Privacy Policy
Effective Date: July 21, 2026 | Last Updated: July 21, 2026
KeySentry AI LLC (“KeySentry AI,” “we,” “us,” or “our”) operates the KeySentry AI platform at www.getkeysentry.com (the “Service”). This Privacy Policy describes how we collect, use, store, and protect information when you use our Service.
By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Account Information
- Name — as provided by your identity provider or entered during registration
- Email address — used for authentication, notifications, and support
- Organization name — the name of your team or company
- Role assignment — your access level within your organization
1.2 Credential Data
When you add a credential, we store:
- Credential name and platform identifier
- Encrypted API key — encrypted using AES-256-GCM before storage. We never store API keys in plaintext.
- Key mask — a partial, non-reversible display string for visual identification
- Expiry and rotation metadata
1.3 Billing Connector Data
When you connect a billing connector, we store encrypted connector credentials using the same AES-256-GCM method. Billing connectors are used solely to retrieve your organization’s usage and spend data from AI platforms.
1.4 Usage and Activity Data
- Audit log entries — every action taken within the platform with user attribution and timestamp
- Usage and spend data — retrieved from connected AI platforms via billing connectors
- Session information — authentication tokens managed by our identity provider
1.5 Information We Do NOT Collect
- We do not collect payment card numbers, bank account details, or financial account credentials
- We do not collect Social Security numbers or government-issued identification
- We do not track your browsing activity outside of the KeySentry AI platform
- We do not sell, rent, or share your data with advertisers
2. How We Use Your Information
- Provide the Service — store, encrypt, and manage your AI platform credentials
- Authentication and access control — verify your identity and enforce role-based permissions
- Notifications — send email alerts for credential expiry, rotation schedules, and budget thresholds
- Audit and compliance — maintain audit trails for security compliance
- Usage monitoring — display AI platform spend and usage data
- Support — respond to your support requests
- Service improvement — analyze aggregate, anonymized usage patterns
3. How We Store and Protect Your Information
3.1 Encryption
- At rest: AES-256-GCM encryption with unique initialization vectors per operation
- In transit: TLS encryption for all connections
- Master key: Stored in environment variables, separate from the database
3.2 Data Isolation
Each organization’s data is strictly isolated. All database queries are scoped by organization ID with server-side enforcement. Row Level Security (RLS) is enabled on all database tables.
3.3 Infrastructure
- Application hosting: Vercel — SOC 2 Type II certified
- Database: Supabase (PostgreSQL) — SOC 2 Type II certified
- Authentication: Clerk — SOC 2 Type II certified
3.4 Access Controls
Plaintext API keys are never exposed in client-side code. All encryption and decryption occurs server-side. KeySentry AI employees do not have access to your plaintext API keys.
4. Third-Party Services
- Clerk — authentication and session management (privacy policy)
- Vercel — application hosting (privacy policy)
- Supabase — database (privacy policy)
- Stripe — payment processing (privacy policy)
- AI Platform APIs — billing connectors make API calls to retrieve usage data, governed by each platform’s privacy policy
5. Data Retention
- Active accounts: Data retained for the lifetime of your account
- Deleted credentials: Permanently removed from the database
- Audit logs: Retained for the lifetime of your organization
- Account deletion: All data deleted within 30 days upon request to privacy@getkeysentry.com
6. Your Rights
- Access: Request a copy of your personal information
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your account and data
- Data portability: Export your data in JSON format
- Withdrawal of consent: Withdraw consent for data processing
Contact privacy@getkeysentry.com to exercise these rights. We respond within 30 days.
7. Cookies and Tracking
We use only essential cookies for authentication and session management. We do not use advertising cookies, third-party analytics trackers, or cross-site tracking.
8. Children’s Privacy
KeySentry AI is not directed to individuals under 18. We do not knowingly collect personal information from children.
9. International Data Transfers
Our infrastructure is hosted in the United States. By using the Service, you consent to the transfer of your information to the United States.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be posted on our website with an updated effective date.
11. Contact Us
KeySentry AI LLC
Email: privacy@getkeysentry.com
Website: www.getkeysentry.com
General inquiries: raj@getkeysentry.com