Last updated August 2026. Written in plain language, because privacy shouldn't need a translator.
At a glance
We store only what keeps your account working, and we never have a password to lose.
Stored
Name, email, public keys, device IDs and your login history.
Never stored
Passwords. Private keys. Plaintext recovery codes. Ever.
01
Your name, email, the public half of your passkeys, device identifiers, and a log of sign-ins and transfers. That is the complete list there is no hidden profiling.
02
Passwords. Your passkey is generated on your device and the private key never leaves it. Even recovery codes are stored only as one-way hashes, so a database leak reveals nothing usable.
03
Every session is scored by our risk engine device, location, typing rhythm and frequency. That history powers the security alerts you see, and you can read the full log on your Activity page.
04
We don't read your messages, track you across other sites, or sell data to anyone. The demo has no advertising and no third-party trackers.
05
You can revoke any session or every session at once from the Activity page. A confirmation email is sent whenever a session is signed in from an unusual place.
06
For privacy questions, reach us on the Contact page. We'll answer from a human, not a bot.