KeySprig
PrivacyTermsCookies

KEYSPRIG

Privacy Policy

Last updated 10 October 2026.

Who is responsible

The data controller is KeySprig. Contact: privacy@keysprig.xyz.

TODO: replace this placeholder with the legal entity name and registered address once they are confirmed. Do not treat the product name alone as a complete legal identity.

What we store

KeySprig stores only what the service needs to run your vault:

  • Account email, and a password hash if you create an email-and-password account. These are held by Supabase Auth.
  • If you choose Google sign-in, Google’s account profile for that login (typically email and basic profile) is processed through Supabase Auth. Google is not used unless you pick that sign-in method.
  • Encrypted API key values (ciphertext, nonce and key version). The hosted service can decrypt them to make approved requests. This is not a zero-knowledge vault.
  • Key names and the policy you set: allowed hosts, authentication header and prefix, allowed HTTP methods, and the per-minute request limit.
  • Connected AI agents (OAuth client id and label) and the key grants you approve, including expiry and revocation.
  • Audit events such as key created or deleted, client approved or disconnected, and API-call metadata (key name, destination host, method and outcome). Audit events do not store secret values, request bodies or provider response bodies.
  • Short-lived per-agent, per-key rate-limit counters used to enforce the limit you configured.

Who processes it

These processors handle data on our behalf:

  • Supabase — accounts, authentication, OAuth grants and the vault database.
  • Cloudflare — hosts the KeySprig Worker and static website.
  • AgentMail — sends transactional email such as confirmation and password-reset messages.
  • Google — only if you sign in with Google, for that identity login. It does not receive your stored API keys.

Why we process it

Contract: we process your account, keys, policies, agents and grants to provide the vault you asked for.

Legitimate interests: we keep security and audit logs so we can detect abuse, debug failures and show you activity in the dashboard. Those logs do not include secret values.

How long we keep it

We keep this data while your account exists. When you delete your account, KeySprig revokes connected agents and deletes your keys, permissions, agents, audit events and the authentication user. Backups held by our processors may persist for a short time until they rotate.

International transfers

Our processors may handle data outside the European Economic Area. Where they do, they rely on their own standard contractual clauses or an equivalent transfer tool. Ask privacy@keysprig.xyz if you want the current processor list and transfer terms.

Your rights

If UK or EU data-protection law applies to you, you can ask to access, correct, delete, restrict or export your data, or object to processing that relies on legitimate interests. You can also complain to a supervisory authority, such as the Hellenic Data Protection Authority (dpa.gr).

The practical way to delete everything KeySprig holds is the Delete account control in Settings after you sign in. You can also email privacy@keysprig.xyz.

PrivacyTermsCookies
Created by the aislop.gr team and GPT.