Data controller
Your personal data is processed by Tres Technology LLC as the data controller.
- Address: 8 The Green, Suite 13105, Dover, DE 19901, USA
- Email: info@keyzula.com
In short
KeyZula is an end-to-end encrypted (zero-knowledge) vault. The passwords, 2FA secrets, SSH keys, notes, item names and website addresses you store are encrypted on your device. We cannot see, read or share this content.
Your master password is never sent to or stored on our servers. That's why we can't reset it if you forget it.
We don't sell your data or use it for advertising.
Data we process
| Category | Details |
|---|---|
| Account data | Your name, email address; a verifier derived from your master password on your device and hashed again on the server (never the master password itself); your encrypted account keys. |
| Vault data | Stored only in encrypted form; we cannot read its content. The number of items and when they were created or updated are visible. |
| Organization data | Organization name; members' email addresses, roles and membership status; department names and collection permissions. Collection names are encrypted. |
| Session and security records | Name and type of the signed-in device, IP address, browser information, session start and last activity times; failed sign-in attempts; a hash of a random device identifier generated in your browser to recognize known devices; when your email was verified. If you enable two-step verification, your authenticator key is stored encrypted with a server key and your recovery code only as an irreversible hash. |
| Audit logs | In organizations: who acted on which item or collection, when and from which IP address (not the item contents). |
| Technical logs | Short-lived server logs with the IP address, time and requested address of requests. |
| Analytics (only with your consent) | Usage statistics on the marketing website (keyzula.com), such as pages visited and device and browser type. The web vault (app.keyzula.com) uses no analytics. |
Purposes and legal bases
- Providing the service (account creation, sign-in, syncing your vault across devices, sharing): Art. 6(1)(b) GDPR, performance of a contract.
- Security (session management, preventing abuse and unauthorized access, rate limiting, audit logs): Art. 6(1)(f) GDPR, legitimate interests.
- Legal obligations (requests from competent authorities, record-keeping duties): Art. 6(1)(c) GDPR.
- Improving the marketing website (analytics): Art. 6(1)(a) GDPR, your consent, which you can withdraw at any time.
Recipients
We only share personal data in the following cases:
- Email delivery: Verification, security notification and invitation emails are sent through our email service provider, together with your email address and the message content. We don't send marketing emails.
- Hosting: Our servers are located in Türkiye; the data controller is based in the United States. The hosting provider can access data only as needed to operate the infrastructure; vault contents are encrypted and cannot be read.
- Google Analytics (only with your consent): Usage statistics from the marketing website are transferred to Google, possibly to countries outside your own, including the United States. Advertising and personalization features are disabled.
- Password breach checks: When you start a breach check, only the first 5 characters of your password's SHA-1 hash are sent to Have I Been Pwned, never your password or personal data. This information does not identify you or your password.
- Authorities: Competent authorities where required by law. Because vault contents are encrypted, they cannot be disclosed in readable form in this case either.
Retention
- Account, vault and organization data: until your account or the organization is deleted.
- Sessions: up to 30 days after sign-in; other sessions end immediately when you sign out or change your master password.
- Audit logs: as long as the organization exists.
- Database backups: 14 days, then deleted automatically.
- Technical server logs: kept at a limited size; the oldest entries are deleted automatically.
- Analytics: for the retention period configured in Google Analytics.
Security
Your vault data is encrypted on your device with keys derived using Argon2id and with XChaCha20-Poly1305. Connections to the server use HTTPS only. The verifier sent to the server is hashed again before storage. Shares are encrypted to each recipient's own public key, and a revoked member's key copy is deleted.
Your rights
You have the right to access, rectify and erase your data, to restrict or object to processing, to data portability and to withdraw consent at any time without affecting the lawfulness of prior processing (Art. 15–21 GDPR). If you are in Türkiye, you also have the rights under Art. 11 of the Turkish Personal Data Protection Law (KVKK).
To exercise your rights, email info@keyzula.com. We respond within 30 days. You also have the right to lodge a complaint with a data protection supervisory authority.
Deleting your account
You can delete your account yourself at any time in the web vault under Settings → Delete account, confirming with your master password. Your account, personal vault, folders and sessions are deleted immediately. Organizations where you are the only member are deleted as well; if you are the sole owner of an organization with other members, you must transfer ownership first.
If you can't access your vault, you can also request deletion by emailing info@keyzula.com from the email address registered to your account. Deleted data is also removed from backups within 14 days. Your activity in organization audit logs is kept as long as the organization exists.
Children
KeyZula is not intended for anyone under 16. If we learn that we are processing data of someone under 16, we will delete it.
Changes
We may update this policy when needed and will announce significant changes on our website. The current version is always available on this page.