KeySoftPrivacy Policy
LegalLast updated: July 25, 2026
1. Data Controller
The Data Controller for personal data is:
Mikesoft by Michael Gasperini
VAT ID: 02693140465
Email: keysoft@mikesoft.it
Website: www.mikesoft.it
2. Nature of the Application
KeySoft is an Android password manager. The codebase is also prepared for iPhone and iPad cloud-simulator testing, but KeySoft is not published on the Apple App Store. It is built with a "privacy by design" and "offline first" approach: vault secrets remain on the user's device.
KeySoft does not involve creating an account: there is no sign-up, no remote login and no user profile on our servers. Consequently there is no account-linked data to delete outside the user's device.
3. Categories of Processed Data
3.1 Locally stored data
Credentials, notes, and other vault secrets entered by the user are stored and processed locally on the user's device. Specifically, the application saves the following on the device:
- Custom display name, optional
- Passwords and sign-in credentials for web services
- Verification and derivation metadata for the Master Password; the Master Password itself is never stored
- Application preferences: theme, language, security settings
- The biometric authentication preference and, only when enabled, the vault key protected by the device SecureStore
- Categories and notes attached to passwords
3.2 Technical data
The application may use technical information from Android or, in simulator test builds, Apple systems that is necessary for operation, but does not collect it for statistical or profiling purposes. Specifically it may access:
- The device biometric sensor, for authentication only
- The system clipboard, to copy a password, with automatic clearing
- Local notifications, for security alerts
- Application state, for automatic locking
3.3 Data security and email addresses
Email addresses entered as part of a credential stay in the local vault and are not accessible to the developer. Vault secrets are encrypted at rest. Backups are only created on the user's initiative, and an exported backup is encrypted when the user chooses to protect it with a password; KeySoft does not send backups to external servers.
4. Legal Basis for Processing
The processing of personal data is based on the user's consent (Art. 6, para. 1, lit. a GDPR) and on the performance of the agreement relating to the use of the application (Art. 6, para. 1, lit. b GDPR).
5. Purpose of Processing
Personal data is processed exclusively to:
- Provide the secure password management service
- Authenticate the user
- Personalise the way the application is used
- Apply security measures such as automatic locking and screenshot protection
- Show local security notifications
6. Data Sharing and Transfer
Vault secrets, including passwords, credentials, and notes, are stored and processed locally and are not transmitted by KeySoft. Network connectivity is used exclusively by Expo Updates (expo.dev) to check for and download compatible updates.
For that purpose, Expo Updates may receive the device operating system/platform, randomized tokens used to determine update downloads, app/build and runtime versions, and ordinary technical request or service data such as IP address, request headers, errors, performance metrics, and update interactions. Passwords, credentials, notes, and other vault secrets are not sent.
7. Data Retention
Personal data is retained on the user's device until:
- The user uninstalls the application
- The user manually deletes the data from the application
- The user resets the device data
There are no automatic backups on external servers. Responsibility for backups rests entirely with the user.
8. Rights of the Data Subject
Under the GDPR the user exercises their rights directly through the app's features:
- Access: view all data through the app interface
- Rectification: change data directly in the application
- Erasure: delete data using the reset function or by uninstalling the app
- Portability: export data using the app's export features
- Objection: stop using the application
For privacy-related questions, contact: keysoft@mikesoft.it
9. Data Deletion
You can delete your data in one of the following ways:
Method 1: App Reset (Recommended)
From the app settings, select the reset/delete data option.
⚠️ Note: This operation is irreversible. Ensure you have exported any important passwords before proceeding.
Method 2: Uninstalling the App
Uninstalling the app removes the local database from the device.
Method 3: Manage data in device settings
On Android, clear app data in system settings. In a development or test build installed on a simulator, removing the app also removes its local data.
Before deleting data, we strongly recommend exporting your passwords if you intend to keep them.
Once data is deleted, it cannot be recovered in any way as no copy exists on our servers.
10. Security Measures
The application protects the local vault with the following measures:
- KS1 format with AES-256-CBC encryption and HMAC-SHA256 integrity verification
- Key derivation from the Master Password using Argon2id in native builds, with PBKDF2 as a fallback where Argon2id is unavailable
- Derived keys, salts and initialisation vectors generated by a cryptographically secure random number generator
- Optional biometric authentication, with the vault key held in the device SecureStore and protected by device authentication
- Automatic application locking
- Protection against screenshots and screen recording
- The app is excluded from Android automatic backup: vault data does not end up in the device cloud backup
Internet connectivity is used exclusively to check for and download compatible updates through Expo Updates, over HTTPS, and not to transmit vault secrets.
11. Minors' Data Processing
The application is not intended for minors under 16. We do not knowingly collect personal data from minors under 16.
12. Third-Party Services
KeySoft DOES NOT use third-party analytics services, advertising networks, or tracking tools. Specifically, the application does not integrate:
- Google Analytics or equivalent analytics services
- Advertising SDKs, for example AdMob or Facebook Ads
- Crash reporting tools, for example Firebase Crashlytics or Sentry
- Push notification services
- Social media SDKs
- Cloud storage services
All notifications are LOCAL ONLY and generated directly by the device. No data is sent to external notification services.
Expo Updates (by Expo / EAS): the app uses this service to check for and download compatible over-the-air updates. For that purpose, it may receive the Android operating system/platform or, for simulator test builds, iOS, randomized tokens used to determine update downloads, app/build and runtime versions, and ordinary technical request or service data such as IP address, request headers, errors, performance metrics, and update interactions. It does not receive passwords, credentials, notes, or other vault secrets. Expo privacy policy: expo.dev/privacy
13. Permissions and Specific Features
| Purpose | Data usage |
|---|---|
| Biometric AuthenticationEnable unlocking through fingerprint or other biometric authentication supported by an installed build, as an alternative to the Master Password. Biometric behaviour on real Apple hardware is outside the current cloud-simulator test coverage. | Biometric data and templates are managed exclusively by the device and operating system. KeySoft does not acquire, store, or transmit biometric data, templates, or hashes. The key material used for biometric unlocking is stored in SecureStore and protected by device authentication. |
| Local NotificationsDisplay local security alerts (weak passwords, auto-lock warnings, backup reminders). | All notifications are generated and displayed locally. No data is sent to external servers. |
| File/Storage AccessRequired for Backup and Restore features (Import/Export). | The app accesses only files explicitly selected by the user. Exported files are encrypted if the user chooses to protect them with a password. |
| Screen Protection (Flag Secure)Protect sensitive information from screenshots and screen recordings. | This permission does not access or store any data. It only prevents the OS from capturing screen content when the app is active. |
| Camera and Photo GalleryAllow the user to choose a personal profile picture from the gallery or camera. | The app only accesses images explicitly selected by the user. Images are saved locally as a profile avatar and are never transmitted to external servers. |
| ClipboardCopy passwords to the clipboard for quick use in other apps. | The password is temporarily copied to the clipboard and automatically cleared after 60 seconds (default setting). The app does not read clipboard content from third-party apps. |
Network connectivity is used exclusively by Expo Updates to check for and download compatible automatic app updates. Passwords, credentials, notes, and other vault secrets are not transmitted over the network; Expo Updates may receive only the technical information and ordinary network-request data described above.
14. User Responsibility
Given the offline and local nature of the application, the user is solely responsible for safeguarding the Master Password and backups.
⚠️ Important: The developer cannot recover lost or forgotten data, as no copy exists on external servers.
15. Cookies and Tracking
KeySoft DOES NOT use cookies, web beacons, pixels, or other tracking technologies. The application does not collect telemetry, analytics, or usage statistics.
16. GDPR Compliance
This application is designed around the principles of the General Data Protection Regulation (EU) 2016/679:
- Privacy by design: an architecture that collects no external data
- Privacy by default: the most protective settings are active from first launch
- Data minimisation: only strictly necessary data is stored
- User control: full control over your own data from the app interface
- No profiling: no automated decision-making and no profiling
17. Right to Complain
Users have the right to lodge a complaint with the supervisory authority if they believe their data protection rights have been violated.
Garante per la Protezione dei Dati Personali
Piazza Venezia, 11 - 00187 Roma, Italy
www.garanteprivacy.it
18. Changes to Privacy Policy
We reserve the right to update this Privacy Policy. Material changes will be communicated through an app update and, where appropriate, a dedicated notice. Continued use of the application after those changes implies acceptance of the updated policy.