The complete accounting. Short version: a record, a thumbnail, and a path back to the original. No copy of your files, ever.
Three things per file: the memory record (extracted text, plain-words nicknames, dates, amounts), a thumbnail, and the path back to the original. They live in one folder on your Mac, inside your user Library: Application Support, then Kepter. The index of records is encrypted; the thumbnails are a plain local cache so scrolling stays fast. Your originals are not in there. They stay exactly where you put them.
All of this reading happens on your Mac. All of the storing that follows happens on your Mac too.
Kepter writes its own memory record for each file, a thumbnail, and the path back to the original, into its own folder in your user Library. It never modifies the files it reads, and it never writes a copy of the file's own bytes into its store.
Nothing, in the reading and storing described above. The one place a network call can happen at all is described in full, with the exact conditions, on the receipts page: a sign-in path that isn't reachable from the download build, an update check that asks first, and a billing SDK that is inactive until billing turns on.
No cookies. No accounts. No analytics, telemetry, or crash reporting in the app. No third party sees your files, because none of them ever reach anyone but you. We do not sell data, and there is remarkably little of it to sell.
Quit Kepter and drag the app to the Trash to stop it. To remove the memory too, delete the Kepter folder from Application Support in your user Library; that removes every record and thumbnail. Your files are untouched, because Kepter never moved, copied, or held them.
Maltby Ventures LLC. hello@kepter.app.