KeyLog: API Key Vault Privacy Policy
Last updated: October 2026
Summary
KeyLog never sends your secrets anywhere. Secret values are stored in the Keychain on this device only, are not synced to iCloud and are only readable while your device is unlocked. To show service logos, the app requests public logo images by the service's domain name.
This policy covers the KeyLog: API Key Vault app for iPhone and iPad, published by mk0.net, an independent app studio. It is written from what the app actually does in its code. Questions: [email protected].
What we receive
Nothing. We have no accounts or servers for this app, and nothing you enter in it is sent to us.
What stays on your device
- Secret values are stored in the iOS Keychain on this device only. They are not synced and are only available while the device is unlocked.
- Key names, projects, environments and dates are stored on this device.
- Downloaded service logos are cached on this device.
- Your settings are stored on this device.
We cannot see this data. It is not uploaded to us.
Permissions the app may ask for
- Face ID: Used to unlock the vault when you turn on the app lock.
- Notifications: Asked when you set rotation or expiry reminders. These are local notifications.
Every permission is optional and can be changed later in the iPhone Settings app. Features that need a permission you decline simply stay unavailable.
Data that leaves your device
The app talks to the following services. Each receives only what is listed, and only for the purpose shown.
- public logo and icon services (such as Clearbit, Google favicons, DuckDuckGo icons, icon.horse) (showing a service's logo): Only the public domain of a service template, for example stripe.com, to download its logo. Your keys and their names are never sent.
- RevenueCat (subscription management): An anonymous app user ID and your subscription status, when the app checks, starts or restores your subscription. Nothing you enter in the app is sent. Their privacy policy.
Your keys and passwords
The API keys and secrets you save are stored only in the iOS Keychain on this device, marked this-device-only and not synchronizable. KeyLog never sends them anywhere. They leave the device only if you export your vault yourself.
Sensitive information
API keys are highly sensitive. KeyLog keeps them in the Keychain on this device, protects the app with an optional Face ID lock and offers passphrase-encrypted exports (AES-GCM). An unencrypted export is a plain file, so store it carefully.
Purchases
Subscriptions are sold and billed by Apple through the App Store. We never see your name, Apple ID, card or payment details. The app checks your subscription status through RevenueCat, which receives an anonymous ID and your purchase status, not your identity.
Ads, tracking and analytics
No ads, no tracking across apps or websites, and no data sold. The app contains no analytics SDK.
Account
No account needed. There is no sign-in.
Children
KeyLog: API Key Vault is not directed at children under 13, and we do not knowingly collect personal information from children.
Keeping and deleting your data
You can delete any key or project in the app, which also removes its secret from the Keychain. You can export your vault first, optionally encrypted with a passphrase. Deleting KeyLog removes its data from this device.
Your rights
Depending on where you live (for example under the GDPR, UK GDPR, CCPA or KVKK), you have the right to access, correct, export or delete your personal data. Because the app keeps your records on your own device, you can do most of this directly in the app or by deleting it. For anything else, or for data held by a service listed above, email [email protected] and we will help within 30 days.
Changes to this policy
If the app starts handling data differently, we will update this page and the date below before the change ships.
Contact
mk0.net, [email protected]