privacy
Privacy
Using keygrant locally
Without a cloud account, the keygrant CLI and MCP server make no network requests of their own. Secrets, their metadata and the local usage counts stay on your machine.
With a cloud account
The cloud service at api.keygrant.app stores:
- Encrypted items. Secret values and descriptions, encrypted on your device. We can’t decrypt them.
- Secret names, in plaintext, so you can see and audit them.
- Devices: each device’s public key, its name and when it was added.
- Account key material your devices need to join, all of it encrypted or public: never your password or Secret Key.
- Approval requests relayed to your phone approver: secret names, the command and the requesting session. Kept for 30 days so the console can show history.
- Audit events, at the level you choose: none, metadata (the default: names, action, session and a command hash), or full (including the command text). See Audit trail.
We don’t sell or share any of it, and we don’t use it for anything except
running the service. keygrant cloud delete deletes the account and everything
above.
This website
keygrant.app is served by Cloudflare, which may collect standard, aggregate visitor analytics. The approver console at app.keygrant.app blocks all third-party scripts, analytics included, with a strict Content Security Policy.
Contact
Questions: open an issue.