Trust & data security
Your data, and your security
DealKeep exists to organize the deals you've already bought — so we hold ourselves to a simple standard: collect as little as possible, protect what we hold, and never lock you in.
We record your deals, not your license keys
DealKeep does not store license keys or redemption codes for lifetime deals. Instead, DealKeep stores the organizational details needed to manage a stack: the tool, tier, plan, refund-window dates, and the categories you assign. Each tool has an optional free-text notes field that is yours to use, and nothing in DealKeep requires a key.
Your stack is yours, and only yours
DealKeep protects account data by isolating it to each user's account and encrypting it in transit and at rest, so no other user can see or query it. DealKeep stores passwords and account-recovery codes only as one-way hashes, never in plaintext.
We're a manager, not a marketplace
DealKeep earns from subscriptions, not from selling deals or your information — no affiliate commissions, no ad networks, no data brokers. Our incentives are aligned with you, not with advertisers or sellers. New to buying lifetime deals? The buyer FAQ covers refund windows, tiers and founder risk.
Leave whenever you want
DealKeep lets you delete your account and its data at any time, or request a copy of the personal information it holds. There is no lock-in and no dark patterns: the deal stack you organized remains yours to take with you. The Privacy Policy explains what DealKeep collects, how long it keeps it, and your rights.
Security facts you can check
Reassurance is cheap; these are the specific, verifiable measures in place, .
- HTTPS only, enforced by the browser. Every page sends
Strict-Transport-Securitywith a one-year max-age,includeSubDomainsandpreload, so a browser that has visited once will refuse a plain-HTTP connection to dealkeep.io afterwards. - Hardened response headers. A Content-Security-Policy,
X-Frame-Options: DENY(the app cannot be framed by another site) andX-Content-Type-Options: nosniffare sent on every response; camera, microphone and geolocation are disabled throughPermissions-Policy. - Isolation at the database, not just in the app. Account data lives in Postgres behind row-level security policies, so every query is scoped to the signed-in user by the database itself.
- Encrypted in transit and at rest. Connections use TLS; stored data is encrypted at rest by the database host, Supabase, which runs on AWS.
- Card details never touch DealKeep. Payments are processed by Stripe; card numbers are entered on Stripe-hosted forms and are not stored or seen by DealKeep's servers.
- Your data is portable. Export your tools as CSV from Settings at any time, and delete your account and its data yourself.
Sources
- Supabase security — Encryption at rest and in transit, and the compliance posture of the database host.
- Stripe security — How Stripe handles card data so merchants like DealKeep never do.
- DealKeep Privacy Policy — What is collected, how long it is kept, and your rights.
Frequently asked questions
Is it safe to store my lifetime deals in DealKeep?
Yes — DealKeep records the details of your deals (tool, tier, plan, refund dates, categories), not the license keys or redemption codes themselves. Your data is isolated to your account and encrypted in transit and at rest.
Does DealKeep store my license keys or redemption codes?
No. There's no field for license keys and we never ask for them. The only place a key could go is the optional notes field on a tool, which is entirely your choice.
Can I delete my data or export it?
Yes. You can delete your account and its data at any time, or request a copy of the personal information we hold. See our Privacy Policy for retention and your rights.
Does DealKeep sell my data?
No. We make money from subscriptions, not from selling deals or user data. There are no affiliate commissions and no ad networks — that independence is the point.
Start free → · Read the Privacy Policy · Pricing · Best lifetime deals