Keyfort Keyfort
Home Terms of Use

Privacy Policy

Effective Date: March 19, 2026  |  Last Updated: March 19, 2026

This Privacy Policy ("Policy") describes how Keyfort ("we," "us," "our," or "the App") collects, uses, stores, and protects information when you use the Keyfort iOS application. By downloading, installing, accessing, or using Keyfort, you acknowledge that you have read, understood, and agree to the practices described in this Policy.

If you do not agree to this Policy, please do not use the App.

1. Overview & Zero-Knowledge Architecture

Keyfort is designed with a zero-knowledge architecture. This means:

  • All sensitive data (2FA secrets, passwords, vault entries, backup files) is encrypted on your device before it leaves the device for any purpose.
  • We do not operate servers that receive, process, or store your data.
  • We cannot access, read, decrypt, recover, or reconstruct your data under any circumstances, including in response to legal process.
  • If you lose access to your device and your iCloud account, your data cannot be recovered by us or any third party.

2. Information We Collect

2.1 Information You Provide Within the App

When you use Keyfort, you may store the following types of data locally on your device:

  • 2FA Account Data: Secret keys, issuer names, account labels, custom icons, and configuration parameters (algorithm, digit count, period) used for generating one-time passwords.
  • Password Vault Entries: Logins, passwords, URLs, notes, and associated metadata stored in the encrypted vault.
  • App Preferences: Theme settings, security configuration (PIN, biometric preferences), notification preferences, backup schedules, and other user-configurable settings.
  • Achievement Data: Usage streaks, milestones, and gamification progress tracked locally.

All of the above data is stored exclusively on your device and, if you enable iCloud Sync, within your private, encrypted iCloud container. We have no access to this data.

2.2 Information We Do NOT Collect

We want to be explicit about what we do not collect:

  • We do not collect your name, email address, phone number, or any other personal identifiers.
  • We do not collect device identifiers (IDFA, IDFV), IP addresses, or geolocation data.
  • We do not collect usage analytics, behavioral data, session logs, or telemetry.
  • We do not use cookies, web beacons, pixel tags, or similar tracking technologies.
  • We do not collect crash reports or diagnostic data through our own systems.
  • We do not create user accounts on any external server.
  • We do not build user profiles or fingerprint your device in any way.

2.3 Apple-Collected Data

Apple may independently collect certain data in connection with its platform services (App Store, iCloud, TestFlight, etc.) in accordance with Apple's own Privacy Policy. This data collection is outside of our control and is governed by Apple's Privacy Policy. This may include:

  • App Store purchase and subscription transaction data.
  • Basic app diagnostics if you have opted in to share analytics with app developers in your iOS settings.
  • iCloud storage usage metadata (not content).

3. How Your Data Is Stored & Secured

3.1 Local Device Storage

  • 2FA Secrets & App Data: Stored locally using SwiftData with on-device encryption provided by the iOS data protection framework. Data is encrypted at rest when the device is locked.
  • Passwords & Sensitive Credentials: Stored in the iOS Keychain, which provides hardware-backed encryption using the Secure Enclave on supported devices. Keychain items are protected with the kSecAttrAccessibleWhenUnlockedThisDeviceOnly access level or equivalent.
  • Biometric Data: Keyfort does not store or process biometric data (Face ID / Touch ID). Biometric authentication is handled entirely by iOS LocalAuthentication framework. We only receive a success/failure result.

3.2 iCloud Sync (Optional)

If you choose to enable iCloud Sync:

  • Data is encrypted on your device before being uploaded to your private iCloud container via Apple CloudKit.
  • Only devices signed in with the same Apple ID can access the synced data.
  • Apple provides infrastructure-level encryption for CloudKit data in transit and at rest.
  • We do not have access to your iCloud container or any data stored within it.
  • You can disable iCloud Sync at any time in the App settings, which will stop syncing and allow you to remove data from your iCloud container.

3.3 Encrypted Backups (Optional)

If you choose to create iCloud backups:

  • Backup files are encrypted on your device before being uploaded to your private iCloud container.
  • You control backup frequency, scope (codes, vault, settings), and retention.
  • Backup files can be deleted from within the App.

3.4 Exported Files

When you export data from Keyfort:

  • The exported file is encrypted with a password you choose at the time of export.
  • The file is generated and stored locally on your device.
  • You are solely responsible for the security and distribution of exported files once they leave the App.
  • We strongly recommend using strong, unique passwords for exported files and storing them securely.

4. How Your Data Is Used

Your data is used exclusively to provide the App's core functionality:

  • Generating time-based (TOTP) and counter-based (HOTP) one-time passwords.
  • Storing and retrieving credentials from the encrypted vault.
  • Syncing encrypted data between your Apple devices via iCloud (if enabled).
  • Creating and restoring encrypted backups (if enabled).
  • Displaying 2FA codes in Home Screen widgets (if configured).
  • Tracking achievement progress and usage streaks locally.

We do not use your data for advertising, marketing, profiling, data mining, machine learning training, or any purpose other than providing the App's functionality to you.

5. Third-Party Services

5.1 Have I Been Pwned (HIBP)

Keyfort offers an optional password breach detection feature powered by the Have I Been Pwned API. When you use this feature:

  • Only the first 5 characters of a SHA-1 hash of your password are sent to the HIBP API (k-anonymity model).
  • Your actual password is never transmitted, logged, or exposed.
  • The response is processed entirely on your device.
  • This feature is opt-in; it is only triggered when you explicitly initiate a breach check.
  • HIBP's use of data is governed by their own Privacy Policy.

5.2 Apple Services

Keyfort integrates with the following Apple services, each governed by Apple's terms and privacy policies:

  • Apple CloudKit: Used for iCloud Sync and iCloud Backup features.
  • Apple StoreKit 2: Used for processing in-app purchases and subscriptions.
  • Apple LocalAuthentication: Used for Face ID and Touch ID integration.
  • Apple WidgetKit: Used for Home Screen widget functionality.

5.3 No Third-Party Analytics, Advertising, or Tracking

Keyfort does not integrate, embed, or use:

  • Third-party analytics SDKs (e.g., Google Analytics, Firebase Analytics, Mixpanel, Amplitude).
  • Advertising SDKs or ad networks.
  • Crash reporting services (e.g., Crashlytics, Sentry, Bugsnag).
  • Attribution or marketing SDKs.
  • Social media SDKs or login integrations.
  • Any form of user tracking, fingerprinting, or behavioral profiling.

6. Data Sharing & Disclosure

We do not sell, rent, lease, trade, license, or otherwise disclose your personal data to any third parties for any reason. Specifically:

  • We do not share data with advertisers or data brokers.
  • We do not share data with analytics providers.
  • We do not share data with affiliated or unaffiliated third parties for their own marketing purposes.
  • We do not participate in data cooperatives or data exchanges.

Because we do not collect or possess your data, we are technically unable to share it. In the unlikely event we receive a legal request (subpoena, court order, government inquiry) for user data, we would have no data to produce.

7. Data Retention & Deletion

Since all data is stored on your device and optionally in your private iCloud container, you have full control over data retention and deletion:

  • Individual Entries: Delete specific 2FA accounts or vault entries at any time within the App.
  • All Data: Use Settings > Data > Delete All Data to permanently erase all App data from your device.
  • iCloud Data: Disable iCloud Sync to stop syncing and remove data from your iCloud container.
  • iCloud Backups: Delete individual backup files from within the App's backup management screen.
  • Uninstalling: Removing the App deletes all locally stored data (Keychain items may persist until explicitly deleted or the device is reset).
  • Complete Removal: To ensure all data is removed, delete all data within the App before uninstalling, and disable iCloud Sync.

We do not retain any data on our systems because we do not have systems that receive your data.

8. Data Security

We take security seriously and have implemented the following measures:

  • Encryption at Rest: All sensitive data is encrypted using AES-256 encryption via iOS data protection and Keychain.
  • Encryption in Transit: All iCloud communications use TLS encryption provided by Apple's CloudKit framework.
  • App Lock: The App can be locked with Face ID, Touch ID, or a custom PIN code.
  • Screen Recording Protection: Sensitive content is automatically hidden when screen recording or screen mirroring is detected.
  • Auto-Lock: The App automatically locks when switched to the background.
  • No Remote Access: There are no remote administration capabilities, backdoors, or server-side access to your data.

However, no method of electronic storage or transmission is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. See our Terms of Use for important limitations on liability.

9. International Data Transfers

Because we do not collect or process your data on our servers, there are no international data transfers initiated by us. If you enable iCloud Sync, Apple may store your encrypted data in data centers in various countries. Such transfers are governed by Apple's privacy practices and applicable data protection agreements.

10. Your Rights Under Applicable Law

10.1 General Rights

Depending on your jurisdiction, you may have certain rights regarding your personal data, including:

  • Right to Access: You can access all your data directly within the App at any time.
  • Right to Rectification: You can edit any entry within the App.
  • Right to Erasure: You can delete any or all data within the App.
  • Right to Data Portability: You can export your data in encrypted format.
  • Right to Restrict Processing: Since data is processed only on your device, you control all processing.
  • Right to Object: You can stop using the App at any time.

Because Keyfort operates with a zero-knowledge architecture and we hold none of your data, most data rights can be exercised directly within the App without needing to contact us.

10.2 European Economic Area (EEA) / UK — GDPR

If you are located in the EEA or UK, the General Data Protection Regulation (GDPR) applies to you. Given our zero-knowledge architecture:

  • We do not act as a data controller or data processor for the personal data you store in Keyfort, as we never access or process this data.
  • You are the sole controller of your own data.
  • The legal basis for any processing that occurs on your device is your explicit consent (by choosing to use the App) and the performance of the contract (these Terms and the App functionality).

10.3 California — CCPA / CPRA

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with specific rights. Because we do not collect, sell, or share personal information:

  • We do not sell your personal information.
  • We do not share your personal information for cross-context behavioral advertising.
  • We do not use or disclose sensitive personal information for purposes beyond providing the App's functionality.
  • We have no personal information to disclose, delete, or correct upon request because we do not hold any.

10.4 Brazil — LGPD

If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD) applies. Consistent with the above, we do not process personal data on our servers and you retain full control over your data within the App.

10.5 Other Jurisdictions

We are committed to complying with applicable data protection laws in all jurisdictions. If your local law grants you additional rights not listed here, please contact us and we will do our best to accommodate your request, though in most cases the zero-knowledge architecture means you can exercise all rights directly within the App.

11. Children's Privacy

Keyfort is not directed at, marketed to, or intended for use by children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. Because we do not collect personal information from any user, there is no mechanism by which a child's data could be inadvertently collected by us.

If you are a parent or guardian and believe your child has stored sensitive data in the App that you would like removed, you can delete the data directly from the device or uninstall the App.

12. Do Not Track

Keyfort does not track users and therefore does not respond to Do Not Track (DNT) browser signals. We do not engage in any form of tracking regardless of DNT settings.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or App functionality. When we make material changes:

  • The updated Policy will be posted at this URL with a new "Last Updated" date.
  • Material changes may be communicated through the App or App Store release notes.
  • Your continued use of the App after the effective date of a revised Policy constitutes your acceptance of the changes.

We encourage you to review this Policy periodically. If you disagree with any changes, you should discontinue use of the App.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, your data, or our privacy practices, please contact us at:

Email: [email protected]

We will make every effort to respond to your inquiry within 30 days.

© 2026 Keyfort. All rights reserved. | Privacy Policy | Terms of Use