Back to Keyfren

Privacy Policy

Last updated 31 August 2026
This page describes how Keyfren actually works today, in plain language rather than legal language. It is not a substitute for legal advice.

What we store

Your account: an email address and a hashed password. We never store the password itself, only a bcrypt hash of it.
Your contacts and everything you record about them: names, phone numbers, email addresses, notes, tags, and the dates you last spoke.
Messages and emails you send or receive through Keyfren, along with calendar events you create here.

What we take from Gmail and Google Calendar

Connecting Google is optional and Keyfren works without it. If you do connect it, we ask for exactly two permissions, both of them read-only: gmail.readonly and calendar.readonly.
Read-only is the whole story. Keyfren cannot send email from your account, cannot delete or modify anything in your mailbox, and cannot create, move, or cancel anything in your calendar. We never ask for a permission that would let us.
From Gmail we read messages exchanged with people already in your contacts, and we store the sender, recipient, subject, body text, and date so the app can show you a conversation history without going back to Google every time. From Calendar we read event times, titles, locations, and attendees.
We do not read, store, or analyse mail from people who are not among your contacts, and we never scan your mailbox for advertising or model-training purposes.
The access tokens that make this possible are encrypted before they are written down, using a key held separately from the database. Disconnecting the integration in Settings deletes them.
Android Messenger and iMessage appear in Settings but are not connected to anything yet. They read nothing today; if that changes, this page changes first.

About the people in your contacts

Most of the people in your Keyfren account never signed up for Keyfren, and we think that deserves saying plainly rather than burying it.
What we hold about them, their name, contact details, your notes, and the history of your conversations, exists for one purpose: helping you, the account holder, keep up a relationship you already have. We do not use it for anything else, we do not sell it, we do not build profiles from it, and we do not combine it with data from other accounts.
Nobody else sees it unless you deliberately share a specific contact, and then only that contact and only with the person you chose.
You are responsible for having a legitimate reason to keep information about the people you know, and for honouring any request they make of you about it. If someone asks you to remove them, you can delete that contact and everything attached to them from your account at any time.

What we do with it

We use it to run the product you are using: showing your contacts, ranking who is worth reaching out to, and scheduling meetings you ask us to schedule.
We do not sell it. We do not use it to build advertising profiles.
The message polish feature runs locally on rules, not on a language model, so the text of your messages is not sent anywhere for that.

How long we keep it

While your account is open, we keep what you put in and what you connected, because the product is a memory and deleting it silently would defeat the point.
When you delete your account, it goes immediately and in full, and any Google access we hold is revoked at the same time. See the section below.
Deleting an individual contact removes that contact along with their messages, emails, and notes.

Who else can see it

Other Keyfren users cannot see your data. Isolation is enforced by the database itself through row-level security, not only by application code.
If you deliberately share a contact with someone, they can read what you shared, and only that.
We use a small number of service providers to operate: a hosting provider, an email provider for account emails such as password resets, and PostHog, which we use two separate ways below.
First, if a request to our server fails unexpectedly, we send PostHog the technical details, what kind of error, which endpoint, nothing about you personally, so we can fix it. That happens regardless of your analytics choice below, the same way it would with any error-monitoring tool: it is about keeping the service working, not about tracking you.
Second, if you accept analytics, we also use PostHog in your browser to count page views and basic device and browser information. That part is switched off until you accept, it never records your screen, and it never receives your contacts or the text of your messages. You can change your mind in Settings at any time.

Where your data is processed

Keyfren the business operates out of Panama, but the database that holds your data and the server that runs the app are hosted in the United States. If you are in the EU, UK, or anywhere else with rules about moving personal data across borders, that means your data leaves your region to be processed.
We have not yet put a formal transfer mechanism, such as Standard Contractual Clauses, in place with our hosting providers. That is a real gap for a product this early, and one we intend to close as Keyfren grows rather than paper over.
If you are evaluating Keyfren for your team or company, we have a Data Processing Agreement template with the full detail on sub-processors and this transfer question: keyfren.com/dpa.

How to get your data out, or delete it

Settings has a "Download my data" button that gives you a single file containing everything we hold for your account: profile, contacts, messages, emails, calendar events, and integration settings. You can also export just your contacts as CSV or vCard.
Settings also has a "Delete account" button. It is real and immediate: your account row is deleted, and every contact, message, email, calendar event, share, and stored token attached to it is deleted with it.
If you had connected Google, we also ask Google to revoke the access you granted, so the connection does not outlive the account.
We do not require you to email anyone or wait for us to process a request. The button does the work.

Contact

Questions about any of this, or where to send a request: support@keyfren.com. Keyfren is operated out of Panama City, Panama.