Last updated: September 7, 2026 · Effective: January 1, 2025 · v3.8
KeyAssist ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your personal data.
To exercise these rights: privacy@keyassist.app
| Category | Data | Purpose | Legal Basis |
|---|---|---|---|
| Account | Name, email, country | Authentication, service delivery | Contract |
| Profile & onboarding | Equipment you own (equipment, equipmentOther), how you heard about us (hearAbout), and preferred country & equipment used as search defaults (prefCountry, prefEquipment) | Personalization, onboarding, tailoring search results | Consent |
| Client Journal (cloud copy, paid plans) | Your customers' name, phone, address, VIN, vehicle and key details, prices, job notes and key photos — the records you enter in the Journal. On the Free plan the Journal stays on your device only; on a paid plan it syncs automatically to your account while you are signed in. | Your own record-keeping — mirroring your Journal across your devices | You are the controller of your customers' data; KeyAssist processes it only on your instruction, as your processor (GDPR Art. 28 — see Terms §16). Stored on Firebase (Google) alongside your profile. |
| Usage | Cases viewed, searches, session duration | Service improvement, analytics | Legitimate interest |
| Billing | Payment method (via Stripe — we don't store card numbers) | Subscription management | Contract |
| Technical | IP address, browser type, device type | Security, fraud prevention | Legitimate interest |
| Cookies | Session token, preferences | Authentication, personalization | Consent / Contract |
We share your data only with these third-party service providers:
| Service | Purpose | Data shared | Compliance |
|---|---|---|---|
| Firebase (Google) | Authentication & database | Email, UID, usage events; on paid plans also your Client Journal records and key photos (cloud copy) | EU-US DPF, GDPR SCCs |
| Stripe | Payment processing | Email, billing address | PCI DSS Level 1 |
| Vercel | Hosting & edge delivery | IP address (logs) | SOC 2 Type II |
| Sentry | Error tracking (opt-in only) | Error events, device type | GDPR, EU data region available |
| Microsoft Clarity (Microsoft Corporation) | Privacy-friendly product analytics & session heatmaps (consent-gated) | Anonymized interaction events, page URLs, device/browser; processed in USA/EU | Data Processing Addendum |
| Upstash (Vercel KV / Redis) | API rate-limiting | Hashed IP + request counters (ephemeral, ~1h TTL); processed in USA/EU | Data Processing Addendum |
| Resend (Resend Inc.) | Email delivery: welcome / account-confirmation mail, email-change verification, trial reminders, and — only if you ticked the product-updates box at registration — one optional day-7 reminder (with an unsubscribe link) | Recipient email address, message content; delivered via AWS SES (USA) | Data Processing Addendum |
| NHTSA vPIC (US Dept. of Transportation) | VIN decoding (optional VIN lookup you initiate) | Only the VIN you type; no account identifier is sent — a public government API | Public API (no PII stored by us) |
| jsDelivr (open-source CDN) | Delivery of static library assets (incl. the transformers.js on-device voice-search engine) | No personal data beyond the standard HTTP request (IP), same as any CDN fetch | Privacy policy |
| Hugging Face (Hugging Face, Inc.) | On-device voice search — delivers the offline Whisper speech-recognition model to your browser (the transformers.js library itself is served via jsDelivr, above) | None — model files download to your device; your audio is transcribed locally and never leaves your browser | Public CDN file downloads. Hosts: huggingface.co, *.hf.co, cas-bridge.xethub.hf.co |
| Embedded media & static assets — YouTube (Google), GitHub, jsDelivr, Hugging Face | YouTube: video thumbnails and click-to-play players on case pages (privacy-enhanced youtube-nocookie embed); GitHub: brand logo images; jsDelivr / Hugging Face: the on-device voice-search model (rows above) | Your IP address and standard browser request headers when the image or file loads — no cookies before you press play | Google privacy policy · GitHub privacy statement |
We never sell your personal data to third parties. Sentry and Microsoft Clarity are only activated with your explicit cookie consent.
This subprocessor list is kept current and updated whenever we add, change, or remove a service provider.
We use cookies in two categories:
We do not use advertising cookies, cross-site trackers, or sell browsing data. You can change your cookie preferences at any time in Account settings → Cookie preferences, or by emailing us.
| Data category | Retention period | What happens on deletion |
|---|---|---|
| Account profile (Firestore) | While account is active | Deleted within 24h of account deletion request |
| Favorites & saved cases | While account is active | Deleted simultaneously with account |
| Client Journal cloud copy (paid plans) | While your account exists and the job is in your Journal | Deleting a job erases its customer data from the cloud copy at once (only a deletion marker with the job id and time remains, so your other devices learn of it) and removes its photos; deleting your account removes the whole copy within 24 hours. Moving back to the Free plan stops syncing but does not delete the copy — delete the jobs, delete your account, or email privacy@keyassist.app and we purge it. Deleted data can linger in routine database backups for up to 30 days. |
| Billing records (Stripe) | 7 years after last transaction | Stripe retains for legal/tax compliance — not under our control to delete sooner |
| Error logs (Sentry) | 90 days (Sentry free tier) | Auto-purged by Sentry; you can request immediate deletion via privacy@ |
| Server request logs (Vercel) | 30 days | Auto-purged by Vercel infrastructure |
| Usage analytics linked to your account ID | Up to 2 years | Deleted with your account (and on request) |
| CSP violation reports (security telemetry) | 180 days | Auto-purged; security telemetry with minimal / no personal data |
| Bot / abuse-detection reports | 180 days | Auto-purged; honeypot / abuse-prevention data |
| API request logs (paid endpoints) | 90 days | Auto-purged; access audit for paid endpoints |
| Email-change magic-link tokens | 7 days | Auto-purged; single-use, expire within 24h of issue |
Account deletion timeline: When you delete your account (Account settings → Delete account), KeyAssist deletes your Firestore profile and Firebase Auth entry within 24 hours. Stripe subscription is cancelled immediately. Billing records are retained for 7 years as required by Canadian tax law (Income Tax Act).
We protect your data with:
KeyAssist is not intended for users under 18 years of age. We do not knowingly collect data from children.
Your data may be processed outside your country of residence, including in the United States and the European Union, by the subprocessors listed in Section 3. Every such transfer relies on a valid safeguard — Standard Contractual Clauses (SCCs) and, where the provider is certified, the EU-US Data Privacy Framework (DPF).
| Processor | Processing location | Transfer mechanism |
|---|---|---|
| Firebase (Google) — profile, favorites, Client Journal cloud copy | USA / EU | EU-US Data Privacy Framework + SCCs |
| Stripe | USA | Standard Contractual Clauses (Stripe DPA) |
| Vercel | USA | Standard Contractual Clauses (Vercel DPA) |
| Sentry | USA / EU | SCCs; EU data region available |
| Microsoft Clarity | USA / EU | EU-US Data Privacy Framework + Microsoft DPA/SCCs |
| Upstash (Vercel KV) | USA / EU | Standard Contractual Clauses (Upstash DPA) |
| Resend (via AWS SES) | USA | Standard Contractual Clauses (Resend DPA) |
| Hugging Face & jsDelivr (CDN) | Global CDN | Public model/library file downloads — no personal data transferred |
| YouTube (Google) & GitHub (media, logo images) | USA / global CDN | Public image and player loads — IP address only (Google: EU-US Data Privacy Framework) |
Scope of self-serve export: "Export my data" returns your profile, saved preferences, favorites, and locally-stored data as JSON/CSV. The Client Journal has its own Export (CSV) and Backup (JSON, includes key photos) buttons — they return every job and are the Journal's data-portability path; the cloud copy on paid plans mirrors those same records. For a complete GDPR Article 15 copy of everything linked to your account (including server-side records not in the self-serve bundle), email privacy@keyassist.app and we will provide it within 30 days.
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you additional rights regarding your personal information.
To exercise your CCPA rights, contact: privacy@keyassist.app · Subject line: "CCPA Request"
Do Not Sell My Personal Information: KeyAssist does not sell personal information to third parties. This page serves as our opt-out notice — no further action is needed.
We'll notify you by email and/or a prominent in-app notice at least 30 days before significant changes. The "Last updated" date at the top reflects the most recent revision.
Data privacy questions: privacy@keyassist.app
Mailing: 327 Portage Ave, Winnipeg, MB R3B 2C1, Canada
Response time: within 30 days for GDPR requests.
English · Українська · Español · Português · Deutsch · Français · Polski · العربية · עברית · فارسی · اردو · Italiano · Türkçe · 日本語 · 简体中文 · Русский · हिन्दी · Bahasa Indonesia · Tiếng Việt · 한국어 · ไทย · Nederlands · Română · Bahasa Melayu · 繁體中文 · Ελληνικά · Čeština · Magyar · Svenska · বাংলা