STILLKEY LEGAL
Privacy Policy
This policy explains what data Stillkey processes, why it is needed, and the choices available to you. Stillkey is designed so that vault contents are encrypted in your browser before cloud synchronization.
Effective and last updated: July 27, 2026
1. Who we are
Stillkey is an independently operated browser-based password manager. For questions about this policy or requests concerning personal data, contact txbsahom@gmail.com.
For the personal data described in this policy, Stillkey acts as the controller unless a service provider acts as an independent controller under its own terms.
2. Data we process
Account and authentication data
When you create or use an account, Firebase Authentication processes information such as your email address, account identifier, selected authentication provider, session information, IP address, and browser or device information. If you use Google Sign-In, Google may provide your name, email address, profile picture, and Google account identifier.
Encrypted vault data
Your vault may contain website or application names, usernames, email addresses, passwords, folder names, and optional images that you choose to add. Stillkey encrypts this information in your browser and sends a single encrypted vault blob to Cloud Firestore for synchronization.
Device storage and preferences
Stillkey stores an encrypted copy of your vault, your selected theme, and authentication session information in browser storage. The encrypted local vault can remain on a device after sign-out until you clear the site’s browser data.
Technical and security data
Hosting and authentication providers may process request logs, IP addresses, user-agent information, timestamps, and security signals to deliver the service, prevent abuse, and diagnose failures. Stillkey does not currently use advertising trackers or analytics tools.
3. How and why we use data
- Provide the service: create accounts, authenticate users, synchronize encrypted vaults, and respond to support or deletion requests.
- Protect the service: prevent abuse, enforce access controls, investigate failures, and maintain service integrity.
- Meet legal obligations: respond to valid legal requests and comply with applicable law.
Where the GDPR or similar laws apply, these activities are generally based on performance of our agreement with you, our legitimate interests in operating and securing Stillkey, and compliance with legal obligations. Where consent is legally required, you may withdraw it at any time without affecting earlier lawful processing.
Stillkey does not sell personal data, use vault contents for advertising, or use Google user data to train advertising or artificial-intelligence models.
4. Google Sign-In and Google user data
Google Sign-In is optional. Stillkey requests only basic authentication scopes for your identity and profile. This allows Firebase Authentication to confirm your Google account and associate it with your encrypted vault.
Stillkey does not receive your Google password and does not request access to Gmail, Google Drive, contacts, calendars, or other Google content.
Google user data is used only for account authentication, account identification, security, and providing the user-facing Stillkey service. It is shared only with providers needed to deliver those functions or when required by law.
5. Vault encryption
Vault contents are encrypted in your browser with AES-GCM. The encryption key is derived from your vault password using PBKDF2 with SHA-256 and a unique salt. Firestore receives the resulting encrypted vault blob rather than readable vault entries.
Stillkey does not store your vault password and cannot recover or read vault contents without it. For email/password accounts, changing or resetting the account password does not automatically re-encrypt an existing vault. Losing the password used to encrypt a vault can therefore make that vault permanently inaccessible.
6. Service providers and disclosures
Stillkey relies on the following providers:
- Google Firebase: authentication and storage of encrypted vault data in Cloud Firestore.
- Google: optional Google Sign-In and related account-security functions.
- Vercel: website hosting, content delivery, and operational request logs.
These providers process data under their own terms and privacy documentation. Data may also be disclosed when required by law, to protect users or the service, or as part of a reorganization where applicable safeguards are used.
7. International transfers, storage, and retention
Firebase Authentication operates from United States data centers, while Firestore and Vercel may process data through global infrastructure. Where required, service providers use contractual and legal safeguards for international transfers.
Account data and encrypted vault data are kept while your account is active or as needed to provide Stillkey. If you request deletion, we will delete the account and associated encrypted vault from active systems within a reasonable period, subject to legal obligations, security needs, and provider backup cycles. Operational logs are kept according to provider retention settings.
Encrypted data stored locally in your browser is controlled by your device. Clear the site data for stillkey.net to remove that local copy.
8. Your choices and privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to withdraw consent where processing relies on consent.
To exercise a right or request account deletion, email txbsahom@gmail.com from the address connected to your Stillkey account. We may need to verify your identity before completing a request.
If the GDPR applies, you may also complain to your local data protection authority. In Portugal, the supervisory authority is the Comissão Nacional de Proteção de Dados.
9. Security, children, and limitations
Stillkey uses browser encryption, per-user Firestore access rules, and HTTPS. No system can guarantee absolute security. Stillkey has not yet completed an independent professional security audit, so you should keep separate backups of critical credentials and use the service with care.
Stillkey is not directed to children under 16. If you believe a child has provided personal data without valid authorization, contact us so that we can investigate and delete it where appropriate.
10. Changes and contact
We may update this policy when Stillkey’s features, providers, or legal obligations change. The effective date at the top will be updated when material changes are published.
Privacy and support contact: txbsahom@gmail.com.