Privacy policy
Last updated: August 2026 · Written to be read, not skimmed past.
The short version
KeyNesta processes your two-factor authentication secrets on your device only. If you enable sync, our servers store encrypted data we cannot read. We show no ads, run no third-party trackers, and never sell or share usage data. Ever.
What we can never see
- Your 2FA secrets and the codes they generate
- The names of the services and accounts in your vault
- Your notes, tags, folder structure, and vault contents in general
- Your vault passphrase and encryption keys
These are encrypted on your device before any optional upload. This is architectural, not a promise of good behavior — see the security architecture.
What we store if you create a sync account
- Your email address — to identify your account, and nothing else.
- A hash of your account password (bcrypt) — never the password itself. This password authenticates sync; it cannot decrypt your vault.
- Encrypted vault objects — opaque ciphertext with version numbers and timestamps needed for syncing.
- Device records — the name and platform you give each device, so you can review and revoke access.
Without a sync account, KeyNesta sends nothing anywhere. The app is fully functional offline and account-free.
What we don’t do
- No advertising or advertising SDKs.
- No selling, renting, or sharing of any data with third parties.
- No behavioral analytics harvested from your vault or usage.
- No logs of secrets or generated codes.
Your rights and controls
- Export your data at any time — encrypted backups and standard formats, self-service.
- Delete individual devices, your synced data, or your entire account, self-service.
- Local vaults on your devices are yours; removing one from a device never touches another device’s copy.
Contact
Privacy questions: privacy@keynesta.com. Security reports: security@keynesta.com.