Privacy Policy
Last updated July 12, 2026
This Privacy Policy explains how KeyCustody, Inc. ("KeyCustody," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit keycustody.io, use our product at app.keycustody.io, request a demo, or otherwise interact with us (together, the "Services").
KeyCustody is a business-to-business system of record for physical keys, codes, and combinations. It is not a consumer product, and the Services are intended for organizations and their authorized personnel.
1. Our role: controller and processor
Our responsibilities depend on the data involved:
- As a controller. For information we collect about visitors, prospects, and the individuals who administer an account — such as website analytics, demo requests, billing contacts, and account credentials — we determine how and why the data is used, and this Policy governs.
- As a processor (service provider). For the content our customers put into the product — records about keys, codes, combinations, people, locations, and custody events ("Customer Content") — we process personal information on behalf and under the instructions of the customer organization (the controller). Our handling of Customer Content is governed by our customer agreement and Data Processing Addendum ("DPA"), not this Policy. If you are an employee, contractor, or member of an organization that uses KeyCustody, please direct privacy requests to that organization.
2. Information we collect
- Information you provide. Name, work email, phone, organization, industry, role, and message content when you request a demo, contact us, or correspond with support; account registration and profile details; and billing and payment details you provide to complete a subscription.
- Customer Content. Information your organization enters into the product. By design, KeyCustody stores metadata about secrets by default (for example, what a code controls, who is authorized, and when it last rotated) rather than the secret values themselves; encrypted storage of secret values is a separate feature an administrator must explicitly enable.
- Usage and device data. Log data, IP address, browser and device type, pages viewed, referring pages, approximate location derived from IP, and similar diagnostics collected automatically when you use the Services.
- Cookies and similar technologies. See "Cookies and tracking" below.
3. How we use information
- Provide, operate, secure, and maintain the Services;
- Respond to demo requests, inquiries, and support tickets;
- Process transactions, manage subscriptions, and send related billing and administrative communications;
- Monitor, troubleshoot, and improve performance, reliability, and security, and to prevent fraud and abuse;
- Send product updates and, where permitted, relevant marketing (you can opt out at any time);
- Comply with legal obligations and enforce our agreements.
4. Legal bases (EEA/UK)
Where the EU or UK GDPR applies, we rely on: performance of a contract (to provide the Services you request); legitimate interests (to secure, improve, and market our Services in a proportionate way); consent (for certain cookies and marketing, which you may withdraw); and legal obligation (to meet regulatory requirements). Where we process Customer Content as a processor, our customer is responsible for establishing the legal basis.
5. How we share information
We do not sell personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under applicable U.S. state laws. We disclose information only as follows:
- Service providers (subprocessors). Vendors who process data on our behalf to run the Services — for example authentication, payment processing, cloud hosting and content delivery, database hosting, email delivery, error monitoring, and product analytics. Our providers today include Clerk (authentication), Stripe (payment processing), Vercel (hosting and content delivery), Resend (transactional email), and Sentry (error monitoring), along with cloud infrastructure and database hosting providers. A current subprocessor list is available on request at privacy@keycustody.io.
- Professional advisors and corporate transactions. Auditors and counsel, and a successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards.
- Legal and safety. When required by law, subpoena, or legal process, or to protect the rights, property, or safety of KeyCustody, our customers, or the public.
6. Cookies and tracking
This marketing website (keycustody.io) sets no cookies and runs no analytics, advertising, or session-recording trackers. Fonts are self-hosted, and no third-party scripts load. Because we place nothing non-essential on your device here, there is no cookie banner to accept or reject — there is simply nothing to consent to. If that ever changes, we will load non-essential technologies only after you opt in, and add granular controls.
The signed-in product at app.keycustody.io uses strictly necessary cookies to keep you logged in and secure your session; it does not use advertising cookies. We honor Global Privacy Control (GPC) signals as an opt-out for supported categories, and you can record your preferences at any time through Your Privacy Choices.
7. Data retention
We keep personal information only as long as needed for the purposes described here, to comply with legal, tax, and accounting obligations, and to resolve disputes and enforce agreements. Customer Content is retained per the customer agreement; on termination, it is deleted or returned within 30 days, except where retention is legally required. Audit-relevant records within the product are append-only and are not silently altered.
8. Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, tenant isolation between customer organizations, role-based access controls, append-only event logging, and least-privilege internal access. Support access to a customer's data is customer-granted, scoped, time-limited, and audited. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. International data transfers
We may process and store information in the United States and other countries. Where we transfer personal information across borders, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or another lawful transfer mechanism.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of your personal information; to object to or restrict certain processing; and to withdraw consent. Where applicable U.S. state laws provide rights to access, delete, correct, and opt out of sale/sharing or targeted advertising, we honor those rights (note: we do not sell or share personal information or serve targeted advertising).
To exercise a right, contact us at privacy@keycustody.io. We will verify your request and respond within the time required by law. You will not be discriminated against for exercising your rights. If you are covered by an organization's account, we may refer your request to that organization as the controller. If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority; where legally required, we will designate a representative and update this Policy accordingly.
11. Children's privacy
The Services are intended for organizations and are not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new "last updated" date and, for material changes, provide additional notice as required by law.
13. Contact us
Questions or requests regarding this Policy can be sent to privacy@keycustody.io. Our postal address is available on request.