Last updated: August 20, 2026
Kael Security (“we”, “us”) provides a zero-knowledge, end-to-end encrypted password manager, available as a web app and browser extension. This policy explains what information we collect, why, and — just as importantly — what we structurally cannot see, because your vault is encrypted on your device before it ever reaches our servers.
Every item you save — logins, secure notes, payment cards, identities, SSH keys — is encrypted client-side with AES-256-GCM before it is transmitted. We store the resulting ciphertext, the item’s type, and non-sensitive metadata (folder, favorite flag, timestamps) needed to organize and sync your vault. We cannot decrypt this content.
If you create or join an organization to share select vault items with teammates, we store the organization name, membership roles, and — for each member — a copy of the shared vault key individually encrypted for that member’s public key. We cannot decrypt these either; only the intended member’s browser can.
The extension reads the page you’re currently viewing only to detect login and signup forms and to perform autofill locally in your browser. It does not transmit your browsing history, page content, or the contents of pages you visit to our servers — the only network traffic it generates is your own encrypted vault syncing with your account.
We do not use your data for advertising, and we do not run third-party analytics or ad-tracking scripts.
Because encryption and decryption happen entirely in your browser, we structurally cannot see: your master password, the decrypted contents of any vault item, or the decrypted vault key itself. This also means if you forget your master password, we cannot recover it or your vault for you — there is no backdoor. Keep your password hint or a written backup somewhere safe.
We do not sell your data. We do not share it with third parties for marketing purposes. We may disclose information if required to by law, or to protect the rights, safety, or security of Kael Security, our users, or the public.
We retain your account and encrypted vault data for as long as your account is active. Security logs are retained only as long as needed for the security and integrity purposes described above. If you delete your account, we delete your account data; some minimal records may be retained where required for legal or security purposes.
We don’t use tracking or advertising cookies. The web app stores a short-lived session refresh token in your browser’s session storage (cleared when you lock your vault or close the browser) and remembers your last-used email address in local storage for convenience. Your master password and decrypted vault key are never written to disk or persisted in any browser storage.
You can review and update your account details from within the app. To request a copy of your account data, or to permanently delete your account and associated data, contact us at the address below. Depending on where you live, you may have additional rights over your personal data under applicable law; we honor requests to exercise those rights.
Vault data is encrypted client-side with AES-256-GCM. Your master password is never transmitted — only a hash derived from it, which is further hashed with Argon2id before storage. All traffic between your device and our servers is encrypted in transit (HTTPS). We apply rate limiting and standard security headers to our API.
Kael Security is not directed at children, and we do not knowingly collect information from children under 16.
We may update this policy from time to time. Material changes will be reflected here with an updated “Last updated” date.
Questions about this policy or your data? Email us at privacy@kael.es.