Privacy policy
How KeyVault collects, uses, protects, and retains service information.
Information KeyVault handles
Discord sign-in provides an account identifier, username, optional global display name, and optional avatar reference. KeyVault also stores server-side session records needed to keep a browser signed in.
The service handles the groups, products, variants, encrypted product keys, delivery configuration, panel memberships, payment references, and audit records that users submit or create.
Why the information is used
Account data is used to authenticate users, recognize the configured platform owner, enforce roles, and show the correct workspace. Inventory and delivery data is used to provide the key-delivery functions requested by users.
Operational records may be used to secure the service, diagnose failures, prevent abuse, and document sensitive changes. Raw product keys should never be written to application logs.
Cookies and sign-in
KeyVault uses temporary OAuth state and an HttpOnly browser-session cookie. These are necessary for Discord sign-in, request verification, and authenticated navigation; they are not described as advertising cookies.
The OAuth state cookie expires after ten minutes and is removed after sign-in. The browser-session cookie may remain valid for up to 30 days. Both cookies are HttpOnly, use SameSite=Lax, and are marked Secure in production. Logging out revokes the server-side session and asks the browser to remove its session cookie.
Service providers and transfers
Discord processes OAuth sign-in under Discord’s own terms. Stripe processes enabled card checkout and billing-portal activity. No production cryptocurrency provider receives data unless the operator later selects and configures one.
KeyVault uses hosting and database infrastructure to operate the service. Information may be processed where KeyVault or its service providers operate, subject to the safeguards required by applicable law.
Retention and security
KeyVault protects inventory secrets with encryption and uses hashed session tokens, scoped authorization, security headers, access limits, and audit records. No technical measure eliminates every risk.
Records are retained while needed to operate the service, maintain workspace history, secure accounts, resolve disputes, and satisfy legal obligations. Expired sessions and operational records may be removed according to service maintenance schedules. Deletion requests remain subject to security, fraud-prevention, backup, and legal-retention requirements.
Your rights and choices
Depending on applicable law, users may have rights to access, correct, export, restrict, object to, or delete personal information. KeyVault may verify the requester’s identity before acting on a request and may retain records required for security or legal reasons.
Users can also limit the information processed by signing out, revoking panel access they control, removing inventory or configuration they own, or discontinuing use of the service.