Controller and contact
GREGOR STERNAT, located at 9 RUE DEGAS, 77330 OZOIR-LA-FERRIERE, FRANCE, controls the limited personal data described in this notice. Questions and data-rights requests can be sent to [email protected].
Keyglass is local-first software. The publisher does not operate an account system or a service that receives, hosts, indexes, or recovers your vault.
Data Keyglass never receives
Project names, environment names, secret keys, secret values, favorites, and vault search activity are not sent to the publisher, Polar, Cloudflare, or the update service. Keyglass has no analytics, telemetry, advertising SDK, or crash-reporting service.
Secret values are read from Keychain only for an explicit reveal, secure copy, authenticated export, keyglass get, or keyglass run operation.
Local and iCloud Keychain
A new installation stores records in the local Apple Keychain. If you explicitly enable iCloud Keychain sync, Apple may synchronize those records between Macs signed in to your Apple Account. Apple controls that processing under your Apple settings and Apple’s terms.
Disabling sync moves active records back to the local Keychain. To prevent an offline Mac from restoring a deleted synchronized record, Keyglass may retain minimal deletion tombstones after a prior opt-in. A tombstone contains only the record type and a random stable identifier in its Keyglass payload—never a project name, environment name, secret key, or secret value. A workspace that never enables sync publishes no tombstones to iCloud.
Licensing and purchases
Polar handles checkout, payment, invoices, refunds, and license-key services. Keyglass activation sends Polar the license key, the public Keyglass organization identifier, your chosen Mac label, and the condition major_version: 1. Validation and deactivation also send the activation identifier returned by Polar. Normal network requests disclose connection information such as an IP address to Polar.
Keyglass stores the local license key and activation record in Apple Keychain. Polar determines its checkout, order, tax, retention, and international-transfer practices under its privacy policy.
Updates and website hosting
Sparkle contacts the configured HTTPS appcast when Keyglass checks for a signed release. The appcast host receives normal request information such as IP address, timestamp, and requested resource. Keyglass does not attach vault content or secret data to an update request.
The static website is hosted on Cloudflare Pages. It sets no analytics or advertising cookies and does not store a theme preference or other site settings in your browser. Cloudflare may process standard connection and security logs under its privacy policy.
Support requests
If you contact support, the publisher processes your email address, message, attachments, product version, and sanitized diagnostic context to answer the request and protect the product. Providing this information is voluntary, but support may be unable to investigate without enough non-secret context.
Never send secret values, license keys, exported .env files, Keychain dumps, real customer data, or credentials. Replace sensitive project, environment, and key names with neutral examples.
Purposes, legal bases, and recipients
License and purchase data is processed to perform the software license and sale contract. Accounting records are kept where required by law. Support and security correspondence is processed to perform support obligations and for the legitimate interests of diagnosing failures, preventing abuse, and protecting users.
Recipients are limited to the publisher and the providers needed for the relevant purpose: Polar for purchases and licensing, Cloudflare for static hosting and security, Apple for an iCloud Keychain opt-in, the update-feed host for release checks, and email providers for support. Some providers may process data outside the European Economic Area under the safeguards described in their own privacy terms.
Retention
The publisher cannot retain vault data it never receives. Local records remain in Apple Keychain until you delete them, remove the local license record, or complete the relevant migration. Synchronized Keychain data and minimal tombstones follow Apple’s storage behavior.
Support exchanges are kept while a request is active and afterwards only for as long as needed for security, follow-up, or legal claims. Purchase and accounting information is kept for applicable statutory periods. Polar, Cloudflare, Apple, and email providers apply their own documented retention periods to data they control.
Your choices and rights
You can delete Keychain records in Keyglass, disable iCloud sync, deactivate a license, remove the app, and choose not to send support information. Where data-protection law applies, you may request access, correction, deletion, restriction, portability, or objection by emailing [email protected].
You may also complain to your local data-protection authority. In France, the supervisory authority is the Commission nationale de l’informatique et des libertés (CNIL). The publisher may retain information where a legal obligation or the establishment, exercise, or defence of legal claims requires it.
Changes to this notice
Material changes will be dated on this page. Keyglass will not turn secret data into hosted, analytics, or advertising data without a new explicit product decision, corresponding technical changes, and an updated notice.