Skip to content
Keyglass
SecurityCLI

Privacy

Your secrets are not our data.

Effective August 3, 2026 · Controller: Grégor Sternat

The short version

Keyglass has no account, hosted secrets backend, analytics, or advertising SDK. Project names, environment names, keys, and secret values are stored in Apple Keychain on your Mac. They are never sent to the publisher, Polar, or the update service.

App data

A new installation uses the local Keychain. If you explicitly enable iCloud Keychain sync, Apple may synchronize the Keychain records between Macs signed in to your Apple Account. That processing is governed by your Apple settings and Apple’s terms. Search operates on record metadata; secret values are loaded only for an explicit reveal, secure copy, export, or CLI operation.

If you later disable sync, active records move back to the local Keychain. Because an offline Mac can redeliver an older synchronized record, Keyglass keeps minimal deletion tombstones synchronized without automatic expiry after a prior opt-in. A tombstone contains only the record type and a random stable identifier in its Keyglass payload — never a project or environment name, secret key, or secret value. Keyglass adds no deletion timestamp to that payload; Apple Keychain may retain system attributes such as item creation or modification dates under Apple’s terms. A workspace that has never enabled sync publishes no tombstones to iCloud.

Licensing and purchases

When you purchase, activate, validate, or deactivate a license, Polar processes the information needed to provide that service. Activation requests include the license key, a Mac label, product identifiers, the major app version, and the activation identifier. Keyglass keeps the local license record in Apple Keychain. The legal basis is performance of the license contract and prevention of license abuse. Polar determines its own checkout retention and international-transfer practices under its published privacy terms.

Updates, website, and support

Sparkle contacts the configured HTTPS appcast only when Keyglass checks for a signed release. The static website sets no analytics or advertising cookies; it stores only your light/dark preference in your browser. A hosting provider may process standard security logs such as IP address, timestamp, and requested path. If you contact support, the publisher processes your address, message, and attachments to answer the request and retain the exchange only as long as needed for support, security, and legal obligations. Never send secret values to support.

Your choices and rights

You can delete Keychain records in the app, disable iCloud sync, clear website storage in your browser, deactivate a license, and remove the app. Where data-protection law applies, you may request access, correction, deletion, restriction, portability, or objection, and may complain to your local data-protection authority. Contact[email protected]. The publisher may need to retain purchase records where tax or accounting law requires it.

Changes

Material changes will be dated on this page. Keyglass will not turn secret data into hosted or analytics data without a new, explicit product decision and corresponding notice.

Keyglass
PrivacyTermsSupport