Privacy Policy
Last updated: July 21, 2026
Keyring ("we", "us") is a free tool that runs primarily in your browser. This policy explains what data is processed, what leaves your device, and what does not.
1. Data you generate or store
- Generated passwords are created locally in your browser. They are never transmitted to us.
- Vault entries (site name, username, password, notes) are saved to your browser's local storage. If you enable encryption, they are encrypted with AES-GCM using a key derived from your master passphrase via PBKDF2 (SHA-256, 250,000 iterations). We never see the master passphrase or the vault contents.
- Clearing your browser data will delete your vault. Use the Export feature to keep a backup.
2. Breach checker
The breach checker uses HaveIBeenPwned's Pwned Passwords API with k-anonymity. Your password is hashed locally with SHA-1, and only the first 5 characters of that hash are sent to the API. The full password and full hash never leave your device.
3. Server logs
Our hosting provider records standard request logs (IP address, user agent, requested URL, timestamp) for reliability and abuse prevention. These logs contain no information about the passwords you generate, check, or store.
4. Cookies and analytics
Keyring does not set tracking cookies. If we add analytics or advertising in the future, this policy will be updated and, where required, a consent banner will be shown before those services load.
5. Third-party services
- HaveIBeenPwned Pwned Passwords — used only when you click "Check" on the Breach check tab.
6. Children
Keyring is not directed at children under 13 and we do not knowingly collect data from them.
7. Changes
We may update this policy. Material changes will be reflected in the "Last updated" date above.
8. Contact
Questions? See the contact page.