Skip to content
Legal

Privacy Policy

Last updated June 1, 2026

MoolKey is a deterministic, stateless password and PIN manager. The whole product is designed around a single idea: the less we hold, the less there is to leak. Your Master Key and every password or PIN it derives are computed on your device and never transmitted to us. This policy explains the account metadata and security records that we do process.

The short version

  • We never receive your Master Key or any generated password or PIN.
  • Account email or phone identifiers are masked on your device before they leave it; your login email is stored for authentication.
  • We don’t sell your data or run advertising or retargeting campaigns.
  • The marketing site may use Google Analytics 4 and Microsoft Clarity for aggregate usage and UX measurement. Analytics events contain page and interaction metadata only; passwords, PINs, passphrases, identifiers, hashes, and generated credentials are never sent.
  • Derivation works fully offline — when it does, no request is sent at all.

What we store

When you use the hosted MoolKey backend with an account, we store only the minimum needed to authenticate you and sync your account metadata:

  • Your login email address.
  • A bcrypt hash of your login password (never the password itself).
  • Masked identifiers, e.g. milxxxxxxxary@gmail.com.
  • Canonical app names you’ve saved, such as google or github.
  • A per-account version integer and password length.
  • For couple sharing: a link between two accounts, and a flag marking which accounts are shared.
  • Partner notifications, created and updated timestamps, audit records, and session-security data.

What we never store

  • Your Master Key.
  • Your Shared Key.
  • Any generated password or PIN.
  • The plaintext of your MoolKey login password.
  • Anything secret-shaped inside session tokens or audit logs.
  • Secrets in localStorage, caches, or on disk.

There is no encrypted vault of generated credentials. MoolKey recreates passwords and PINs from inputs you already know instead of decrypting a stored list.

Couple sharing keeps this promise. When you share an account with a partner, both of you derive it from a Shared Key you agree on and type yourselves. We store the link between your two accounts and a shared on/off flag, not the Shared Key or generated credential.

How we use what we store

We process the limited data above to:

  • Authenticate you and keep your session secure.
  • Sync the account metadata that lets you re-derive the right password on any device.
  • Operate, maintain, and protect the service against abuse and fraud.
  • Comply with legal obligations where they apply.

Our lawful bases (where the GDPR applies) are performance of our contract with you, our legitimate interest in operating a secure service, and compliance with legal obligations.

Marketing analytics

The marketing site is delivered through Google Tag Manager. Its configured Google Analytics 4 tags measure page views, navigation, content selection, tool usage, and visits to the separate MoolKey app. Microsoft Clarity may measure clicks, scrolling, page performance, and session behavior on all marketing and free-tool pages.

Clarity input and output areas are explicitly masked, including the homepage demonstration and every password, PIN, passphrase, strength-check, breach-check, and generated-value area. Masked content is not uploaded to Clarity. Analytics tags should be configured with the applicable consent requirements for the visitor’s location.

Cookies

The hosted app uses strictly necessary cookies for authentication and security. The marketing site may also use analytics cookies or similar storage when the configured GA4 and Clarity tags are allowed. We do not use advertising or retargeting cookies. See ourCookie Policy for the details.

Data retention

Account metadata is retained for as long as your account is active. When you delete your account, we remove the associated metadata from production systems promptly and from backups within 30 days. Security and audit logs are retained for a limited period for fraud prevention and then deleted.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your data, and to object to or restrict certain processing. Because we hold so little, most of this is self-service from the operator console — but you can always reach us athello@moolkey.com and we’ll help.

Children

MoolKey is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data.

International transfers

We may process the limited metadata described above in countries other than your own. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.

Changes to this policy

We’ll update this page when our practices change and revise the “last updated” date above. Material changes will be communicated through the app or by email.

Contact

Questions about privacy? Emailhello@moolkey.com.