Privacy

What Kefli keeps, and who can read it.

Your saves are encrypted on your phone before they leave it. We can't read which pages you've saved or what they say. This page sets out what we, and anyone else involved, can see.

Last updated 9 October 2026

On your phone

Kefli has no accounts. When you start a library, your phone makes a key that belongs to you alone, and shows it to you as a recovery code. The key stays in your phone's secure storage. Write the recovery code down: it's the only way to bring your library back on a new phone, and we can't recover it for you.

Your phone keeps a readable copy of your library in Kefli's private storage, so you can read and listen without a connection. Other apps can't open that storage.

On our server

Each save is encrypted with your key on your phone, and only then sent to Kefli's server. The article's text is encrypted the same way and stored as a separate file. What the server can see is limited to:

  • your library's public identifier, which is made from your key and doesn't say who you are;
  • how many saves you have, and when each was made or changed;
  • a label showing those saves belong to Kefli;
  • the size of each encrypted file, and how much of your 200 MB of storage they use.

Nobody but you can read which pages you've saved, their titles or their text. Listening uses your phone's own voice, so no server ever sees an article's text in readable form.

The copies

By default, every save is also copied to independent backup servers that we don't run. That's why your library outlives us: if Kefli closed tomorrow, everything you've already saved would still be there, and still readable and listenable in the app. The backup servers see the same encrypted saves our server sees, and no more.

Two things to know about timing:

  • A new save waits on your phone until our server can be reached, then goes out.
  • A new save can briefly have only Kefli's copy, until a backup server accepts it. The app counts any saves that aren't backed up yet, under Advanced.

What other sites learn

Some of what Kefli does has to talk to other websites, and they learn a little from it:

  • When you save a post from X, Kefli asks X for the post, so X learns which post was saved.
  • Pictures in an article are fetched when you read it, so the site hosting a picture learns which article is open.
  • If a site turns Kefli's fetch away, Kefli loads the page once in a browser engine on your phone, which runs the page's own scripts as any browser would.

Logs and backups

Nothing in any of our logs is a web address, a title or a piece of text you saved. Our servers log the time, the kind of request, the first part of its path, whether it worked, its size and how long it took. They don't log query strings, sign-in headers, what was sent or the page you came from. Where a log needs to tell libraries apart, it keeps a short, one-way fingerprint of the identifier, never the identifier itself. Logs are deleted after seven days.

We back up our server so a fault can't lose your library. Those backups hold the same encrypted files, and are kept for up to eight weeks, so after you delete your data, encrypted copies can remain in them for up to eight weeks before they expire.

This website

This website sets no cookies, runs no analytics and loads nothing from other sites: its fonts, pictures and films are all served from here.

The browser extension

The extension has its own privacy note, which covers what it reads from a page and where it sends it: Extension privacy.

Deleting your data

You can delete your library from all your devices and from our server, from inside the app. How to delete your data explains what's deleted, what we ask others to delete, and what can't be promised.

Questions

Write to privacy@kefli.app. We'll never ask for your recovery code, and you should never send it to anyone.