Monitored company
Keeper Security
clause.watch tracks 1 legal document published by Keeper Security, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Change history
2026-09-06 · Terms of Use
Summary of Changes
Scope of the Diff
- The diff indicates that approximately 15,240 words were removed from the document.
- No replacement language or newly added terms are provided.
- Because the deleted text is not shown, it is not possible to determine which provisions were removed or how the remaining agreement changed.
Key Legal Risks
Loss of Important Protections
The deleted material may have included provisions relating to:
- Confidentiality and data security
- Customer ownership of data and intellectual property
- Data retention and deletion
- Privacy obligations and regulatory compliance
- Warranties, indemnities, and limitations of liability
- Audit rights and breach notification
- Termination rights and post-termination obligations
- Service levels and support commitments
Removing such terms could materially reduce the customer’s protections or create uncertainty about the parties’ obligations.
AI Training and Data Use
The provided diff does not identify whether any provisions concerning AI training were added, removed, or changed.
In particular, the available information does not establish whether the agreement now:
- Permits the provider to use customer data, prompts, outputs, or usage information to train or improve AI models
- Limits AI training to de-identified, aggregated, or anonymized data
- Requires customer consent or provides an opt-out
- Prohibits use of customer data for model training
- Grants the provider rights to retain or reuse data after termination
- Addresses ownership of AI-generated outputs or derived models
- Requires human review, security controls, or restrictions on sensitive data
If the deleted text contained a prohibition or limitation on AI training, its removal could significantly expand the provider’s rights. Conversely, if it contained a provider permission to train models, its removal could restrict those rights. The direction of the change cannot be determined from the redacted diff.
Recommended Review
The complete deleted language should be obtained and compared against the current version, with particular attention to:
1. Customer-data ownership and permitted uses
2. AI model training, model improvement, and data-retention rights
3. De-identification and aggregation standards
4. Opt-out, consent, and deletion mechanisms
5. Confidentiality, security, and regulatory compliance
6. Liability allocation for unauthorized data use
Bottom line: This diff shows a potentially material wholesale deletion, but it does not provide enough information to identify the specific legal or AI-data changes.
2026-09-05 · Privacy Policy
Executive Summary
The revised terms consolidate and expand Keeper’s website, SaaS, partner, privacy, security, and support provisions. The most significant changes concern confidentiality, artificial intelligence, data governance, partner responsibilities, and liability. Customers should review the incorporated DPA, Privacy Policy, Partner Portal materials, and referenced online policies because these documents may change over time.
AI Training and Use of Data
- Customer Confidential Information and AI tools: The SaaS Terms now expressly prohibit either party from making the other party’s Confidential Information available to artificial intelligence tools—including generative AI and large language models—unless the use is solely internal, occurs in a secure access-controlled environment, and does not result in AI model training or unauthorized retention, disclosure, or use.
- Partner restriction: Partner Terms contain a similar prohibition on using Keeper Confidential Information with AI tools. The clause appears intended to prevent training models on confidential information, but it permits secure internal AI use if no training or unauthorized retention occurs.
- Potential ambiguity: The AI restrictions apply to “Confidential Information,” while the SaaS Terms separately define Customer Data as Customer Confidential Information. This should protect vault-related Customer Data contractually, but the terms do not provide detailed technical standards, audit rights, deletion requirements, or an express prohibition on all model training involving every category of customer-related data.
- Partner training data: The Partner Terms state that the partner authorizes Keeper to process “training data” through third-party providers and represents that it has the necessary rights to do so. “Training data” is not clearly defined and could create uncertainty about whether it includes partner, reseller, employee, or customer information. Partners should seek clarification and confirm that appropriate notices, consents, and downstream contracts exist.
Customer Data and Privacy
- Keeper states that it may collect, use, and analyze aggregated, anonymized usage, telemetry, and operational data to operate, secure, support, and improve the Services, provided the data does not include Customer Data or identify customers or users.
- The Privacy Policy distinguishes between Keeper acting as a processor for business customers and an independent controller for account registration, billing, support, service analytics, website interactions, and partner-program information.
- Business administrators may access and process user data, including insights derived from users’ interactions with the Services. This expands the importance of employer/admin controls and applicable organizational privacy notices.
- Keeper continues to state that it cannot access encrypted vault contents, Master Passwords, or encryption keys under its zero-knowledge architecture.
Other Important Changes and Risks
- Website submissions are expressly nonconfidential; Keeper may retain, monitor, or remove communications, and feedback becomes Keeper’s sole property.
- SaaS terms impose broader customer duties concerning security configuration, backups, access controls, endpoint encryption, notices, and consents.
- Customer liability is generally capped at fees paid in the prior 12 months, with a higher cap for indemnification obligations; exclusions apply for IP misuse, fraud, gross negligence, willful misconduct, and non-limitable liabilities.
- Partner terms allow Keeper to update Partner Portal terms, channel requirements, discounts, and commercial conditions, generally binding partners through continued participation.
- Trials/evaluations receive reduced protections and may not undergo the same security reviews or compliance audits as paid Services.
2026-09-04 · Terms of Use
Summary of the Available Change
Scope of Deletion
The diff states that approximately 15,240 words were removed, but it does not identify which provisions were deleted or provide the replacement text.
Because the deleted language is unavailable, it is not possible to determine with confidence:
- Which contractual rights or obligations changed
- Whether liability, indemnity, confidentiality, security, or termination terms were removed
- Whether pricing, service levels, warranties, or audit rights were affected
- Whether data-processing terms were narrowed or eliminated
- Whether the agreement now contains gaps or conflicting provisions
AI Training and Customer Data
The supplied diff does not show any specific language concerning AI models or training. Accordingly, it is impossible to confirm whether the revision:
- Permits or prohibits using Customer Data to train, fine-tune, validate, or improve AI models
- Restricts use to aggregated, de-identified, or anonymized data
- Allows human review or disclosure of Customer Data for model development
- Grants the provider ownership or broad usage rights over prompts, inputs, outputs, or derived data
- Requires deletion or segregation of Customer Data from training datasets
- Applies different rules to personal data, confidential information, or sensitive data
- Gives the customer an opt-out or requires affirmative consent
- Imposes retention, security, audit, or breach-notification obligations relating to AI training
The removal of a data-use restriction could materially expand the provider’s ability to use Customer Data. Conversely, removal of a provider authorization could restrict such use. The effect depends entirely on the missing provisions.
Key Legal Risks Created by the Incomplete Diff
- Scope risk: A large deletion may have removed important protections without showing what replaced them.
- Interpretation risk: If defined terms, exceptions, or cross-references were deleted, remaining provisions may become ambiguous or ineffective.
- Data-protection risk: Deleted privacy or security language could create uncertainty regarding lawful processing, retention, subprocessors, international transfers, and regulatory compliance.
- AI-specific risk: Any deleted training-related limitation could permit broader use of customer information than expected, potentially including confidential or personal data.
- Operational risk: Deleted service levels, support commitments, or security obligations may reduce the customer’s remedies.
Recommended Next Step
Obtain the full redline or both the prior and revised versions of the agreement. The deletion-only summary is insufficient to assess the legal effect, particularly regarding Customer Data and AI-model training.
2026-09-01 · Privacy Policy
Contract Change Summary
Overview
The diff indicates that approximately 15,240 words were removed from the document. However, no text showing the deleted provisions has been provided. Because the deletions are summarized rather than reproduced, it is not possible to determine which rights, obligations, limitations, or protections were removed.
Key Risks
- Material terms may have been deleted: The removed content could include provisions on fees, service levels, warranties, indemnities, liability caps, confidentiality, security, audit rights, termination, governing law, or dispute resolution.
- Risk allocation may have changed: Deleting disclaimers, liability limitations, indemnities, or customer obligations could materially shift risk between the parties.
- Customer protections may have been removed: The deletion may affect data security commitments, breach-notification obligations, data-processing restrictions, deletion/return requirements, or regulatory compliance terms.
- Operational uncertainty: If definitions, procedures, or incorporated schedules were removed, the remaining contract may contain gaps or conflicting provisions.
AI Training and Customer Data
The provided diff does not show the deleted language, so it is impossible to determine whether the contract changed:
- Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether such use requires customer consent or may occur automatically;
- Whether data is anonymized, de-identified, aggregated, or retained for training;
- Whether prompts, inputs, outputs, usage data, or telemetry are included;
- Whether the provider may share data with affiliates or third-party model providers;
- Whether customers can opt out of AI training;
- How long training data is retained; or
- Whether the provider must delete customer data and derived model artifacts upon termination.
Any deletion of these provisions could either remove a customer restriction on AI training or remove a customer protection or opt-out right. The direction and practical effect cannot be determined from the summary alone.
Recommended Next Step
Obtain the actual deleted text and the complete before-and-after versions. The AI-data provisions should be specifically compared for language concerning:
1. “Train,” “fine-tune,” “improve,” or “develop” models;
2. Customer Data, Content, Inputs, Outputs, and Usage Data;
3. Consent and opt-out mechanisms;
4. De-identification or aggregation requirements;
5. Retention and deletion; and
6. Third-party or affiliate access.
Without the underlying text, no reliable conclusion can be drawn about the legal effect of the changes.
2026-08-31 · Terms of Use
Summary of Changes
Overall Change
- The diff states that approximately 15,240 words were removed from the document.
- No replacement language or text showing what was removed has been provided.
Legal and Commercial Significance
- This is potentially a material change. Removing a large portion of a contract could eliminate or weaken important provisions, including:
- Data-use permissions and restrictions
- Confidentiality and security obligations
- Intellectual-property ownership and licensing
- Liability limitations and indemnities
- Warranties and disclaimers
- Termination and deletion obligations
- Audit, compliance, and dispute-resolution rights
- The legal effect cannot be determined reliably without seeing the deleted text and the remaining agreement. A deletion may either reduce a party’s obligations or remove protections that previously benefited the customer.
Customer Data and AI Training
- The provided diff does not identify whether customer data may be used to train, fine-tune, evaluate, or improve AI models.
- It is therefore impossible to determine whether:
- Customer data may be used for model training;
- Data may be combined with other customers’ data;
- Human reviewers or service providers may access data for training or quality control;
- Prompts, outputs, metadata, or usage information may be retained and used for product improvement;
- The provider must obtain consent before using customer data for AI purposes; or
- The provider must delete training data or model-derived information after termination.
- Because the deletion is extensive, it may have removed either an AI-data-use authorization or a restriction on such use. This should be treated as an unresolved and potentially significant risk until the deleted provisions are reviewed.
Recommended Next Steps
- Obtain the full before-and-after versions or a redline showing the actual deleted language.
- Search the removed and remaining text for terms such as “train,” “training,” “fine-tune,” “improve,” “machine learning,” “artificial intelligence,” “models,” “customer data,” “content,” “prompts,” “outputs,” and “service improvement.”
- Confirm expressly that customer data, prompts, outputs, and related metadata may not be used to train or improve AI models without the customer’s prior written consent, unless that use is intended and appropriately limited.
2026-08-30 · Terms of Use
Change Summary
1. New or Consolidated Website Terms
- The website terms appear to have been substantially expanded or reorganized, including provisions covering:
- Website use restrictions, scraping and automated data collection;
- Electronic communications and non-confidential submissions;
- Personal-data handling through chat, forms and email;
- Intellectual property ownership;
- Disclaimers, liability limits, indemnification and termination;
- Entity-specific governing law and venue.
- Risk: Website submissions are expressly deemed non-confidential. Users should not submit passwords, confidential business information, sensitive personal data or security vulnerabilities except through designated channels.
- Continued website use accepts updated terms, creating a unilateral-change risk.
2. Customer Data and AI Model Training
SaaS Terms
- Customer Data expressly includes data supplied by the customer or users, including vault records, and is classified as Customer Confidential Information.
- Keeper may collect, use and analyze aggregated, anonymized usage, telemetry and operational data to operate, secure, support and improve the services, provided it does not include Customer Data or identify the customer or users.
- Confidential Information may not be made available to artificial-intelligence tools, including generative AI and large language models, except for internal use in a secure, access-controlled environment that:
- does not result in AI model training; and
- does not cause unauthorized retention, disclosure or use.
- Positive protection: This is an express contractual restriction against using confidential customer information to train AI models.
- Residual risk: The restriction applies to “Confidential Information,” but the permitted use of aggregated/anonymized telemetry could potentially support machine-learning or AI development if Keeper considers the data sufficiently anonymized. The agreement does not provide detailed de-identification standards, audit rights or a specific prohibition on training models using derived or anonymized data.
Partner Terms
- Partners receive a similar restriction against making Keeper Confidential Information available to AI tools, except in a secure environment without model training.
- However, Partner Terms state that the Partner has rights to authorize processing of “training data” by third-party providers.
- Important ambiguity/risk: “Training data” is not defined and could be read broadly. It may create uncertainty about whether certain partner-provided information can be used to train systems, particularly by vendors supporting Keeper’s learning-management or supplemental services. Partners should seek clarification that customer, end-user and confidential information will not be used for AI-model training without express, informed authorization.
3. Privacy Policy Changes and Data Use
- Keeper distinguishes between controller and processor roles. For business customers, it generally acts as processor, while independently controlling account, billing, support, website and usage-analytics data.
- Business administrators may access and process insights derived from users’ interactions with the services, subject to the organization’s controls and privacy notices.
- Keeper may use limited contact, payment and usage information through vendors for support, analytics, marketing and account operations.
- The policy states that Keeper does not access encrypted vault contents and does not sell or share personal information under applicable privacy laws.
- Risk: “Usage analytics,” “insights” and aggregated data are described broadly. The policy does not expressly state that these categories will never be used for AI or machine-learning model training.
4. Other Material Risks
- Customer is responsible for backups, access controls, endpoint security and obtaining required notices and consents.
- Fees are generally nonrefundable; automatic recurring billing and suspension rights apply.
- Liability is capped generally at fees paid in the preceding 12 months, with limited exceptions.
- Service availability is 99.9%, but the remedy is generally limited to termination.
- Free or evaluation products may lack normal security reviews, support and reliability.
2026-08-28 · Privacy Policy
Key Changes and Legal Risks
> Note: The diff appears to add or consolidate extensive terms, with the prior text largely unavailable. The analysis below focuses on material provisions appearing in the revised text.
1. Customer Data and AI Model Training
SaaS Terms
- “Customer Data” expressly includes data provided by the customer or users, including vault records, and is classified as Customer Confidential Information.
- Keeper may collect, use and analyze aggregated, anonymized usage, telemetry and operational data to operate, secure, support and improve the Services.
- This permission is expressly limited to data that:
- does not include Customer Data; and
- does not permit identification of the customer or its users.
- Confidential Information may not be made available to artificial intelligence tools, including generative AI and large language models, unless:
- used solely internally;
- in a secure, access-controlled environment; and
- the use does not result in AI model training or unauthorized retention, disclosure or use.
Risk/impact: The wording is favorable regarding training on Customer Data, but the exception for “aggregated anonymized” data is broad and does not expressly address whether telemetry or usage patterns could be used to train or fine-tune AI systems. Customers should seek confirmation that no Customer Data, prompts, outputs, metadata, or identifiable usage information will be used for model training.
Partner Terms
- Partners are subject to a similar AI restriction for Confidential Information.
- However, the Partner Terms also state that the partner authorizes Keeper to engage third parties and confirms it has rights to authorize processing of “training data” through those providers.
Important inconsistency/risk: “Training data” is not defined. This could authorize processing of data used for training—potentially broader than the SaaS restriction—and may create compliance and consent obligations for partners, especially where they act as processors for resellers or end customers.
2. Privacy and Data-Protection Changes
- Keeper’s role is differentiated:
- generally a processor for business customers;
- an independent controller for account, billing, analytics, support, website and partner-program information.
- Business administrators may access and process user data, including insights derived from service use.
- The Privacy Policy and DPA are incorporated into the agreements.
- Keeper may transfer personal data internationally using the Data Privacy Framework, Standard Contractual Clauses and other mechanisms.
- Vendors may receive limited personal, payment, usage and support information.
Risk: The policy permits analytics, marketing optimization, cookies and service-improvement processing outside the encrypted vault. “Zero Knowledge” therefore does not mean that all account-related metadata is inaccessible or excluded from analytics.
3. Commercial and Operational Risks
- Annual fees are generally nonrefundable and automatically recurring.
- Keeper may change prices at renewal and update incorporated policies or Partner Portal terms.
- Service availability is 99.9%, but only for the Keeper Services API and subject to broad exclusions.
- The sole remedy for service-level failure is termination.
- Disaster recovery objectives are an 8-hour RTO and 24-hour RPO, potentially allowing up to 24 hours of data loss.
- Liability is generally capped at fees paid in the prior 12 months, with limited exceptions.
- U.S. customers must generally arbitrate disputes in Wilmington, Delaware.
4. Data Retention and Deletion
- Paid subscriptions not renewed within 90 days may result in deletion of vault files.
- Inactive free accounts may be deleted after 12 months.
- Keeper cannot decrypt vault data or modify vault contents, which may limit practical access, correction and deletion remedies.
2026-08-24 · Terms of Use
Summary
Scope of the Change
The diff states only:
> [Removed approximately 15,240 words from the document]
No replacement text or details identifying the deleted provisions are provided.
Legal and Commercial Risks
Because the deleted language is not shown, it is not possible to determine which contractual rights or obligations have changed. The deletion could potentially affect important areas such as:
- Data ownership and permitted use
- Confidentiality and security obligations
- Customer warranties and indemnities
- Liability limits and exclusions
- Service levels and support
- Termination and data deletion
- Intellectual-property rights
- Audit and compliance obligations
- Subcontractor or third-party use
- Governing law and dispute resolution
A deletion of this size creates a significant review risk: provisions may have been removed without corresponding replacement language, leaving gaps or unintentionally shifting risk to the customer.
AI Training and Customer Data
The available diff does not identify whether customer data may be used to train, fine-tune, evaluate, or improve AI models. It is therefore impossible to confirm whether:
- Customer data may be used for provider-wide model training;
- Data may be used only to provide the contracted services;
- Customer prompts, inputs, outputs, or usage data are retained;
- De-identified, aggregated, or pseudonymized data may be used;
- Human reviewers or third-party AI providers may access the data;
- The customer can opt out of training or secondary use;
- Customer data is deleted from training systems after termination; or
- The provider makes commitments regarding model confidentiality, memorization, or isolation.
If provisions addressing these topics were deleted, the customer may have fewer protections or may face ambiguity about secondary use of its data. Conversely, the deletion may have removed a broad provider right to train models, but that cannot be determined from the supplied information.
Recommended Action
Obtain the actual deleted text and any replacement language before approving the change. Particular attention should be given to provisions concerning “customer data,” “usage data,” “service improvement,” “machine learning,” “artificial intelligence,” “model training,” “aggregated data,” and “de-identified data.” Until reviewed, treat the amendment as potentially material and do not assume that customer data is excluded from AI training.
2026-08-23 · Privacy Policy
Change Summary
1. AI and Model-Training Provisions
SaaS Terms
A new confidentiality restriction addresses artificial intelligence tools, including generative AI and large language models. Neither party may provide the other party’s Confidential Information to AI tools unless:
- The use is solely for the receiving party’s internal purposes;
- The AI environment is secure and access-controlled; and
- The information is not used for AI-model training or unauthorized retention, disclosure, or use.
Risk/impact: This is a meaningful restriction on using customer or Keeper confidential information with third-party AI services. It does not expressly prohibit all AI processing of Customer Data, however. The restriction applies to “Confidential Information,” while Customer Data is separately defined as Customer Confidential Information. Keeper may still process permitted aggregated, anonymized usage, telemetry, and operational data to operate, secure, support, and improve the Services.
Partner Terms
The Partner Terms contain a similar prohibition on submitting Confidential Information to AI tools except in a secure, access-controlled environment that does not result in model training or unauthorized retention or disclosure.
However, the Partner Terms also state that the Partner has the necessary rights to authorize “the processing of training data” through third-party providers.
Risk/impact: This wording is potentially ambiguous and should be clarified. It could be read as authorizing third-party providers to process data described as “training data,” despite the separate prohibition on AI model training. The agreement does not define “training data,” identify the providers, or specify whether any data may be used to train, fine-tune, evaluate, or improve AI models.
Privacy Policy
The revised policy states that:
- Business-customer data is generally processed by Keeper as a processor and only to fulfill contractual obligations or customer instructions.
- Keeper does not access encrypted vault contents under its zero-knowledge architecture.
- Keeper may use limited contact, payment, technical, service-usage, analytics, and diagnostic information to operate and improve services.
- Vendor/service-provider processing is limited to essential business functions.
There is no express blanket statement that Customer Data will never be used to train AI models. The policy also does not clearly distinguish ordinary service improvement from AI training, model evaluation, or machine-learning development.
2. Other Important Changes
- The website navigation appears streamlined by changing “Legal & Compliance” to “Compliance.”
- A “Legacy Terms” section now identifies terms applicable before March 9, 2026, potentially indicating a new effective-version structure.
- Partner terms allow Keeper to update Partner Portal program terms and requirements, with continued participation constituting acceptance. This creates an ongoing unilateral-change risk.
- Business administrators may access and process user data, including usage-derived insights and account controls; end users should not assume their organizational account activity is private from the administrator.
- Evaluation versions may receive reduced security review, support, reliability, and compliance protections, with broad disclaimer of liability.
Between 2021-08-11 and 2022-12-28 · Terms of Use
Change Summary
1. AI and Customer Data Use
New restrictions on AI use of confidential information
The SaaS Terms now expressly prohibit either party from making the other party’s Confidential Information available to artificial intelligence tools, including generative AI and large language models, except where all of the following apply:
- The use is solely for the receiving party’s internal purposes;
- The AI environment is secure and access-controlled; and
- The information is not used for model training or unauthorized retention, disclosure, or use.
The Partner Terms contain a similar restriction for Partner Confidential Information. This is a meaningful protection against confidential business information being submitted to public AI tools or used to train external models.
Customer Data excluded from service-improvement analytics
The SaaS Terms state that Keeper may collect, use, and analyze aggregated, anonymized usage, telemetry, and operational data to operate, secure, support, and improve the Services. This permission is expressly conditioned on the data:
- Not including Customer Data; and
- Not permitting identification of the Customer or its Authorized End Users.
This appears to prohibit using vault records or identifiable Customer Data to train or improve AI models. However, the clause does not expressly mention AI training, synthetic data, model development, or re-identification risk. “Aggregated anonymized” may therefore require careful interpretation and technical validation.
Potential ambiguity involving “training data”
The Partner Terms state that Partner authorizes Keeper to use third parties to administer, support, and deliver services, and that Partner has the necessary rights to authorize “the processing of training data through such providers.” This is potentially significant and unclear:
- “Training data” is not defined;
- It could refer to employee or partner training materials, but could also be read broadly enough to include data used for AI or other model training; and
- It may conflict with the separate prohibition on AI model training involving Confidential Information.
Partners should seek clarification or require a definition confirming that Customer Data and Confidential Information cannot be used for AI training.
2. Privacy Policy Changes
The Privacy Policy more clearly distinguishes Keeper’s roles as:
- A processor for business Customer Data; and
- An independent controller for account registration, billing, support communications, usage analytics, website interactions, and partner-program information.
Keeper states that business Customer Data is processed only to fulfill contractual obligations or as instructed by the business customer. It also states that encrypted vault contents remain inaccessible under the zero-knowledge architecture.
The policy permits automated chat tools to record requests, suggest content, and assist responses, but does not expressly state whether those tools use submitted information for AI training. Customers should review vendor terms and obtain confirmation that support communications are not used for model training.
3. Other Material Risks
- Privacy Policy and Partner Portal terms may be updated periodically, with continued use or participation constituting acceptance.
- Business administrators may access usage-derived insights and control account features.
- Customer remains responsible for security configuration, access controls, endpoint encryption, backups, notices, and consents.
- Liability is generally capped at fees paid during the preceding 12 months, with limited exceptions.
- U.S. customers are subject to mandatory arbitration in Delaware for most disputes.
- Free or evaluation versions disclaim support, security reviews, and liability.
Between 2020-04-10 and 2022-04-29 · Privacy Policy
Summary of Changes
Overall Change
- Approximately 15,240 words were removed from the document.
- No replacement text or added provisions are provided in the diff.
- Because the deleted language is not included, it is not possible to determine which specific rights, obligations, limitations, or protections were removed.
Customer Data and AI Training
- The provided diff contains no visible language addressing customer data, AI training, machine learning, model development, or related data rights.
- However, the large-scale deletion may have removed provisions concerning:
- Whether the provider may use customer data to train or improve AI models;
- Whether customer data may be aggregated, anonymized, or de-identified for model training;
- Whether prompts, inputs, outputs, usage data, or metadata may be retained or analyzed;
- Ownership or licensing of customer data and AI-generated outputs;
- Opt-out rights or restrictions on using confidential or personal information;
- Security, deletion, retention, or data-isolation obligations.
Key Legal Risks
- Unclear allocation of rights: The deletion may eliminate express limits on the provider’s use of customer data or may remove customer protections and usage rights.
- Potentially broader implied permissions: If data-use restrictions were deleted without replacement, the remaining agreement may permit broader use of data under general rights, service-improvement, or license provisions.
- Loss of protections: Deleted provisions may have included confidentiality, privacy, security, indemnity, audit, deletion, or regulatory-compliance protections.
- Interpretation uncertainty: A court or contracting party may rely on the remaining language, which could create ambiguity about data ownership, permitted uses, and AI-training rights.
- Operational and compliance exposure: If customer data can be used for AI training or service improvement, this could create confidentiality, privacy, intellectual-property, or sector-specific regulatory risks.
Recommended Review
The deleted 15,240 words should be retrieved and compared with the current version before approval. Particular attention should be given to provisions addressing:
1. Customer Data and Confidential Information;
2. AI or machine-learning training and model improvement;
3. Data licenses and permitted processing;
4. Aggregated, anonymized, or de-identified data;
5. Retention, deletion, and security;
6. Ownership of inputs, outputs, and derived data; and
7. Opt-out, consent, and subcontractor or third-party access rights.
Conclusion: The diff is too abbreviated to confirm the substantive legal effect, but the scale of the deletion creates a significant risk that important customer-data and AI-training protections have been removed.
Between 2015-04-05 and 2020-04-20 · Terms of Use
Summary of Important Changes and Risks
1. New or Consolidated Legal Documents
The update appears to reorganize Keeper’s legal materials into a central terms page containing:
- Website Terms of Use
- SaaS Terms of Use
- Partner Terms
- Privacy Policy
- Service Level Objectives
- Support terms
- Usage Guidelines
- Security, zero-knowledge, trust-center and other resource pages
- Legacy terms retained for versions before March 9, 2026
Risk: Many important obligations are incorporated by reference to webpages, policies, the Data Processing Addendum (“DPA”), Partner Portal materials and documentation. Those materials may change separately, potentially altering the parties’ rights and obligations without a separately signed amendment.
2. Customer Data and Zero-Knowledge Commitments
The SaaS Terms define “Customer Data” broadly to include data supplied by the customer or end users, including vault records, and classify it as Customer Confidential Information.
Keeper states that:
- Customer controls the master password and encryption keys.
- Keeper cannot access encrypted vault records.
- Keeper may collect limited account, support, telemetry and operational information.
- Keeper may use and analyze aggregated, anonymized usage, telemetry and operational data to operate, secure, support and improve the services.
- Such data must not include Customer Data or permit identification of the customer or end users.
Risk: The exclusion for Customer Data is helpful, but “aggregated,” “anonymized,” “usage,” “telemetry,” and “operational data” are not precisely defined. Customers should confirm whether metadata, activity patterns, administrative analytics or derived insights could be used for product improvement.
3. AI Model Training Restrictions
A new express confidentiality restriction provides that neither party may make the other party’s Confidential Information available to artificial intelligence tools, including generative AI and large language models, except for internal use in a secure, access-controlled environment that:
- Does not result in AI model training; and
- Does not cause unauthorized retention, disclosure or use.
The Partner Terms contain a similar restriction, although they include a drafting error (“it's internal use”).
Importance: This is a significant limitation on AI use and appears to prohibit submitting Customer Confidential Information—including Customer Data—to external AI tools where the information may be retained or used to train models.
Residual risk: The clause applies to “Confidential Information,” not necessarily all personal data or non-confidential information. It also does not expressly address AI outputs, model memorization, provider logging, prompt retention, or use of de-identified data. The DPA and Privacy Policy should be reviewed for consistent AI-processing language.
4. Privacy Policy Changes
The Privacy Policy more clearly distinguishes Keeper’s roles:
- Processor for business-managed accounts.
- Independent controller for registration, billing, support communications, website interactions, analytics and partner-program information.
- Controller for individual and family users.
It also authorizes use of vendors for support, analytics, payment processing and live chat, and permits international transfers using the Data Privacy Framework, Standard Contractual Clauses and other mechanisms.
Risk: Keeper may use service and usage data for analytics, service improvement and marketing, subject to applicable law. Business customers should ensure their DPA, notices and instructions adequately restrict these uses.
5. Commercial and Liability Changes
Notable customer risks include:
- Annual fees generally nonrefundable.
- Automatic recurring charges.
- Suspension for unpaid fees.
- Liability generally capped at fees paid in the prior 12 months, with a higher cap for indemnification.
- No liability cap for IP misuse, fraud, gross negligence or willful misconduct.
- U.S. customers contracting with Keeper Security, Inc. are generally subject to Delaware arbitration.
6. Operational Risks
The service-level commitment is limited to 99.9% API availability and excludes emergency maintenance, force majeure and customer-specific or integration-related issues. The exclusive remedy for a breach is termination, rather than service credits.
Between 2018-09-13 and 2020-04-10 · Privacy Policy
Structured Summary of Important Changes
1. Major structural expansion
The update appears to replace a short or consolidated terms page with a comprehensive legal library covering:
- Website Terms of Use
- SaaS Terms of Use
- Partner Terms
- Privacy Policy
- Data Processing Addendum references
- Service-level objectives
- Support terms
- Usage guidelines
- Security, zero-knowledge, trust-center and related resources
- Legacy terms and a change-summary section
This substantially increases the number of incorporated policies and external webpages that may govern the customer.
2. AI model and training restrictions
SaaS Terms
A new confidentiality provision restricts either party from making the other party’s Confidential Information available to artificial-intelligence tools, including generative AI and large language models, except where all of the following apply:
- The use is solely for the receiving party’s internal purposes;
- The AI environment is secure and access-controlled; and
- The use does not result in model training or unauthorized retention, disclosure or use.
Risk/impact: This is a meaningful contractual restriction on employees, contractors and service providers using confidential information with public or hosted AI tools. “Confidential Information” is broad and may include customer data, business information and information that reasonably should be understood as confidential. Violations could create breach, confidentiality and potentially injunctive-relief exposure.
Partner Terms
The Partner Terms contain a similar prohibition applicable to Partner Confidential Information. Partners must ensure that information is not submitted to AI tools in a way that causes model training or unauthorized retention, disclosure or use.
Risk/impact: The Partner is responsible for controlling downstream personnel and may need AI-use policies, approved-tool lists and technical controls.
3. Customer Data use and AI training
The SaaS Terms expressly state that:
- Customer Data includes data supplied by the customer or users, including vault records;
- Customer Data is Customer Confidential Information;
- Keeper may collect, use and analyze aggregated, anonymized usage, telemetry and operational data to operate, secure, support and improve the Services; and
- Such data must not include Customer Data or permit identification of the customer or users.
This is a relatively favorable limitation: the text does not authorize Keeper to use Customer Data or encrypted vault contents to train AI models. The separate AI restriction also prohibits use of Confidential Information that results in AI model training.
However, the wording permits use of “aggregated anonymized” usage and telemetry data for service improvement. Customers should confirm that the DPA, Privacy Policy and any product-specific terms do not authorize broader use of personal data, prompts, support communications or derived data for AI training.
4. Privacy-policy changes and data governance
The Privacy Policy now distinguishes Keeper’s roles as controller or processor and describes collection of:
- Account, billing, device, IP and usage information;
- Website, marketing, cookie and chat data;
- Partner and reseller information; and
- Support communications.
It also permits vendors and service providers to process limited information for support, analytics, account security and related business functions.
Risk/impact: The Privacy Policy is incorporated into the agreements and may be updated. Customers should review the DPA, vendor list, retention provisions, international-transfer mechanisms and whether support/chat data can be used for analytics or AI functionality.
5. Other significant commercial/legal risks
- Annual fees are generally nonrefundable and automatically recurring.
- Service availability is limited to a 99.9% monthly API target, with broad exclusions; the stated remedy is termination only.
- Liability is generally capped at fees paid in the preceding 12 months, with limited exceptions.
- Customers bear responsibility for access controls, backups, endpoint security and user activity.
- Keeper may update agreements and partner-portal terms, subject to stated limitations.
- U.S. customers may be subject to mandatory Delaware arbitration, excluding certain intellectual-property disputes.
- Free or evaluation versions receive reduced protections and may not have undergone equivalent security reviews.
Between 2015-04-06 and 2018-09-13 · Privacy Policy
Summary
Scope of the Diff
- The diff states only: “Added approximately 15,240 words to the document.”
- The actual added legal text is not included.
- No deletions or replacement language is shown.
Key Legal Changes
- Cannot be determined from the provided diff.
- Without the added text, it is not possible to identify changes concerning:
- Customer data ownership or licensing
- Permitted data uses
- Confidentiality and security obligations
- Data retention or deletion
- Subprocessors or third-party disclosures
- Liability, indemnification, or limitation of liability
- Audit rights or compliance obligations
- Termination effects
- Governing law or dispute resolution
AI Model Training and Data Use
- The provided diff does not state whether customer data may be used to:
- Train, fine-tune, or improve artificial intelligence or machine-learning models
- Create aggregated, de-identified, or derived datasets
- Retain prompts, inputs, outputs, or usage metadata for model development
- Share data with AI providers, subprocessors, or affiliates
- Opt customers in or out of model-training practices
- Accordingly, no conclusion can be reached about whether the changes create new AI-training rights or risks.
Important Limitation
The statement that approximately 15,240 words were added is not a substitute for the contract language. The additions could materially expand the provider’s rights or the customer’s obligations, but the nature and significance of those changes cannot be assessed without the text.
Information Needed
To perform a meaningful legal review, provide the actual added provisions, preferably with:
- The surrounding original text
- Section headings and numbering
- Any deletion or replacement markings
- Definitions of “Customer Data,” “Usage Data,” “Aggregated Data,” “Content,” “AI,” or similar terms