Skip to content

We built Keryth so that we
genuinely cannot read your work.

Privacy is not a feature we added to Keryth. It is the reason Keryth exists. Here is exactly how it works. No jargon, no small print.

Your device Keryth app, desktop app, or browser Your chats and files All content starts here Encryption AES-256 on your device Our servers Secure, access-controlled infrastructure Receive encrypted block Unreadable without your credentials Temporary — sandboxed process File decryption Sandboxed virus scan RAG indexing and embedding Temporary plaintext only Plaintext deleted Immediately and automatically Encrypted storage Only encrypted copy kept EU-based LLM — encrypted transit Relevant excerpts sent to LLM EU-based provider · encrypted in transit Response encrypted AES-256 on our servers Your device — decrypt the response Readable only on your device

Read your writing

Our staff have no access to your files or chat history. The architecture makes this technically impossible, not just against policy.

Use your writing to train AI models

Your content is used for one purpose only: powering your own AI assistant. It is not used to train, improve, or fine-tune any model — ours or anyone else’s.

Sell or share your data

We do not sell personal data. We do not share it with advertisers, data brokers, or third-party analytics platforms. We share only the minimum required data with our payment provider Mollie, and our LLM provider Mistral. Both are EU based and bound by the same GDPR rules as we are.

Serve you advertisements

Keryth has no advertising model. Your subscription is our revenue. We have no financial incentive to profile you or monetise your attention.

Retain plaintext after indexing

The only moment your text exists unencrypted on our servers is during the RAG indexing step. It is deleted automatically and immediately — never stored, never logged.

Allow staff access during indexing

The indexing and embedding pipeline is fully automated and isolated. No member of staff has any technical means to access your content during this process — even if they wanted to.

LBFG Ltd, the UK-based company behind Keryth, is legally required to comply with UK GDPR, the domestic version of the regulation that was retained and enshrined into British law after Brexit. In practice, UK GDPR and EU GDPR are substantively identical. This means that whether you are writing from Paris, New York, Sydney, or anywhere else in the world, the same robust protections apply to your data when you use Keryth.

In plain terms, GDPR means we cannot collect data we don’t need, cannot keep it longer than necessary, cannot share it without your knowledge, and cannot use it for purposes you haven’t agreed to. It gives you real, enforceable rights over you own information, not just a privacy policy you have to trust us to honour, but legal obligations we are required by law to to uphold. If we breach them, you have the right to report us to the Information Commissioner’s Office (ICO) in the UK, or to your legal data protection authority if you are based in the EU or EEA.

These rights apply to you regardless of where in the world you are based. GDPR was designed to protect individuals, not just EU citizens. If you use a service operated by a UK or EU company, these protections follow you.

You can reach our privacy team directly at privacy@keryth.com. We aim to respond within two business days. You can also reach us directly on our Stoat server here https://stt.gg/KvK7MTRx and chat with our development team.

Ready to write with nothing to hide?