Last updated 10 October 2026
Privacy
What Keel collects, how it is protected, and the choices you have.
1.Overview
Keel is a HoardSpace product: a place to store and share secrets such as API keys and credentials. Because of that, we collect as little as we can and keep secret values encrypted. This page explains what we handle and why.
2.What we collect
- Account details. Your name and email address, and the sign-in method you use, handled through our authentication provider.
- Workspace content. Projects, environments, secret keys, encrypted secret values and their version history, members, and roles.
- Activity records. Audit events that record who did what and when. Secret values are never written to audit events.
- Messages you send us. The name, email, company, topic, and message you submit through the contact form.
- Technical data. Your network address is used briefly to rate limit requests. It is held in memory and not stored in your workspace.
3.How we use it
We use your information to:
- provide, secure, and operate Keel;
- authenticate you and enforce project roles and environment access;
- show you an audit trail of activity in your projects;
- reply to the messages you send us; and
- prevent abuse and keep the service reliable.
We do not sell your information or use it for advertising.
4.How secrets are protected
- Secret values are encrypted with AES-256-GCM before they are stored. The encryption key is kept in the server environment, not in the database.
- Values are decrypted only when an authorised person reveals, exports, or syncs them, and each of those actions is recorded without the value itself.
- Access is limited by project role and by the environments a member has been granted.
5.Service providers
We rely on a small number of providers to run Keel:
- Authentication. Clerk handles sign-in, sessions, and your account profile.
- Database hosting. Your workspace data is stored in MongoDB.
- Integrations you enable. If you connect Vercel, the secrets you choose to sync are sent to your Vercel project.
These providers process data only to deliver their part of the service.
6.Retention and deletion
You can delete secrets and projects from the dashboard at any time. Deleting a project removes its secrets, version history, members, invitations, and integration settings.
Messages sent through the contact form are kept for as long as needed to respond and follow up.
8.Your choices
You can update your profile from your account settings, remove secrets and projects yourself, and leave any project you belong to. To ask about access to, correction of, or deletion of your personal data, contact us.
9.Changes to this page
We may update this policy as Keel changes. The date at the top shows when it was last revised. Material changes will be announced in the product.
10.Contact
Questions about privacy? Send us a message and choose the security and compliance topic.