Skip to content

Legal

Privacy policy

We built KeyValt so that the most sensitive things you store — your portal credentials — are unreadable to us. This policy explains what we can see, what we can’t, and your rights.

Last updated: 4 October 2026

Summary

  • Your vault (portal names, website addresses, usernames, passwords, authenticator secrets, notes) is encrypted on your device. We cannot decrypt it.
  • We collect the minimum account, billing and security data needed to run the service.
  • We do not sell your data and we do not use advertising or tracking cookies.

What we collect

  • Account data: name, email address, profile preferences, authentication proof hashes, encrypted key material, two-step verification settings.
  • Encrypted vault data: ciphertext plus non-secret metadata (item type, which account belongs to which portal, timestamps, revision numbers, favourite and usage flags). If you add a portal from the public KeyValt directory, we also see which directory entry it came from (for example, “GST portal”) so we can deliver its login configuration; names and addresses of portals you add yourself stay encrypted.
  • Device and security data: device names, browser and OS, IP addresses, sign-in history, security events and audit logs.
  • Billing data: plan, subscription status, invoices and payment status from Razorpay. We never receive full card numbers.
  • Support data: messages you send to support. Please never include passwords in support messages.
  • Product analytics: first-party, aggregate usage events (for example “portal created”) without vault contents. You can opt out in Settings.

What we cannot see

We never receive your master password, recovery key, vault key or any decrypted vault item. KeyValt staff, including administrators, cannot view, export or restore the plaintext contents of your vault.

How we use data

  • To provide, sync and secure the service (including fraud prevention and abuse detection).
  • To send transactional emails: verification, security alerts, receipts and important account notices.
  • To process payments and comply with tax and accounting obligations.
  • To improve the product using aggregate analytics.

Processors

ProcessorPurpose
Cloud hosting & managed PostgreSQLApplication hosting and encrypted data storage
RazorpayPayment processing and subscriptions
Email delivery providerTransactional email
Google (optional)Sign in with Google, only if you choose it

Retention

  • Vault data is kept until you delete it. Trashed items are purged automatically after the retention period you choose (7, 30 or 90 days; 30 by default).
  • When you delete your account, your vault and personal data are deleted immediately. Limited billing records are retained as required by law, and security and audit logs are kept for up to 1 year with the link to your account removed.
  • Security and audit logs are deleted after 1 year; aggregate usage analytics after about 13 months.
  • Sessions and one-time tokens expire automatically.

Your rights

You can access and export your data from Settings → Your data, correct your profile, and delete your account at any time. You may also contact us to exercise any right available under applicable law, including grievance redressal.

Contact

Privacy questions and grievances: suppport@keyvalt.com