Privacy Policy
1. Introduction
KCH Labs ("we", "us", "our") operates the SecureKeep mobile application ("the App") and the website at securekeep.app ("the Site"). This Privacy Policy explains what information we do and do not handle, and how.
SecureKeep's vault is built on a zero-knowledge architecture: the passwords, documents, notes, and messages you store in the App are encrypted on your device and never leave it. We cannot read them, and we never receive them. The limited information described in this policy relates only to optional support and feedback features, and to standard website analytics, never the contents of your vault.
For the purposes of the EU/UK General Data Protection Regulation (GDPR), the data controller is KCH Labs. You can reach us at support@securekeep.app.
2. Your Vault Data: What We Never Collect
The core of SecureKeep is designed so that we have no access to your personal vault contents. We do not:
- Require an account, login, or registration to use the App
- Collect, transmit, or store the passwords, documents, notes, photos, or video/audio messages you save in your vault
- Have access to your master password or encryption keys, which never leave your device
- Use advertising identifiers, tracking pixels, cross-app fingerprinting, or sell/share/trade your data for advertising
3. Vault Data Stored Locally on Your Device
All data you create in SecureKeep is stored exclusively on your device:
- Vault data (credentials, documents, notes, video and audio messages): encrypted with AES-256-GCM and stored in a local SQLite database
- Encryption keys:your master password is never stored; a derived key is generated via PBKDF2-SHA256 (600,000 iterations) and held in memory only while the App is unlocked
- Biometric data:if you enable biometric unlock, an encrypted key is stored in your device's secure hardware (iOS Keychain / Android Keystore). We never access or process your biometric data directly; authentication is handled entirely by your device's operating system
- Document and media files:documents, photos, video messages, and audio messages are encrypted and stored in the App's sandboxed file storage on your device
4. Information You Choose to Send Us (Support & Feedback)
SecureKeep includes optional in-app feedback and a website contact form. These are the only features that transmit information off your device, and they are used only when you actively choose to contact us. No vault data is ever included.
When you submit in-app feedback (a bug report, feature request, or testimonial) or use the website contact form, we receive and process:
- The message you write:the subject, body, and category you select
- Your email address:only if you choose to provide it, so we can reply. Leaving it blank submits your feedback anonymously
- A screenshot or attachment:only if you choose to attach one
- Basic technical context:the App version, platform (iOS/Android), and device model and OS version. This helps us reproduce bugs. It does not include advertising identifiers or precise location
Legal basis (GDPR). We process this information on the basis of your consent (which you give by submitting the form) and our legitimate interest in providing support and improving the App. You can withdraw consent and request deletion at any time by emailing support@securekeep.app.
Retention. Feedback and support messages are retained only as long as needed to resolve your request and improve the product, and are deleted on request. We do not use this information for advertising or profiling.
5. Testimonials
If you submit a testimonial through the feedback form, you are asking us to consider publishing it. We only publish a testimonial after review, and we publish only the testimonial text and the first name or initials you provide — never your email address or any device information. You can ask us to remove a published testimonial at any time by emailing support@securekeep.app.
6. Website Analytics
Our website (securekeep.app) uses Vercel Web Analytics to understand aggregate traffic — such as which pages are visited and roughly where visitors come from. This analytics is privacy-focused: it does not use cookies, does not track you across other websites, and does not build an advertising profile of you. It applies to the website only. The mobile App itself contains no analytics or tracking SDKs.
7. Third-Party Services (Sub-processors)
To operate the optional support features and the website, we rely on a small number of service providers who process data on our behalf. They receive only the information described above — never your vault data.
- Supabase:stores feedback and support submissions in a hosted database (United States).
- Brevo:delivers support emails, contact-form messages, and feedback auto-replies.
- Vercel:hosts our website and provides the privacy-focused analytics described above.
- Apple App Store / Google Play:process your app purchase (see Section 9).
Because some of these providers are based in the United States, information you send us may be processed there. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international transfers. If we add or change a service provider in a way that materially affects your privacy, we will update this policy.
8. Device Permissions
SecureKeep may request access to certain device features. These permissions are optional and only requested when you use a specific feature. All data captured through these permissions is encrypted and stored exclusively on your device. It is never uploaded, transmitted, or accessible to us (the only exception is a screenshot you deliberately attach to a feedback message, per Section 4).
- Camera:used to record video messages and capture document photos for your vault. Recordings and photos are encrypted with AES-256-GCM and stored only on your device.
- Microphone:used to record audio messages for your vault. Recordings are encrypted and stored only on your device.
- Photo Library:used to let you attach existing photos or documents from your library to your vault. Imported files are encrypted and stored only on your device.
- Face ID / Biometrics:used to let you unlock your vault without entering your master password. Biometric authentication is handled entirely by your device's operating system; we never access or process your biometric data.
- Motion Sensors:used to detect when your device is placed face-down, which triggers an automatic vault lock for added security. No motion data is stored or transmitted.
You can revoke any of these permissions at any time through your device's Settings. Revoking a permission will disable the corresponding feature but will not affect your existing vault data.
9. Backup Feature
SecureKeep includes an encrypted backup feature that allows you to export your vault data:
- Backups are encrypted with a separate passphrase you choose, using AES-256-GCM
- Backup files are created locally and shared using your device's share sheet
- We never receive, transmit, or store your backup files
- You are solely responsible for where you store your backup files
10. App Store Data
When you purchase SecureKeep through the Apple App Store or Google Play Store, the respective platform processes your payment. We do not receive or have access to your payment details. Please refer to Apple's or Google's privacy policy for information about how they handle purchase data.
11. Your Rights Under GDPR (European Users)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and the right to data portability. Because your vault data lives only on your device, you already have full, direct control over it:
- Access:all vault data is on your device and fully accessible to you; for any feedback you have sent us, email us for a copy
- Delete:delete the App or use the "Delete Vault" option in Settings for vault data; email us to delete any feedback or support messages you have sent
- Data portability:use the encrypted backup feature to export your vault data
- Rectification:edit any information directly within the App
You also have the right to lodge a complaint with your local data protection supervisory authority.
12. Your Rights Under CCPA (California Residents)
SecureKeep does not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not use it for cross-context behavioral advertising. Vault data remains on your device under your control. For any support or feedback data you have sent us, you may request access or deletion by emailing support@securekeep.app.
13. Children's Privacy
SecureKeep is not intended for use by children under the age of 13, and we do not knowingly collect any information from children. If you believe a child has sent us personal information through the feedback or contact form, please contact us and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected in the "Last updated" date at the top of this page and, for material changes, communicated through an app update. Continued use of the App or Site after changes constitutes acceptance of the updated policy.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise any of your rights, contact us at: