Ideas.

Orders are paid through Shopify's checkout or, in the app, through PayMongo, our payment provider. You type card details only on PayMongo's own page. for keeps and our order service never see them.

In your own hand. If you photograph a handwritten note for the insert, for keeps crops it and lifts the ink from the paper on this phone. Only that ink image, not the photo, goes to our order service to print. It follows the order-photo retention period. An unused ink upload becomes due for removal after 24 hours.

Someone else pays. A pay link shows the name you choose to show, the keep's picture, product, price and any gift-for name included in the order summary. It does not show a delivery address or your contact details. The payer gives a name and email; GCash also needs a Philippine mobile number. These details go to PayMongo and are kept with the payment attempt. A pay link ends after 48 hours, and we keep its code only in scrambled form.

Chip in. A chip-in link shows the keep's picture, the product, the price of one share and how many shares are in. Each payer gives a name and email, and a Philippine mobile number for GCash. You see the name, so you know who is in. The contact details go to PayMongo; the share record keeps a scrambled comparison value rather than the raw email or number. Nobody sees how much anyone else paid or who did not pay. Late shares and cancelled chip-ins enter the refund process; uncertain provider results wait for verification before a refund is retried. People may also add a photo and a line (see Birthday videos and greetings).

For an event. The event's kind and day, whose day it is, and the names you give each table, guest or sponsor (with a sponsor's part, such as Candle or Veil) go with the order to our production desk, which prints them on labels and inserts. No card shows another guest's name or any amount. If someone else pays the rest, their link shows only the keep, who asked and the amount of the rest.

Returning buyers. To notice when someone orders again, our order service compares scrambled (keyed-hash) versions of the phone number and email on paid orders. It never compares the numbers or addresses themselves. The people packing an order see only that it is from a returning buyer and which order it is, so they can add a small extra. You never see points, tiers or a count, and this is not used for ads.

Rewards and cash-out records are private. A cash-out request includes the GCash name and number you confirm. Where payouts are enabled, approved cash-outs go through PayMongo, and account cash-out requires an age check of 18 or older. The app does not automatically charge you for a later refund. Closed-account claims need the separate review described below.

How long we keep things — draft for approval

Draft wording for Marwin's review. These periods come from the prepared service, not a promise that all cleanup jobs are already running. A file can become unavailable before it is physically removed. A failed removal is retried. Copies someone saved outside for keeps are outside these cleanup rules.

Counting how for keeps is used

The optional usage-counting service is not approved for this rework and must remain undeployed until Marwin explicitly enables it. This draft does not describe those counts as active. Records needed to handle orders and payments still exist separately.

If counting is proposed later, its notice and choice must be reviewed first. The prepared code has a 395-day default, but only removes old records in limited batches when new counts arrive. It does not yet guarantee deletion after 13 months when collection stops.

Automatic checks and the services we use

For enabled features, OpenAI provides automatic checks on:

It receives only what is being checked, never your private album or backup, and only to check it.

Other services used by the prepared app include:

Provider locations, their own retention and any international transfers still need confirmation against Carry One's configured accounts before publication.

Crash reports

When enabled, crash reports help us understand what failed, the app version, the kind of phone and its system version, and which part of the app was open. They are intended to exclude your photos, keeps, captions, notes, people, dates and contact details. The app filters email addresses, phone numbers, links and codes from error messages before sending them. Sentry can add a random installation identifier; its removal must be confirmed in the configured service before release. These reports are for fixing the app, not advertising.

Where crash reporting is enabled, Sentry (Functional Software, Inc.) handles the reports. The final notice must confirm the configured storage region, identifier removal and retention period; the former 90-day statement is not treated as verified here. You can switch Crash reports off in the app's privacy settings.

Deleting an account

Account deletion asks you to verify your email again with a fresh code and confirm Delete account. The app also lets you choose what happens to its copies on your phone. A web deletion request cannot erase copies on another device or in Photos. A payment already in progress may need to be reconciled before deletion can complete.

When account deletion completes, it removes the account and its private backup and starts or completes removal of its shown keeps, stored account photos and keep links. Open takedown requests about its keep links close as taken down. Non-disc birthday-video and chip-in gift links become unavailable, and their content is queued for cleanup. Gift draws become due for the daily cleanup. A paid disc's video can remain until its extended end date without the organiser's From name; legal holds are also separate. The schedules and retry limits above apply, so deletion is not a promise that every file disappears within ten minutes or a day.

Unpaid earnings claims are preserved, including amounts below the normal PHP 200 cash-out minimum. The deletion receipt may include a reference and the earnings details returned by the service. Keep the reference for support; having a reference alone does not authorize a payout.

Private records needed to handle orders, refunds and earnings can remain, including pay-link and chip-in payments. No automatic expiry for those records is currently implemented.

A claim after account deletion — proposal for approval

This support process is proposed, not yet an implemented identity check or payment promise. Deleting an account does not forfeit a recorded unpaid claim. The service preserves the balance and related cash-out records for a restricted operator to review. A transfer already in progress can hold up deletion until its outcome is reconciled.

  1. Keep the deletion receipt and claim reference. Contact Carry One through the approved support channel once that channel is confirmed. Do not send a password, email sign-in code or full payment-card details.
  2. An authorised operator uses the reference to find the private claim, checks available, pending and reserved amounts, and checks any earlier payment or refund so the same amount is not paid twice.
  3. Before any payment, Carry One must verify that the claimant is entitled to the money and confirm the payment destination through a procedure approved by Marwin. A reference or a typed email alone is not proof. The verification method and the information it requires have not been implemented or approved.
  4. Carry One then confirms the verified outcome and payment reference through the approved channel. Claims below PHP 200 need a separate settlement route; the existing cash-out tools do not provide that route. No payout date, automatic payment or expiry of a claim is promised by this draft.
What still needs review before beta

Open questions for Marwin before approving this wording:

The beta is planned for the Philippines and people aged 13 or older. Show others and cash-out require the later age check. Show others and guest examples stay unavailable until their server, moderation and reporting gates pass. Links, Made together and Gift draw require their readiness checks; this notice does not certify deployment. Payments remain in test mode until Marwin authorises going live. Usage counting remains unapproved.

This is a local review page. Its public address, privacy wording, and related store disclosures have not been approved for publication.