Takes effect when Vallkey opens. The version in force is published here with its date.
Vallkey is built so that we can’t read your vault. This page explains what we do see, why, how long we keep it, and what you can do about it.
What we can’t see
Your vault is encrypted on your devices with keys that never reach us. That covers your passwords, passkeys, notes, cards, files, and also each item’s title, website addresses and tags. Your master password and Secret Key never reach us either: logging in proves you know your password without sending it.
What we collect
- Your account: your email address, to sign in, recover your account and tell you about requests such as a legacy contact asking for a vault.
- Your encrypted vault, padded so its size reveals little, and when it changed.
- Your devices: an encrypted name you give each one, and when each last synced, so you can see and remove them.
- Billing, once you pay: what our payment provider, Stripe, tells us to keep your subscription: your plan, its price, when it renews and whether it’s cancelled. Your card, name and address stay with Stripe.
- Email aliases, if you make them: each alias and the address it forwards to, whether it’s on, and how many emails it forwarded and refused. What an alias is for is encrypted with your keys. Our relay reads each email as it passes, as any mail server does, and keeps none of them.
- In an organization: who its members are, their roles, which vaults each has, and its policies. Its audit log records sign-ins with the IP address they came from, changes its admins make, and items opened or filled in its vaults, by ID. If the organization connects an identity provider, the names and group names it sends.
- Short-lived technical logs, such as IP addresses for rate limiting and security, kept for 30 days.
What we don’t do
- No advertising, no tracking pixels, no selling or sharing data for marketing.
- No third-party analytics or trackers in the apps.
- On this website, analytics are self-hosted and set no cookies.
Breach checks
When you check for breached passwords, your device sends Have I Been Pwned the first five characters of each password’s SHA-1 hash, never a password or a whole hash. The service sees your IP address.
Where data is kept
On our servers with our hosting providers, listed under subprocessors, or on your own server if you host Vallkey yourself.
How long we keep it
As long as your account exists. When you delete your account, your encrypted vault and account details are deleted from our servers within 30 days, and from backups within 90.
Your rights
You can see, export, correct and delete your data from the apps. You can also write to privacy@vallkey.com to ask what we hold about you, and to object to or restrict how it’s used. Where the GDPR applies, you can complain to your data protection authority.
Changes
We’ll say what changed, and when, at the top of this page and by email for changes that matter.
Last updated October 4, 2026