Privacy Policy
KeyDBX does not collect your data. The developer cannot see your database, your passwords, or how you use the app.
Data the developer collects
- The app does not collect personal data or usage data, and it sends no data to the developer.
- The app contains no analytics, advertising, tracking, or third-party SDKs.
- The developer runs no servers. The app itself connects to the network only when you use Dropbox, and it connects only to Dropbox. For cloud locations in the Files app, iOS and that cloud service handle uploads and downloads.
- If you choose in iOS Settings to share analytics with app developers, Apple provides information such as crash reports to the developer under the Apple Privacy Policy. iOS handles this, not the app.
Your database
- Your database exists only on your device and in the storage location you choose: a location in the Files app (such as iCloud Drive) or Dropbox.
- Decryption happens only on your device.
- The app keeps an encrypted copy of the database on your device so that AutoFill can use it when the original file is temporarily unavailable. When you use Dropbox, the app keeps a local copy of the Dropbox file on your device. Neither copy is included in device backups.
- When AutoFill cannot write to the database right away, newly saved passwords and passkeys are held on your device, protected by iOS file protection and excluded from device backups. They are written to the database the next time you unlock it in the app.
- When you export with Credential Exchange, iOS passes the items you select to the other password manager you choose.
Dropbox
This section applies only if you sign in to Dropbox in KeyDBX.
- The app connects directly to the Dropbox API and can access only the KeyDBX app folder in your Dropbox. It cannot see your other files.
- Sign-in uses the iOS system web sign-in sheet, which shares your Dropbox sign-in state with Safari. The app cannot read what you enter on the sign-in page.
- The sign-in token is stored in the Keychain on this device and does not sync to other devices. When you sign out, the app revokes the token and deletes it from the Keychain.
- The app requests your account information from Dropbox and uses only the display name and account ID. The display name appears in Settings. The account ID is stored on your device to confirm which Dropbox account a database belongs to.
- Dropbox handles your files and account under the Dropbox Privacy Policy.
Face ID
- When you turn on Face ID unlock, your master password is stored in the Keychain on this device, protected by Face ID, and does not sync to other devices.
- iOS performs the Face ID check. The app receives only success or failure and cannot access biometric data.
- When the Face ID data on your device changes (for example, you reset Face ID or add an appearance), the stored master password becomes invalid and you enter the master password again.
AutoFill
- AutoFill reads and decrypts the database on your device and does not connect to the network itself.
- App pairing: for an item you pick on another app's sign-in screen, the app remembers that app's bundle ID, display name, and the item UUID on your device. It does not store usernames, passwords, or item titles. You can remove pairings in the app's Settings.
- Keyboard suggestions: each time you unlock or save, the app gives iOS the domain and username of your items (or the item title when there is no username) to show suggestions. Passkeys also include the credential ID and user handle. This information never contains passwords, verification codes, or private keys. This feature is on by default, and you can turn it off in the app's Settings.
Camera and photos
- The camera is used only to scan QR codes for two-step verification.
- The iOS photo picker gives the app only the photo you pick. The app does not need access to your photo library.
- Images are processed on your device. The app does not keep images.
Clipboard
Content you copy from KeyDBX stays on this device, is not shared to your other devices through Universal Clipboard, and is cleared by iOS after 60 seconds.
Diagnostic information on your device
- The unlock timing shown in Settings is stored on your device. It contains only the time, the source read, the file size, the seconds for each stage, and a summary of the key derivation function (KDF) parameters.
- Messages the app writes to the iOS system log do not contain passwords, keys, verification codes, or Dropbox tokens.
- None of this information is sent to the developer.
This website
- This website is hosted on Cloudflare Pages. Cloudflare may keep access logs, such as IP addresses, under the Cloudflare Privacy Policy.
- The website's pages set no cookies, use no analytics or tracking, use no JavaScript, and load no resources from other websites.
- Cloudflare's bot detection adds its own script to the pages. The website's Content Security Policy (CSP) blocks that script from running. Cloudflare security features may set their own cookies.
Reporting issues
- Bug reports use GitHub Issues. Issues are public and anyone can read them. GitHub processes your account and report under the GitHub General Privacy Statement.
- Do not paste passwords, database files, master passwords, key files, or TOTP secrets in an issue.
- Reports on GitHub fall under the GitHub General Privacy Statement.
Contact
- General questions: GitHub Issues.
- Security issues: use GitHub private vulnerability reporting (Security → Report a vulnerability). Do not open a public issue.
Changes to this policy
When this policy changes, this page and its effective date are updated.