Privacy Policy
The short version. Keybound collects nothing. There is no sign-up, no email address, no device identifier, no usage analytics, no crash reporting and no advertising.
This Privacy Policy explains how Flowlab Apps (“we”, “us”) handles information in Keybound (the “app”). It is written to be read, not to be survived.
1. What we collect
Nothing. There is no sign-up, no login, no email address collected, no advertising identifier, no usage analytics and no crash reporting. No SDK in the app reports your behaviour to anyone.
Flowlab Apps operates no server that holds your Keybound data, because no such data ever reaches us. That is not a policy decision we could quietly reverse in an update — there is no backend to send it to.
2. What the app stores, and where
Everything Keybound saves is stored on the device you are using it on.
| What | Where | Why |
|---|---|---|
| Your vault | A single encrypted file in the app's private storage on your device | It holds your logins, notes, cards and keys |
| Your biometric unlock key | Your device's keychain or keystore, protected by biometric hardware | So Face ID or a fingerprint can unlock the vault |
| App preferences | On your device | Auto-lock timing, theme and similar settings |
| Backups you export | Wherever you choose to put them, encrypted with the same scheme | So you can keep a copy you control |
3. Permissions
Keybound asks for the following, and nothing else. Every permission marked optional can be declined, and the app keeps working without it.
- Biometrics (optional) — Face ID, Touch ID or Android biometric unlock. The check happens in your device's secure hardware, and the key is invalidated automatically if your enrolled biometrics change.
- Camera (optional) — Only to scan a QR code when pairing two of your own devices for sync, or to capture a TOTP setup code.
- Local network (optional) — Only when you sync two of your own devices, and only for the duration of that sync.
4. Network activity
Two connections exist, both under your control. Breach checking is opt-in: when you run it, a SHA-1 hash is computed on your device and only the first five hexadecimal characters are sent to api.pwnedpasswords.com, which replies with hundreds of matching prefixes; the comparison happens on your device. The service never receives your password, your full hash, or anything identifying you. Device sync is peer-to-peer: your two devices connect directly over your own local network, authenticated by an ephemeral P-256 key exchange and a short code you confirm on both screens. There is no relay and no copy retained anywhere.
5. Third parties
Have I Been Pwned (api.pwnedpasswords.com) receives a five-character hash prefix, and only if you choose to run a breach check. Their handling of that request is governed by their own privacy policy. If you never run a breach check, the app never contacts them. There are no other third parties, no analytics libraries and no advertising SDKs.
We do not sell, rent, share or disclose your personal information, because we do not hold any of it.
6. What we declare to the app stores
Apple and Google each require a privacy declaration alongside the app listing. These are the answers we give for Keybound, reproduced here so you can check them against the rest of this policy.
| Store declaration | Our answer |
|---|---|
| Apple App Store — App Privacy | Data Not Collected. Nothing is collected from this app, by us or by anyone else, so no data type is linked to you and none is used to track you. |
| Google Play — Data safety | No data collected. No data shared with third parties. No data is transmitted off the device, so there is none to encrypt in transit. Users can erase everything the app holds by deleting it. |
| Account deletion | Not applicable — the app has no account. See Data & Account Deletion. |
One qualification, for completeness: if you run the optional breach check, five hexadecimal characters of a password's SHA-1 hash are sent to Have I Been Pwned. That prefix matches hundreds of unrelated passwords, cannot identify you or the password it came from, is never seen or stored by us, and is only ever sent when you ask for the check. That is why the declarations above still read no data collected. Section 4 describes it in full.
7. Children
Keybound is not directed at children under 13, and it collects no personal information from anyone of any age. Because nothing is collected, nothing is collected from children.
8. Additional notes
Your master password is never stored — not on your device and not anywhere else. We have no server holding your data, no account system and no way to identify you. We could not hand over your vault if we were asked to, because we do not have it.
9. Your rights and your choices
Privacy laws including the GDPR and the CCPA give you rights to access, correct, export and delete personal data a company holds about you. Flowlab Apps holds no personal data about Keybound users, so there is nothing for us to produce, correct or erase on request.
You remain in full control of the data on your own device:
- Delete individual items from inside the app.
- On iPhone and Android, remove the app to delete its local data, subject to your device's own backup and restore settings.
- On a Mac, moving the app to the Trash leaves its data behind. In Settings, turn off Unlock with Touch ID first: that removes the key Keybound keeps in your Keychain, which deleting a folder would not. Then quit Keybound and delete
~/, which holds the encrypted vault and its settings. Backups you exported are your own files and stay where you put them.Library/ Application Support/ com. flowlab. aegisvault - Revoke any permission at any time from your device's system settings.
We do not sell personal information and never have. We do not share personal information for cross-context behavioural advertising.
10. Security
Because your data stays on your device, its security rests on your device's own protections — your passcode, your biometric lock and your operating system's storage encryption. Keep your device updated and locked.
11. Changes to this policy
If this policy changes, the revised version will be published at this address with a new date at the top. If a future version of Keybound ever begins collecting data, this policy will be updated before that version is released, and the app will ask for your consent in-app.
12. Contact
Questions about this policy, or about privacy in any Flowlab Apps app:
- Email: dev@flowlabapps.com
- Support: flowlabapps.
com/ apps/ keybound/ support/
We aim to answer within a few business days.