Home FAQ · Terms · privacy@bigkeyring.com

Privacy Policy

Service: KeyRing (https://bigkeyring.com)
Effective date: July 17, 2026
Last updated: July 17, 2026

This Policy describes how KeyRing (“KeyRing,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use our website, progressive web app, and related services (the “Service”). It is written to match how the product actually works today—including key photos, matching fingerprints, optional map pins, subscriptions, and social sign-in. It is not legal advice; if you need counsel for your jurisdiction, consult a lawyer.
  1. Who we are
  2. Scope
  3. Information we collect
  4. How we use information
  5. Legal bases (EEA/UK where applicable)
  6. How we share information
  7. Service providers & subprocessors
  8. Retention
  9. Security
  10. Your rights & choices
  11. Children
  12. International transfers
  13. Cookies, local storage & similar tech
  14. Changes to this Policy
  15. Contact

1. Who we are

KeyRing is a multi-tenant web application that helps you inventory physical keys with photos, record which lock each key opens, and later identify a key by photographing it again. The Service is operated at https://bigkeyring.com.

For privacy questions, contact: privacy@bigkeyring.com.

2. Scope

This Policy applies to:

  • Accounts and workspaces you create on KeyRing;
  • Use of identify, key library, photos, map pins, billing, and related features;
  • Sign-in via email/password or social providers (e.g., Google, and other providers when enabled);
  • Communications related to the Service (e.g., support).

This Policy does not cover third-party websites or apps that we do not control (for example, Google’s own account pages during sign-in). Their privacy policies apply to their services.

3. Information we collect

We collect information in three ways: you provide it, the Service generates it, or third parties send it when you connect them.

3.1 Account & workspace information

  • Email address (required for your account).
  • Name (optional or provided by a social sign-in provider).
  • Password — if you register with email/password, we store a one-way cryptographic hash, not your plain password.
  • Workspace (tenant) name and slug — the household, property, or organization space that holds your keys.
  • Role within a workspace (e.g., owner), plan tier (free / personal / household), and account status.
  • Account timestamps (e.g., when the account or workspace was created).

3.2 Social sign-in (Google, Facebook/Meta, Apple — when enabled)

If you choose “Continue with” a provider, that provider authenticates you and may share with us:

  • Provider user ID (a unique identifier from that provider);
  • Email address;
  • Display name (if available);
  • Whether the email was marked verified by the provider (when available).

We store a link between your KeyRing user and that provider identity so you can sign in again. We do not receive or store your social network password. We only request scopes needed for sign-in (typically openid / email / basic profile).

3.3 Key inventory content (core product data)

You may store, for each key and related lock:

  • Names and labels — key name, lock name, tags, free-text notes;
  • Location text — lock location descriptions you enter;
  • Map coordinates — optional latitude/longitude and a place label if you drop a pin;
  • Usage history — last used time, use counts, optional notes when you log a use or identify a key;
  • Photos — images of keys (for matching) and optional photos of locks/doors (reference only, not used for visual matching);
  • Derived visual fingerprints (“embeddings”) — numerical descriptors computed from key photos (edge/teeth patterns, color cues, blade templates, perceptual hashes, and similar features) used to match a new photo against your library.

Important: Key photos and fingerprints can reveal physical security details (e.g., bitting patterns of keys). Treat your account credentials carefully. We design the Service so matching runs against your workspace’s library, not a public global key database.

3.4 Identify / camera sessions

  • When you use Identify, you upload a query photo of a key.
  • We process that photo to compute a temporary fingerprint and compare it to keys in your workspace.
  • Query photos used only for a single identify request are processed for matching; we do not treat them as permanent library photos unless you later save them as part of a key (if that feature is offered).
  • Match results may include confidence scores and technical channel scores shown in the UI.

3.5 Billing & subscription

If you subscribe to a paid plan:

  • We record your plan level and Stripe-related identifiers (e.g., customer ID, subscription ID) on your workspace.
  • Payment card numbers are collected and processed by Stripe, not stored as full card data on KeyRing servers.
  • Stripe may process name, email, payment method, billing address, and transaction metadata under its own terms and privacy policy.

3.6 Technical & log data

  • Standard server logs (e.g., IP address, request path, timestamp, user agent) as part of operating and securing the Service;
  • Error and diagnostic logs for reliability;
  • Application tokens (JWT) issued after login — stored in your browser (e.g., local storage) so you stay signed in.

3.7 Optional AI assistance

If enabled by us with an AI provider API key, KeyRing may send limited match context (key/lock names, location text, notes, use stats, confidence) and, in some cases, a copy of the identify photo to generate a short natural-language summary. If AI is not configured, this does not occur.

3.8 Information we do not intentionally collect

  • We do not sell your personal information.
  • We do not require government ID for standard use.
  • We do not scan your device photo library except for images you choose to upload.

4. How we use information

We use information to:

  • Provide the Service — create accounts, store your key inventory, match photos to your keys, show results, and manage workspaces;
  • Authenticate you — password verification or social sign-in, session tokens;
  • Bill and fulfill subscriptions — plan limits, checkout, webhooks from Stripe;
  • Operate and secure — prevent abuse, debug failures, maintain backups, upgrade fingerprint algorithms (re-processing stored photos when the matching model changes);
  • Improve matching quality — within your account’s data (e.g., reindexing embeddings), not by selling data to advertisers;
  • Communicate — respond to support requests; essential service notices;
  • Comply with law — where required (e.g., valid legal process).

5. Legal bases (EEA/UK where applicable)

If GDPR/UK GDPR applies, we typically rely on:

  • Contract — to provide the Service you request (account, inventory, identify, paid plans);
  • Legitimate interests — security, fraud prevention, service improvement, limited logging;
  • Consent — where required (e.g., certain optional features or cookies beyond essentials), which you may withdraw;
  • Legal obligation — when we must retain or disclose information under law.

6. How we share information

We share information only as described below:

  • With service providers who process data on our behalf (hosting, payments, auth providers, optional AI, maps) under contractual or platform terms;
  • With other members of your workspace if household/shared plans and roles allow access to that workspace’s keys and photos;
  • For legal reasons — to comply with law, enforce terms, or protect rights, safety, and security;
  • Business transfers — if we merge, sell, or reorganize, data may transfer under continued protection commitments;
  • With your direction — e.g., when you initiate Google/Facebook/Apple sign-in.

We do not sell personal information or share it for cross-context behavioral advertising as those terms are commonly defined under US state privacy laws.

7. Service providers & subprocessors

Depending on configuration and features you use, processing may involve:

Infrastructure & application hosting

The Service is hosted on cloud infrastructure (e.g., a virtual private server and related storage). Your account data, key metadata, photo files, and embeddings are stored on systems we operate or rent for that purpose. Providers process data as needed to host, backup, and network the Service.

Stripe (payments)

Paid plans use Stripe for checkout, subscription billing, and payment method handling. Stripe acts as a payment processor / merchant of record depending on configuration. See Stripe’s Privacy Policy.

Google (sign-in & optional maps)

Google OAuth / Sign-In: used when you choose Continue with Google. See Google Privacy Policy.

Google Maps (if an API key is configured): map display / pin picking may load Google Maps in your browser and transmit location-related requests per Google’s terms. If Maps is not configured, the app may fall back to OpenStreetMap / Leaflet-style mapping without Google.

Meta / Facebook (sign-in, when enabled)

Used only if Facebook Login is enabled and you choose that option. See Meta Privacy Policy.

Apple (sign-in, when enabled)

Used only if Sign in with Apple is enabled and you choose that option. See Apple Privacy Policy.

xAI / SpaceXAI-compatible API (optional AI summaries)

If configured, match summary text generation may send limited inventory fields and sometimes the identify image to an AI API (e.g., xAI). Provider policies and retention practices apply to that processing. If AI is not configured, identify still works without sending photos to an AI vendor.

OpenStreetMap / map tile providers (fallback maps)

When Google Maps is not used, map tiles and reverse-geocoding (if any) may be requested from open map providers; those providers receive standard web request data (IP, tile URLs).

8. Retention

  • Account & inventory — kept while your account/workspace is active.
  • Photos & embeddings — kept while associated keys remain in your workspace; deleted or orphaned when you delete keys/photos (subject to short-term backups).
  • Identify query images — processed for the request; not retained as library photos unless you save them.
  • Usage events — retained to show history until you delete related data or the account.
  • Billing identifiers — retained as needed for subscriptions, accounting, and legal obligations.
  • Logs — retained for a limited operational period unless needed longer for security or legal reasons.

If you request account deletion, we will delete or anonymize personal data in active systems within a reasonable period, except where we must retain information for legal, security, or dispute-resolution purposes. Backup media may lag behind live deletion for a short window.

9. Security

We implement reasonable technical and organizational measures appropriate to a small multi-tenant SaaS, including:

  • HTTPS/TLS for data in transit to the Service;
  • Password hashing (not reversible storage of passwords);
  • Bearer tokens for API authentication after login;
  • Tenant isolation in application logic (data scoped to your workspace);
  • Server-side verification of social login tokens with the identity provider.

No method of transmission or storage is 100% secure. You are responsible for protecting your password, device access, and who you invite into a shared workspace. Because key photos can be sensitive, we recommend strong unique passwords (or social sign-in), signing out on shared devices, and limiting workspace membership.

10. Your rights & choices

Depending on your location, you may have rights to:

  • Access personal data we hold about you;
  • Correct inaccurate data (much of it you can edit in-app);
  • Delete data or your account;
  • Export / portability of data you provided, where applicable;
  • Object or restrict certain processing;
  • Withdraw consent where processing is consent-based;
  • Opt out of sale/sharing — we do not sell personal information; contact us if you have a related request under state law.

In-product controls: You can edit key metadata, remove photos/keys, and log out (clearing the client token). You can permanently delete your account in the app under Plans → Account & privacy → Delete account (multi-step confirmation; irreversible). Step-by-step instructions: https://bigkeyring.com/delete-account. For other privacy requests, email privacy@bigkeyring.com from your account email.

Social accounts: You can disconnect access in your Google/Facebook/Apple account settings; you may also need to ask us to remove the linked identity on KeyRing.

Marketing: We do not run third-party ad trackers as part of the core KeyRing product described here. If that changes, we will update this Policy.

11. Children

The Service is not directed to children under 13 (or under 16 in some regions). We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.

12. International transfers

We may process and store information in the United States and other countries where we or our providers operate. If you access the Service from the EEA, UK, or other regions, your information may be transferred to countries that may not provide the same level of data protection as your home country. Where required, we use appropriate safeguards (such as standard contractual clauses or provider mechanisms).

13. Cookies, local storage & similar technologies

  • Essential authentication: After login, a session/access token is stored in the browser (e.g., localStorage) so API requests can authenticate.
  • Service worker / PWA cache: The app may cache static assets for offline shell performance; this is not used to sell advertising profiles.
  • Third-party widgets: Social login and maps may set cookies or use storage controlled by Google, Meta, Apple, or map providers when you use those features.

You can clear site data in your browser; you will need to sign in again.

14. Changes to this Policy

We may update this Policy as the Service evolves (for example, adding Facebook/Apple login, new processors, or features). We will post the updated Policy at this URL and change the “Last updated” date. Material changes may also be highlighted in the product or by email when appropriate. Continued use after the effective date of changes constitutes acceptance of the updated Policy where permitted by law.

15. Contact

Privacy requests and questions:
Email: privacy@bigkeyring.com
Web: https://bigkeyring.com

If you are in the EEA/UK and believe we have not resolved your concern, you may lodge a complaint with your local supervisory authority.

Summary (non-binding): KeyRing stores your account, key labels, optional map pins, key/lock photos, and computer-generated fingerprints so we can tell you which of your keys matches a new photo. Payments go through Stripe. Google (and optionally other providers) handle social login. Optional AI summaries may send limited text/images to an AI API. We don’t sell your data.

Return to KeyRing Terms of Service