Everything Kenveil keeps: where each piece of data lives, how it is protected, why it is needed and how long it is kept.
Data
Where
Protection
Why
Kept
Email address
Kenveil server
Stored as you typed it
To sign you in and find your account when you ask support for help
Until you delete your account
Password
Kenveil server
Only an Argon2id hash. The password itself is never stored
To check your password when you sign in
Until you change it or delete your account
Two-step sign-in
Kenveil server
The authenticator key is encrypted with your account key; backup codes are kept only as keyed hashes
To check your codes when you sign in
Until you turn it off or delete your account
Sessions
Kenveil server
Approximate network (/24) and a device summary. Never your full IP address or browser string
So you can see and end sessions
Removed 30 days after a session ends
Security activity
Kenveil server
What happened (for example a sign-in or a password change), when, and the approximate network
So you can spot sign-ins and changes that weren’t you
One year
License and PCs
Kenveil server
The license key only as a hash and its last characters. Each PC as one-way hashes of its hardware (hashed again with a server secret), its name, Windows version and a device key. Raw hardware values never leave the PC
To recognise the PCs your license is activated on
Until you delete your account
Verified accounts and your identity graph
Kenveil server
Encrypted with a key unique to your account
To map and monitor your exposure
Until you remove the account or delete your Kenveil account
Profiles read in your browser
Kenveil server
Name, bio, links and picture address of your own profile on platforms Kenveil can’t read itself, encrypted with your account key
So scans include those accounts
Until you remove the account
Scan history (Exposure Replay)
Kenveil server
Encrypted with your account key
To show how your exposure changes over time
Every scan for a week, then one a day up to 90 days, one a week up to a year, then one a month
Watch alerts
Kenveil server
Title and details encrypted with your account key
To tell you what changed
Until you delete your account
Canary addresses
Kenveil server
The address and the site’s domain as they are, so mail can be routed; your label encrypted. For each mail only the sender’s domain is recorded
To tell you when an address reaches someone new
Until you delete your account
Canary inbox
Kenveil server
A text-only copy of mail to your Canary addresses (no images, no trackers), encrypted with your account key. At most 200 messages
So you can confirm sign-ups made with a Canary address
Deleted after seven days
Removals and look-alike accounts
Kenveil server
The data broker and your description of each removal, and look-alike handles and links, encrypted with your account key
To track removal requests and accounts that imitate you
Until you delete them or your account
Relay connections
Kenveil server
Each connection’s name, public key and tunnel address. The private key stays on your device
To let your devices use Relay
Until you delete your account
Connected browsers
Kenveil server
Which browser and extension version. The description (for example “Chrome 131 on Windows”) is encrypted, and the extension’s pass is kept only as a keyed hash
So the Kenveil extension can act for your account
Until you disconnect the browser, change your password or sign out everywhere else
Connected mailboxes and what was found
Kenveil server
The address, encrypted. For each finding only the sender’s domain (encrypted), a category, dates and a count. Never subjects or contents
To show your accounts, security emails and broker replies found in your mail
Until you remove the mailbox or delete your account
Orders
Kenveil server
The buyer’s email, items, prices and payment details. Keys stay encrypted until you open them once
To deliver your licenses and to meet tax and accounting duties
As long as tax law requires (up to ten years); unopened keys are deleted after 7 days. Deleting your account only unlinks orders
Support tickets
Kenveil server
Subject and messages, encrypted. For tickets you open on the website, our Discord only gets a notice without the content
So you and our support staff can sort out a problem
Deleted 180 days after the ticket is closed, or when you delete your account
Sign-in, device key and license lease
This PC
Windows Credential Manager, protected by your Windows account
To keep you signed in and let Kenveil work offline for 72 hours
Until you sign out or uninstall
Mailbox passwords and sign-ins
This PC
Windows Credential Manager, protected by your Windows account. Never sent to Kenveil
To read your mailboxes on this PC
Until you remove the mailbox or clear this PC in Settings
Settings and mail progress
This PC
The Kenveil folder in your Windows profile
To remember your choices and which mail was already read
Until you uninstall
App logs
This PC
Event names and counts only. No emails, handles, tokens or scan contents
To diagnose problems if you contact support
Rotated daily, kept for 14 days
Extension pairing
Your browser
The extension’s own storage, which websites can’t read
So the extension can act for your account
Until you disconnect the browser
Email address
Kenveil server
Protection
Stored as you typed it
Why
To sign you in and find your account when you ask support for help
Kept
Until you delete your account
Password
Kenveil server
Protection
Only an Argon2id hash. The password itself is never stored
Why
To check your password when you sign in
Kept
Until you change it or delete your account
Two-step sign-in
Kenveil server
Protection
The authenticator key is encrypted with your account key; backup codes are kept only as keyed hashes
Why
To check your codes when you sign in
Kept
Until you turn it off or delete your account
Sessions
Kenveil server
Protection
Approximate network (/24) and a device summary. Never your full IP address or browser string
Why
So you can see and end sessions
Kept
Removed 30 days after a session ends
Security activity
Kenveil server
Protection
What happened (for example a sign-in or a password change), when, and the approximate network
Why
So you can spot sign-ins and changes that weren’t you
Kept
One year
License and PCs
Kenveil server
Protection
The license key only as a hash and its last characters. Each PC as one-way hashes of its hardware (hashed again with a server secret), its name, Windows version and a device key. Raw hardware values never leave the PC
Why
To recognise the PCs your license is activated on
Kept
Until you delete your account
Verified accounts and your identity graph
Kenveil server
Protection
Encrypted with a key unique to your account
Why
To map and monitor your exposure
Kept
Until you remove the account or delete your Kenveil account
Profiles read in your browser
Kenveil server
Protection
Name, bio, links and picture address of your own profile on platforms Kenveil can’t read itself, encrypted with your account key
Why
So scans include those accounts
Kept
Until you remove the account
Scan history (Exposure Replay)
Kenveil server
Protection
Encrypted with your account key
Why
To show how your exposure changes over time
Kept
Every scan for a week, then one a day up to 90 days, one a week up to a year, then one a month
Watch alerts
Kenveil server
Protection
Title and details encrypted with your account key
Why
To tell you what changed
Kept
Until you delete your account
Canary addresses
Kenveil server
Protection
The address and the site’s domain as they are, so mail can be routed; your label encrypted. For each mail only the sender’s domain is recorded
Why
To tell you when an address reaches someone new
Kept
Until you delete your account
Canary inbox
Kenveil server
Protection
A text-only copy of mail to your Canary addresses (no images, no trackers), encrypted with your account key. At most 200 messages
Why
So you can confirm sign-ups made with a Canary address
Kept
Deleted after seven days
Removals and look-alike accounts
Kenveil server
Protection
The data broker and your description of each removal, and look-alike handles and links, encrypted with your account key
Why
To track removal requests and accounts that imitate you
Kept
Until you delete them or your account
Relay connections
Kenveil server
Protection
Each connection’s name, public key and tunnel address. The private key stays on your device
Why
To let your devices use Relay
Kept
Until you delete your account
Connected browsers
Kenveil server
Protection
Which browser and extension version. The description (for example “Chrome 131 on Windows”) is encrypted, and the extension’s pass is kept only as a keyed hash
Why
So the Kenveil extension can act for your account
Kept
Until you disconnect the browser, change your password or sign out everywhere else
Connected mailboxes and what was found
Kenveil server
Protection
The address, encrypted. For each finding only the sender’s domain (encrypted), a category, dates and a count. Never subjects or contents
Why
To show your accounts, security emails and broker replies found in your mail
Kept
Until you remove the mailbox or delete your account
Orders
Kenveil server
Protection
The buyer’s email, items, prices and payment details. Keys stay encrypted until you open them once
Why
To deliver your licenses and to meet tax and accounting duties
Kept
As long as tax law requires (up to ten years); unopened keys are deleted after 7 days. Deleting your account only unlinks orders
Support tickets
Kenveil server
Protection
Subject and messages, encrypted. For tickets you open on the website, our Discord only gets a notice without the content
Why
So you and our support staff can sort out a problem
Kept
Deleted 180 days after the ticket is closed, or when you delete your account
Sign-in, device key and license lease
This PC
Protection
Windows Credential Manager, protected by your Windows account
Why
To keep you signed in and let Kenveil work offline for 72 hours
Kept
Until you sign out or uninstall
Mailbox passwords and sign-ins
This PC
Protection
Windows Credential Manager, protected by your Windows account. Never sent to Kenveil
Why
To read your mailboxes on this PC
Kept
Until you remove the mailbox or clear this PC in Settings
Settings and mail progress
This PC
Protection
The Kenveil folder in your Windows profile
Why
To remember your choices and which mail was already read
Kept
Until you uninstall
App logs
This PC
Protection
Event names and counts only. No emails, handles, tokens or scan contents
Why
To diagnose problems if you contact support
Kept
Rotated daily, kept for 14 days
Extension pairing
Your browser
Protection
The extension’s own storage, which websites can’t read
Why
So the extension can act for your account
Kept
Until you disconnect the browser
This page mirrors the Ledger inside the app.
Never stored
What Kenveil never keeps.
Some data is safest when it is never collected. This is what Kenveil leaves out, and how.
Subjects or contents from your connected mailboxes
Your mailbox passwords (they stay on your PC)
Raw hardware serial numbersFour hardware identifiers are hashed on your PC. Only the hashes are sent, and the server hashes them again.
Relay private keysRelay keys are made on your PC. The private key goes straight into the connection file you save; the server only gets the public key.
Your full IP addressSessions and security activity keep only the approximate network: /24 for IPv4, /48 for IPv6.
Searches about anyone but youScans start only from accounts you verified and your account email. There is no field for anyone else.
Retention
How long things live.
Most of what Kenveil keeps stays until you remove it or delete your account. These expire on their own.
30days
Sessions
Removed 30 days after a session ends, with its approximate network and device summary.
Kenveil server
1year
Security activity
Sign-ins and account changes, kept for a year so you can spot anything that wasn’t you.
Kenveil server
7days
Canary inbox
Text-only copies of mail to your Canary addresses. At most 50 per address and 200 in total.
Kenveil server
14days
App logs
Rotated daily. Event names and counts only, never emails, handles, tokens or scan contents.
This PC
Scan history thins out as it ages
Each scan is saved as an encrypted snapshot for Exposure Replay. Older snapshots are thinned out, so the history stays useful without keeping everything.
First weekEvery scan
Up to 90 daysOne a day
Up to a yearOne a week
After a yearOne a month
Short-lived codes
Each of these codes proves one thing, and each runs out on a short clock whether it was used or not.
Short-lived codes and how long each stays valid
Code
Valid for
Device challengeSigned with a PC’s device key when it activates a license.
60 secondsSingle use
Two-step sign-inThe window for your authenticator code after your password.
5 minutesSingle use, 5 tries
Browser pairing codeConnects the Kenveil extension in your browser to your account.
10 minutesSingle use
Bio verification codeAdded to a profile bio to prove the account is yours.
30 minutes5 tries
Password reset codeIssued by support when you can’t sign in.
1 hourSingle use
Your data, your call
Export it, or delete it for good.
Both are in the app under Settings → Account. Neither needs a support ticket.
Export my data
One JSON file in the kenveil-export-1 format with everything the Kenveil server keeps for your account: profile, accounts, graph, scans, alerts, Canary addresses and inbox, removals, Relay connections, connected browsers and mailboxes, licenses and security history.
Mailbox passwords stay on your PC and are not included.
Settings → Account → Export my data
Delete account
Confirm with your password, and your two-step code if it is on. Your data key is deleted with your account, so every encrypted record becomes unreadable at once, and the records themselves are removed with it.
A license key you bought is released and can be used on a new account. The app also clears your sign-in and saved data from the PC you delete it on.