Privacy

Your secrets are not our data.

Keyglass has no account, hosted secrets backend, telemetry, or advertising SDK. Your secret values stay in Apple Keychain.

Effective August 16, 2026 · Controller: GREGOR STERNAT

Secrets stored
Apple Keychain
Secrets sent to Keyglass
Never
Accounts and analytics
None

Controller and contact

GREGOR STERNAT, located at 9 RUE DEGAS, 77330 OZOIR-LA-FERRIERE, FRANCE, controls the limited personal data described in this notice. Questions and data-rights requests can be sent to [email protected].

Keyglass is local-first software. The publisher does not operate an account system or a service that receives, hosts, indexes, or recovers your vault.

Data Keyglass never receives

Project names, environment names, secret keys, secret values, favorites, and vault search activity are not sent to the publisher, Polar, Cloudflare, or the update service. Keyglass has no analytics, telemetry, advertising SDK, or crash-reporting service.

Secret values are read from Keychain only for an explicit reveal, secure copy, authenticated export, keyglass get, or keyglass run operation.

Local and iCloud Keychain

A new installation stores records in the local Apple Keychain. If you explicitly enable iCloud Keychain sync, Apple may synchronize those records between Macs signed in to your Apple Account. Apple controls that processing under your Apple settings and Apple’s terms.

Disabling sync moves active records back to the local Keychain. To prevent an offline Mac from restoring a deleted synchronized record, Keyglass may retain minimal deletion tombstones after a prior opt-in. A tombstone contains only the record type and a random stable identifier in its Keyglass payload—never a project name, environment name, secret key, or secret value. A workspace that never enables sync publishes no tombstones to iCloud.

Licensing and purchases

Polar handles checkout, payment, invoices, refunds, and license-key services. Keyglass activation sends Polar the license key, the public Keyglass organization identifier, your chosen Mac label, and the condition major_version: 1. Validation and deactivation also send the activation identifier returned by Polar. Normal network requests disclose connection information such as an IP address to Polar.

Keyglass stores the local license key and activation record in Apple Keychain. Polar determines its checkout, order, tax, retention, and international-transfer practices under its privacy policy.

Updates and website hosting

Sparkle contacts the configured HTTPS appcast when Keyglass checks for a signed release. The appcast host receives normal request information such as IP address, timestamp, and requested resource. Keyglass does not attach vault content or secret data to an update request.

The static website is hosted on Cloudflare Pages. It sets no analytics or advertising cookies and does not store a theme preference or other site settings in your browser. Cloudflare may process standard connection and security logs under its privacy policy.

Support requests

If you contact support, the publisher processes your email address, message, attachments, product version, and sanitized diagnostic context to answer the request and protect the product. Providing this information is voluntary, but support may be unable to investigate without enough non-secret context.

Never send secret values, license keys, exported .env files, Keychain dumps, real customer data, or credentials. Replace sensitive project, environment, and key names with neutral examples.

Retention

The publisher cannot retain vault data it never receives. Local records remain in Apple Keychain until you delete them, remove the local license record, or complete the relevant migration. Synchronized Keychain data and minimal tombstones follow Apple’s storage behavior.

Support exchanges are kept while a request is active and afterwards only for as long as needed for security, follow-up, or legal claims. Purchase and accounting information is kept for applicable statutory periods. Polar, Cloudflare, Apple, and email providers apply their own documented retention periods to data they control.

Your choices and rights

You can delete Keychain records in Keyglass, disable iCloud sync, deactivate a license, remove the app, and choose not to send support information. Where data-protection law applies, you may request access, correction, deletion, restriction, portability, or objection by emailing [email protected].

You may also complain to your local data-protection authority. In France, the supervisory authority is the Commission nationale de l’informatique et des libertés (CNIL). The publisher may retain information where a legal obligation or the establishment, exercise, or defence of legal claims requires it.

Changes to this notice

Material changes will be dated on this page. Keyglass will not turn secret data into hosted, analytics, or advertising data without a new explicit product decision, corresponding technical changes, and an updated notice.