Privacy Policy
Last updated: July 2026. Built on a strict Zero-Knowledge Architecture.
1. Zero-Knowledge Architecture
KeyPher is built from the ground up on a strict zero-knowledge architecture. This means your passwords, secure notes, and all sensitive vault data are encrypted locally on your device using military-grade AES-256-GCM encryption before they are ever transmitted to our cloud servers.
Because the encryption and decryption keys are derived directly from your Master Password (which is never sent to our servers), we physically do not have the ability to read, decrypt, or access your vault data. Your secrets are mathematically guaranteed to remain yours.
2. Data We Collect
We believe in data minimization. We only collect what is absolutely necessary to provide the service:
- Account Information: We collect your email address solely for account identification, authentication, and critical security notifications.
- Encrypted Vault Data: We store the encrypted, randomized blobs of your vault data to synchronize them across your devices. To us, this data looks like complete mathematical noise.
3. Data We Do NOT Collect
- We do not collect telemetry or usage tracking data within your vault.
- We do not collect unencrypted passwords, usernames, URLs, or secure notes.
- We do not sell your email, metadata, or any other information to third parties.
- We do not use third-party analytics trackers inside the vault environment.
4. Browser Extension & Permissions
The KeyPher Browser Extension for Chrome, Firefox, and Edge requires specific permissions to function securely and seamlessly:
activeTab / tabs: Used locally to detect the current website's URL so the extension can automatically suggest the correct login credentials.storage: Used to securely cache your encrypted vault data and session tokens locally on your machine, allowing for offline access and faster decryption.host permissions: Required to communicate securely via HTTPS with our cloud backend (cloud.keypher.com) for real-time synchronization.
These permissions are strictly scoped to the functionality of the password manager and are never used to track your browsing history or inject advertisements.
5. Cookies and Local Storage
We use essential cookies and local storage mechanisms exclusively for maintaining your secure session and caching encrypted data. We do not use tracking or advertising cookies.
6. GDPR and CCPA Compliance
If you are a resident of the European Economic Area (EEA) or California, you have the right to access, correct, or delete your personal data. You can exercise these rights at any time directly from the KeyPher settings menu by permanently purging your vault and deleting your account.
7. Contact Us
If you have questions about this Privacy Policy, our security practices, or your data rights, please contact our security team via our support channels.