Privacy policy
Secret values stay on your device
The Latchkey CLI stores API key values as encrypted ciphertext in your local vault file (for example ~/.latchkey/vault.enc.json). We do not receive those values in plaintext when you use the vault locally. Unlocking, listing names, and injecting secrets into child processes happen on your machine.
If you paste a secret into a web form on this site by mistake, treat it as exposed and rotate the key with your provider. Do not send real API keys in support email.
Metadata we may store
When you create an account, subscribe, or use hosted features, we may process:
- Account and billing identifiers — email address, Stripe customer and subscription IDs, plan tier, and payment status in GBP.
- Entitlements — which licence or add-ons (for example leak scan) are active for your email or device, without vault contents.
- Support and transactional email — messages you send us and messages we send about your order or account.
- Local audit metadata — the CLI can record secret names, actions, and timestamps in a local audit log. That log does not include secret values. We do not upload your local audit log unless you explicitly share it with us.
- Standard web logs — IP address, user agent, and request paths for pages and API routes on this site, retained for security and debugging for a limited period.
Processors
We use third-party services to run the site and billing:
- Stripe — payment processing and subscription lifecycle.
- Supabase — storage for entitlement and subscription records tied to your account.
- Brevo — transactional email (for example checkout receipts, licence delivery, or support replies you opt into).
Each processor operates under its own privacy terms. We configure them to handle only what is needed to deliver the service you purchased.
What we do not do by default
- Upload your vault file or decrypted secrets to our servers.
- Sell personal data to data brokers.
- Use your local CLI activity for advertising profiles.
Retention and your rights
Billing records are kept as long as required for tax and fraud prevention. You may request access, correction, or deletion of personal data we hold by emailing Yusuf@yusuf-choudhury.com. Some records (for example invoices) may need to be retained after account closure where UK law requires it.
Changes
We will update this page when our practices change. Material changes will be reflected here with a revised effective date in the changelog when appropriate.
Contact
Data protection enquiries: Yusuf@yusuf-choudhury.com (Yusuf Choudhury, UK).