Keyhold

Privacy policy

Effective 25 September 2026.

In short

Keyhold keeps your data on your own devices and, if you turn on sync, in your own Google Drive. The author of Keyhold never receives, sees or stores any of it. There is no Keyhold server, no account, no analytics and no advertising. How the data is protected is described in How Keyhold protects your data.

What Keyhold stores

Site icons

To show a site’s icon, Keyhold asks that site (or the device on your home network) for it directly, the way a browser does when you open the site. No cookies and no data from your vault are sent with the request. Keyhold never uses a third-party icon service, which would learn every site you have an account on.

The browser extension

The Android app

Google Drive sync (optional)

If you connect Google Drive — in the app, on the phone or in the extension — Keyhold asks for one permission: drive.file. It lets Keyhold see and change only the files Keyhold itself created — a folder named “Keyhold” with your vault file. Keyhold cannot see any other file in your Drive.

Keyhold’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Removing your data

Changes and contact

Changes to this policy are published on this page. Questions: github.com/Galusz/keyhold/issues.