← Back to app

Privacy Policy

Last updated: September 7, 2026 · Effective: January 1, 2025 · v3.8

KeyAssist ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your personal data.

🇪🇺 Your GDPR Rights (EU/EEA users)

To exercise these rights: privacy@keyassist.app

1. Data We Collect

CategoryDataPurposeLegal Basis
AccountName, email, countryAuthentication, service deliveryContract
Profile & onboardingEquipment you own (equipment, equipmentOther), how you heard about us (hearAbout), and preferred country & equipment used as search defaults (prefCountry, prefEquipment)Personalization, onboarding, tailoring search resultsConsent
Client Journal (cloud copy, paid plans)Your customers' name, phone, address, VIN, vehicle and key details, prices, job notes and key photos — the records you enter in the Journal. On the Free plan the Journal stays on your device only; on a paid plan it syncs automatically to your account while you are signed in.Your own record-keeping — mirroring your Journal across your devicesYou are the controller of your customers' data; KeyAssist processes it only on your instruction, as your processor (GDPR Art. 28 — see Terms §16). Stored on Firebase (Google) alongside your profile.
UsageCases viewed, searches, session durationService improvement, analyticsLegitimate interest
BillingPayment method (via Stripe — we don't store card numbers)Subscription managementContract
TechnicalIP address, browser type, device typeSecurity, fraud preventionLegitimate interest
CookiesSession token, preferencesAuthentication, personalizationConsent / Contract

2. How We Use Your Data

3. Data Sharing

We share your data only with these third-party service providers:

ServicePurposeData sharedCompliance
Firebase (Google)Authentication & databaseEmail, UID, usage events; on paid plans also your Client Journal records and key photos (cloud copy)EU-US DPF, GDPR SCCs
StripePayment processingEmail, billing addressPCI DSS Level 1
VercelHosting & edge deliveryIP address (logs)SOC 2 Type II
SentryError tracking (opt-in only)Error events, device typeGDPR, EU data region available
Microsoft Clarity (Microsoft Corporation)Privacy-friendly product analytics & session heatmaps (consent-gated)Anonymized interaction events, page URLs, device/browser; processed in USA/EUData Processing Addendum
Upstash (Vercel KV / Redis)API rate-limitingHashed IP + request counters (ephemeral, ~1h TTL); processed in USA/EUData Processing Addendum
Resend (Resend Inc.)Email delivery: welcome / account-confirmation mail, email-change verification, trial reminders, and — only if you ticked the product-updates box at registration — one optional day-7 reminder (with an unsubscribe link)Recipient email address, message content; delivered via AWS SES (USA)Data Processing Addendum
NHTSA vPIC (US Dept. of Transportation)VIN decoding (optional VIN lookup you initiate)Only the VIN you type; no account identifier is sent — a public government APIPublic API (no PII stored by us)
jsDelivr (open-source CDN)Delivery of static library assets (incl. the transformers.js on-device voice-search engine)No personal data beyond the standard HTTP request (IP), same as any CDN fetchPrivacy policy
Hugging Face (Hugging Face, Inc.)On-device voice search — delivers the offline Whisper speech-recognition model to your browser (the transformers.js library itself is served via jsDelivr, above)None — model files download to your device; your audio is transcribed locally and never leaves your browserPublic CDN file downloads. Hosts: huggingface.co, *.hf.co, cas-bridge.xethub.hf.co
Embedded media & static assets — YouTube (Google), GitHub, jsDelivr, Hugging FaceYouTube: video thumbnails and click-to-play players on case pages (privacy-enhanced youtube-nocookie embed); GitHub: brand logo images; jsDelivr / Hugging Face: the on-device voice-search model (rows above)Your IP address and standard browser request headers when the image or file loads — no cookies before you press playGoogle privacy policy · GitHub privacy statement

We never sell your personal data to third parties. Sentry and Microsoft Clarity are only activated with your explicit cookie consent.

This subprocessor list is kept current and updated whenever we add, change, or remove a service provider.

4. Cookies & Tracking

We use cookies in two categories:

We do not use advertising cookies, cross-site trackers, or sell browsing data. You can change your cookie preferences at any time in Account settings → Cookie preferences, or by emailing us.

5. Data Retention

Data categoryRetention periodWhat happens on deletion
Account profile (Firestore)While account is activeDeleted within 24h of account deletion request
Favorites & saved casesWhile account is activeDeleted simultaneously with account
Client Journal cloud copy (paid plans)While your account exists and the job is in your JournalDeleting a job erases its customer data from the cloud copy at once (only a deletion marker with the job id and time remains, so your other devices learn of it) and removes its photos; deleting your account removes the whole copy within 24 hours. Moving back to the Free plan stops syncing but does not delete the copy — delete the jobs, delete your account, or email privacy@keyassist.app and we purge it. Deleted data can linger in routine database backups for up to 30 days.
Billing records (Stripe)7 years after last transactionStripe retains for legal/tax compliance — not under our control to delete sooner
Error logs (Sentry)90 days (Sentry free tier)Auto-purged by Sentry; you can request immediate deletion via privacy@
Server request logs (Vercel)30 daysAuto-purged by Vercel infrastructure
Usage analytics linked to your account IDUp to 2 yearsDeleted with your account (and on request)
CSP violation reports (security telemetry)180 daysAuto-purged; security telemetry with minimal / no personal data
Bot / abuse-detection reports180 daysAuto-purged; honeypot / abuse-prevention data
API request logs (paid endpoints)90 daysAuto-purged; access audit for paid endpoints
Email-change magic-link tokens7 daysAuto-purged; single-use, expire within 24h of issue

Account deletion timeline: When you delete your account (Account settings → Delete account), KeyAssist deletes your Firestore profile and Firebase Auth entry within 24 hours. Stripe subscription is cancelled immediately. Billing records are retained for 7 years as required by Canadian tax law (Income Tax Act).

6. Security

We protect your data with:

7. Children's Privacy

KeyAssist is not intended for users under 18 years of age. We do not knowingly collect data from children.

8. International Transfers

Your data may be processed outside your country of residence, including in the United States and the European Union, by the subprocessors listed in Section 3. Every such transfer relies on a valid safeguard — Standard Contractual Clauses (SCCs) and, where the provider is certified, the EU-US Data Privacy Framework (DPF).

ProcessorProcessing locationTransfer mechanism
Firebase (Google) — profile, favorites, Client Journal cloud copyUSA / EUEU-US Data Privacy Framework + SCCs
StripeUSAStandard Contractual Clauses (Stripe DPA)
VercelUSAStandard Contractual Clauses (Vercel DPA)
SentryUSA / EUSCCs; EU data region available
Microsoft ClarityUSA / EUEU-US Data Privacy Framework + Microsoft DPA/SCCs
Upstash (Vercel KV)USA / EUStandard Contractual Clauses (Upstash DPA)
Resend (via AWS SES)USAStandard Contractual Clauses (Resend DPA)
Hugging Face & jsDelivr (CDN)Global CDNPublic model/library file downloads — no personal data transferred
YouTube (Google) & GitHub (media, logo images)USA / global CDNPublic image and player loads — IP address only (Google: EU-US Data Privacy Framework)

9. Your Choices

Scope of self-serve export: "Export my data" returns your profile, saved preferences, favorites, and locally-stored data as JSON/CSV. The Client Journal has its own Export (CSV) and Backup (JSON, includes key photos) buttons — they return every job and are the Journal's data-portability path; the cloud copy on paid plans mirrors those same records. For a complete GDPR Article 15 copy of everything linked to your account (including server-side records not in the self-serve bundle), email privacy@keyassist.app and we will provide it within 30 days.

10. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you additional rights regarding your personal information.

To exercise your CCPA rights, contact: privacy@keyassist.app · Subject line: "CCPA Request"

Do Not Sell My Personal Information: KeyAssist does not sell personal information to third parties. This page serves as our opt-out notice — no further action is needed.

11. Changes to This Policy

We'll notify you by email and/or a prominent in-app notice at least 30 days before significant changes. The "Last updated" date at the top reflects the most recent revision.

12. Contact & DPO

Data privacy questions: privacy@keyassist.app

Mailing: 327 Portage Ave, Winnipeg, MB R3B 2C1, Canada

Response time: within 30 days for GDPR requests.


English · Українська · Español · Português · Deutsch · Français · Polski · العربية · עברית · فارسی · اردو · Italiano · Türkçe · 日本語 · 简体中文 · Русский · हिन्दी · Bahasa Indonesia · Tiếng Việt · 한국어 · ไทย · Nederlands · Română · Bahasa Melayu · 繁體中文 · Ελληνικά · Čeština · Magyar · Svenska · বাংলা