Privacy policy
Effective 25 September 2026.
In short
Keyhold keeps your data on your own devices and, if you turn on sync, in your own Google Drive. The author of Keyhold never receives, sees or stores any of it. There is no Keyhold server, no account, no analytics and no advertising. How the data is protected is described in How Keyhold protects your data.
What Keyhold stores
- Your vault — logins, two-factor keys, notes and files you add or watch. It is one file on your device, encrypted with AES-256-GCM.
- Backups — copies of the same encrypted file in folders you choose, and optionally on a server of your own.
- Settings — the folders to back up and to watch, the time and any errors of the last backup, whether Keyhold opens with a fingerprint or Windows Hello, the sites where the browser extension should not save logins, and the pairing token of the browser extension, kept on your device.
- Site icons — the small icons of the sites and devices in your vault, kept next to the vault so they do not have to be fetched again.
Site icons
To show a site’s icon, Keyhold asks that site (or the device on your home network) for it directly, the way a browser does when you open the site. No cookies and no data from your vault are sent with the request. Keyhold never uses a third-party icon service, which would learn every site you have an account on.
The browser extension
- The extension reads login forms on the page you are on, to fill them and to offer saving a new login.
- With the Keyhold app on the same computer, it sends this only to that app (address
127.0.0.1) and to nothing else. A login you type in is held in the app’s memory for two minutes until you confirm it; nothing is saved before that. - On a computer without the app, the extension can open your vault from your Google Drive itself (see below). The vault key then stays in the browser’s memory until you lock it, close the browser or leave it for 30 minutes; the encrypted vault file and the site icons are kept in the browser’s storage for the extension only.
- On a two-step login it keeps the username from the first page in the browser’s memory for up to 10 minutes, so it can be saved together with the password on the same site; it is gone when the tab is closed.
The Android app
- The vault on the phone is sealed with a key held in the Android Keystore.
- If you choose Keyhold as the phone’s password filler, Android shows Keyhold the login fields of the app or web page you tap, so it can offer your logins and codes. A new login is saved only when you agree to Android’s “Save to Keyhold?” question.
- The camera is used only while you scan a two-factor QR code; the picture never leaves the phone.
- Your fingerprint and the phone’s PIN are checked by Android, and Windows Hello by Windows; Keyhold only learns whether it was you.
Google Drive sync (optional)
If you connect Google Drive — in the app, on the phone or in the extension — Keyhold asks for one permission: drive.file. It lets Keyhold see and change only the files Keyhold itself created — a folder named “Keyhold” with your vault file. Keyhold cannot see any other file in your Drive.
- Keyhold uploads the vault file already encrypted on your device, so Google stores data it cannot read.
- The Google access token stays on your device or in your browser. The author has no access to your Google account or your Drive.
- Data received from Google is used only to keep your own vault in sync between your devices. It is not shared with anyone, not sold, not used for advertising and not used to train any AI model.
Keyhold’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Removing your data
- Disconnect Google Drive in Keyhold, or remove Keyhold’s access at myaccount.google.com/permissions.
- Delete the “Keyhold” folder from your Drive.
- Uninstall Keyhold and delete its folder in
%APPDATA%and your backup folders. On Android, uninstalling the app removes everything it kept. Removing the browser extension removes what it kept in the browser.
Changes and contact
Changes to this policy are published on this page. Questions: github.com/Galusz/keyhold/issues.