Privacy Policy

1. Information We Collect

We collect information you provide directly, such as your name and email address when you create an account. If you sign in with Google or GitHub, we receive your name and email address from that provider.

We automatically collect usage data: pages visited, which tool was run and whether it succeeded, AI assistant usage, session duration, and general device and browser information.

When you are signed in we also store the work itself, not only the fact that it happened — Calculator operations are kept with their inputs and outputs, except that key material, PANs and PINs are replaced with a placeholder in your browser before the record is sent — those values never reach us. The HSM Simulator works differently: its host commands are logged with the request and response exactly as sent, unmasked, so a failing command can be reproduced, and its session state — including any key loaded into the simulated device — is stored so it follows you between devices. Keep test data in it: KeyLab is a conformance testing tool and must never be given production card data or live keys.

Anonymous visitors are identified by a short-lived UUID stored in the `kl_anon` cookie and an HMAC of the IP address. These are not linked to a personal identity unless you create an account, at which point past anonymous activity in the same session is associated with your user record.

We never receive or store your card details. Payments are processed by Stripe; only the resulting subscription status is kept on our servers.

2. How We Use Your Information

We use your information to: (a) provide, maintain and secure the service and your account; (b) send service-related communications such as account confirmations and security alerts; and (c) study how the tools are used and where they fail.

The third one is why we collect anything at all. KeyLab is a conformance testing tool, and almost nobody reports a wrong result — errors are found by looking at what was run and what came back. Usage records are what make that possible, and they are the reason the tools get corrected.

We never sell, rent, license or otherwise commercialise your data, in any form, to anyone. It is used to run and improve KeyLab and for nothing else.

Marketing and product-update emails are sent only if you opt in during registration. That consent is separate from the service itself — you can withdraw it or unsubscribe at any time without losing access.

3. Data Storage & Security

Your data is stored on servers located in Brazil. We use TLS for data in transit, access controls, and encrypted storage for credentials such as password hashes and tokens.

HSM command logs and HSM session state are kept exactly as sent, without masking — a redacted command cannot be replayed to reproduce the problem it was kept for. Calculator history is masked in your browser before it is sent, as described above. All three exist only for signed-in accounts.

Deleting your account deletes them with it: operation history, saved workspace material, HSM session state and the HSM command log. Anonymous usage counters survive with the link to you removed. There is no separate control for clearing history on its own; to have part of it removed, write to thiago@keylab.cloud.

4. Cookies & Analytics

Essential cookies keep you signed in (httpOnly, secure, SameSite). They are required for the service to work and are not used for analytics.

For product analytics we set `kl_anon`, an anonymous UUID, on your first visit. It lasts one year and lets us recognise a returning browser and join in-app events into one trail. We also derive an HMAC of your IP address for the same purpose. Neither carries your name or email, and neither is linked to a personal identity unless you create an account, at which point activity from the same session is associated with your user record.

Google Analytics 4 runs only when an analytics-consent flag is present in your browser storage, and never otherwise.

To clear these identifiers, delete cookies and site data for keylab.cloud in your browser, or write to thiago@keylab.cloud and we will remove the records held against them.

5. Third-Party Services

We integrate with the following third-party services: (a) Google and GitHub for optional single sign-on — if you choose to sign in with them, we receive your name and email address, subject to their respective privacy policies; (b) Google Analytics 4 for anonymised usage analytics, subject to the consent flag described above — its privacy policy applies to data collected through it; (c) Anthropic for the AI assistant, only when you actively send a message — your prompt is processed by Anthropic's API and is subject to their privacy policy; and (d) Stripe for payments — card details are entered with Stripe and never reach our servers, which keep only the resulting subscription status.

6. Your Rights (LGPD / GDPR)

Under the Brazilian General Data Protection Law (LGPD) and the European General Data Protection Regulation (GDPR), you have the right to: (a) access your personal data; (b) correct inaccurate data; (c) request deletion of your data; (d) export a copy of your data in a portable format; (e) object to or restrict processing of your data; and (f) file a complaint with a supervisory authority (ANPD in Brazil, or your local DPA in the EU).

Deleting your account, from Settings, exercises the deletion right in full and needs no request. Access, correction, export and partial removal are handled by hand: write to thiago@keylab.cloud and we will respond within 15 business days.

7. Contact

For privacy-related questions, data access requests, or to exercise any of your rights, contact us at thiago@keylab.cloud. We will respond to your request within 15 business days.

Last updated: 2026-08-25