KeyNest Privacy Policy
KeyNest (Chinese name: 钥匣; application bundle name: com.sanvar.vault) is provided by Liu Xinhua (刘新华, referred to as “we”, “us” or “our”). It encrypts and manages account passwords on your device, generates two-step verification codes, and imports and exports encrypted backups. This Policy explains the purposes, methods, scope and retention periods of personal information processing, and how you can manage your information and contact us.
We respect your privacy and take appropriate security measures in accordance with applicable law. Please read this Policy before using the relevant features, paying particular attention to account passwords, verification secrets, backups, copying and quick unlock.
Privacy summary
- Vault contents are processed and stored in encrypted form on your device. They are not uploaded to a developer-operated server, and the developer cannot read them.
- The app does not provide online account registration, cloud synchronization or master password recovery, and does not track you through advertising or behavioral analytics services.
- System scanning, image recognition, file selection and ratings are invoked only when you choose the relevant action. An enabled default fingerprint or face method may automatically start system authentication when you enter an unlock or identity verification screen.
- The app does not obtain raw fingerprint or facial data or biometric templates. Your unlock pattern is processed locally and is not included in exported encrypted backups.
- Copying writes selected content to the device clipboard. Backups you export are not automatically deleted when you delete records or uninstall the app.
1. How we process information
The app processes only information needed for the relevant feature. To perform the service agreement between you and us, the app processes information locally that you enter or import and that is necessary for the service you select. Where processing is based on consent, we act within your authorization; separate consent must be obtained where required by law. Reading this Policy does not authorize processing unrelated to the features you use.
1.1 Local account and password management
You may enter or import record names, account names or usernames, passwords, website addresses, notes, tags and favorite status. The app uses this information locally to display, search, edit, categorize, copy and manage records, and stores necessary record identifiers, associations and creation or modification times.
Account names, usernames and account IDs refer to accounts for third-party services that you save. They do not mean you must register an online KeyNest account, and are not used for advertising or tracking across apps. A record cannot be saved without its required information; optional fields may be left blank. Website addresses are displayed locally. The app does not automatically visit them or retrieve website icons over the network.
1.2 Two-step verification codes
You may enter verification record names, accounts, issuers, secrets, algorithms, digit counts and periods manually, or import them through system scanning, a selected image or an encrypted backup. The app generates verification codes locally using the secret, generation parameters and device time, and stores the account associations you configure.
Verification secrets are important credentials for access to third-party accounts. The app does not send them to a developer-operated server or sign in to third-party services on your behalf. Codes cannot be generated without the secret and required parameters.
1.3 Master password, quick unlock and security settings
The master password is used locally to create and unlock the encrypted vault. The app stores encrypted verification material derived from the password and does not persist the plaintext master password. Unlock pattern sequences and related encrypted material are used locally for pattern enrollment and verification, and are not included in exported encrypted backups.
Fingerprint and face authentication are handled by the device system. The app uses the authentication result and security credentials returned by the system to access keys; it does not read or store raw fingerprint or facial data or biometric templates. Once a quick method is enabled, entering the relevant unlock or verification screen may start system authentication directly. You may cancel and choose another configured method.
Settings for auto-lock time, the default unlock method, pattern traces and additional verification when accessing passwords, together with necessary failed-attempt counts and retry waiting information, are stored locally for the selected security features. The master password remains available when optional quick unlock is not enabled.
To remember your agreement choice, the app stores only the confirmed Privacy Policy version, User Agreement version and confirmation time locally, without attaching a device identifier or uploading the confirmation record. Missing or invalid records cause a new prompt. Reading a document does not automatically record agreement.
1.4 Encrypted backups and editing recovery
During export, the app locally encrypts password records, verification records and their associations using the backup password you set, then saves the file to the location you select through the system file picker. During import, it accesses only the selected backup file, decrypts it locally, and lets you preview and resolve duplicate records. The plaintext backup password is not persisted as a credential.
The app may keep an encrypted editing recovery draft locally so editing can resume after locking. Drafts are not uploaded to a developer-operated server. An exported backup restores account and verification records; it does not fully duplicate all device settings, quick-unlock credentials or system authentication information.
1.5 Copying and the clipboard
Only when you choose to copy does the app write the selected account, password, verification code or other content to the system clipboard, with sharing restricted to the local device. To avoid deleting content copied later, the app reads the current clipboard and compares it with the content from this copy operation. After approximately 30 seconds, it attempts to clear the content if it has not been replaced.
Clipboard clearing may fail because of background execution limits, process termination or system restrictions. You may paste copied content into another app; please verify that the destination is trustworthy. Clipboard content is not sent to a developer-operated server or used for analytics or tracking.
1.6 Ratings and support contact
The app invokes Huawei AppGallery's system rating service only when you select the rating entry. It does not read your Huawei account details or review content from that service, and does not pass vault contents to it. Huawei processes rating information according to the rules and privacy statements shown by that service.
When you contact us by email, we process the email address, issue description and necessary attachments you voluntarily provide only to reply, verify and handle your request. Do not send your master password, account passwords, verification secrets, unlock pattern or complete backups. The email provider handles email transmission and storage under its own rules. The app does not automatically send support emails.
1.7 Feature availability and processing boundaries
The app locally checks the system API version, supported system capabilities and available authentication methods to determine which features to show or enable. The current version does not send advertising identifiers, location, contacts, behavioral analytics or crash reports to the developer, and does not provide personalized recommendations or advertising marketing.
Records you save may contain sensitive personal information. Save only information you are authorized to process, and consider authorization requirements for information about other people. These records are used only for your selected local management, verification code or backup features. Reading this Policy does not authorize their use for other purposes.
2. System features and permissions
- Biometric authentication: the app uses the system biometric capability (ohos.permission.ACCESS_BIOMETRIC) for enabled fingerprint or face unlock and identity verification. That method is not used when it is not enabled.
- Privacy window: the app uses the system privacy window capability (ohos.permission.PRIVACY_WINDOW) to limit exposure through screenshots and screen recordings. It is not used to collect personal information.
- Scanning: the system scanning interface handles camera capture and the app receives recognition results. The app does not directly request camera permission or independently capture or save camera images.
- Image selection: the app accesses the single image you select through the system photo picker to recognize a QR code. It does not request permission to read your entire photo library.
- File selection: the app accesses the backup file or save location you specify through the system file picker. It does not request broad access to device files.
Scanning, image and file selection, authentication and rating services are provided by the device system or Huawei. Those services' own information processing is governed by their interface notices and applicable privacy rules. The app does not pass unrelated vault records to them. If you cancel selection or authentication, the corresponding operation may not complete, but other available features remain usable.
4. Storage location and retention
Vault data is stored in encrypted form only on your device and is not transmitted to or stored on a developer-operated server. The device's location depends on where you use it; it is not described as the country of a developer server. The app does not provide vault cloud synchronization or proactively transfer vault data across borders.
Records are retained to provide your chosen local management features until you delete them, clear the local vault, or the system deletes app data. Necessary security settings, encrypted material and local editing recovery information support the relevant features and are handled when the local vault is cleared. Uninstalling or clearing app data may make the local vault and device credentials unrecoverable.
Backups you export remain in the location you select and are not automatically deleted when records are deleted, the vault is cleared or the app is uninstalled. To remove all copies, separately delete backups, copies held by third-party storage services and content you previously copied elsewhere.
Clipboard retention and clearing are described in Section 1.5. We retain support contact information only for the shortest period needed to handle the request and necessary follow-up, except where continued retention is required by law, in which case it is limited to the required scope and period. Copies held by email recipients and email services are handled under their respective rules.
5. Information security
The app reduces information exposure risks through local encryption, session locking, system key protection, identity verification and privacy windows. After unlocking, displaying, copying, editing or generating codes requires processing the relevant plaintext in device memory. Security measures cannot guarantee absolute protection if the device is compromised, controlled by malware or credentials are exposed.
Set a sufficiently strong master password and keep it safe. Unlock patterns generally have fewer possible combinations than strong passwords; use them carefully and combine them with device locking and other security settings. If system biometrics or device credentials become invalid, you may need the master password to unlock or configure access again.
We cannot recover your master password or backup password, or decrypt the vault for you. If an information security incident related to this app occurs, we will take response, notification and reporting measures required by applicable law. Report security issues through the contact below without sending sensitive credentials.
6. Managing your information
- Access and correction: after unlocking, view and edit records in the password vault and verification code screens.
- Deletion: delete an individual password or verification record. Deleting a password record keeps the linked verification record by default. Removing an association also keeps both records. Delete both separately if needed.
- Copying and export: copy selected content or use “Settings — Encrypted export” to export restorable account and verification records and their associations.
- Disable optional features: disable fingerprint, face or pattern quick unlock in settings. Canceling a system picker does not automatically import an image or file.
- Clear the vault: follow the prompts under “Settings — About KeyNest — Clear local data” to clear the local vault. Exported backups and content copied elsewhere must be deleted separately.
The app does not provide a developer-operated online account, so there is no online KeyNest account that needs closure through the developer. The developer cannot access, correct, export or delete your local vault on your behalf. For information we actually hold through support contact, you may contact us to request access, correction, deletion, withdrawal of consent or other rights available under law.
We will verify requests within a reasonably necessary scope, handle them promptly and explain the result. Withdrawing consent does not affect lawful processing before withdrawal. Disabling an optional feature does not affect other features that do not require that authorization. You may ask us to explain this Policy.
7. Protection of minors
The app is not designed specifically for children. Minors should read this Policy and use the app with a guardian's guidance, and carefully manage master passwords, backups and third-party accounts. Processing personal information of children under fourteen requires the guardian's appropriate consent and compliance with applicable special protection requirements.
If a guardian believes we have improperly processed a minor's information through support contact or similar activities, please contact us using the email below. We will verify and handle the matter in accordance with law. This does not mean the developer can access or remotely delete a local vault on a device.
8. Policy updates
We will update this Policy and its update date when features or information processing change. We will notify you through an in-app notice or another appropriate method of significant changes to processing purposes, methods, information categories or your rights. Where renewed consent is required by law, we will obtain it before the relevant processing.
General statements in this Policy do not automatically authorize new online, synchronization, advertising or analytics features; these require separate and accurate disclosure. You may save a copy of this Policy for reference.
9. Contact us
Personal information processor and app provider: Liu Xinhua (刘新华)
Email: flyxinhua@163.com
For questions about this Policy, information processing or your personal information rights, contact us at this email. We will respond as soon as reasonably possible and handle the matter in accordance with law. Identify the app and your issue, but do not send your master password, account passwords, verification secrets, unlock pattern or complete backups.
If you are dissatisfied with the result, you may lodge a complaint with the relevant authority or seek relief from a court with jurisdiction in accordance with law.