Privacy policy
What Kenveil collects, why, where it is kept and for how long, and the rights you have over it. No analytics, no ads, no tracking.
On this page
Who is responsible
The controller responsible for your personal data under the EU General Data Protection Regulation (GDPR) is the operator of Kenveil:
The short version
- Kenveil collects only what it needs to run your account, your license and the tools you use. The Ledger lists every item: where it is kept, how it is protected, why, and for how long.
- Your identity graph, scan history, alerts, Canary mail and removal records are encrypted with a key unique to your account. Deleting your account destroys that key.
- Scans start only from accounts you verify as yours. Kenveil does not search for anyone else.
- This website has no analytics, no ads and no tracking. It sets no cookies unless you sign in to your account.
- We do not sell your personal data, and we do not use it for advertising.
What this policy covers
This policy covers the Kenveil website, your Kenveil account, the Kenveil app for Windows, the Kenveil for Chrome extension, and support and sales in the Kenveil Discord. It explains what personal data we process, why, on which legal basis, who else receives it, how long we keep it and what rights you have.
Visiting this website
When you open a page, your browser sends the usual technical details with the request, such as your IP address, the type of browser and the page you asked for. Our server needs them to deliver the page. We do not use them to identify you or to follow you around the site, and we do not keep access logs of your visits.
The website loads nothing from other companies: no analytics, no advertising, no social media buttons, no embedded videos and no externally hosted fonts. The status indicator in the footer asks our own server whether the service is running and sends nothing about you.
Legal basis: our legitimate interest in providing a working and secure website (Art. 6(1)(f) GDPR).
Your Kenveil account
To create an account, you give us an email address and a password. We keep:
- Your email address, to sign you in and to find your account when you ask support for help.
- Your password, only as an Argon2id hash. The password itself is never stored. When you choose a new password, we check it against known breached passwords, as described under “Who else receives data”.
- Two-step sign-in, if you turn it on: the authenticator key, encrypted with your account key, and backup codes kept only as keyed hashes.
- Sessions: the approximate network (a /24 range for IPv4, a /48 range for IPv6) and a short device summary, so you can see and end your sessions. Never your full IP address or your browser’s full identification string.
- Security activity: what happened, for example a sign-in or a password change, when it happened, and the approximate network, so you can spot activity that was not you.
Legal basis: performing our contract with you (Art. 6(1)(b) GDPR). Security activity and the breached-password check rest on our legitimate interest in keeping accounts safe (Art. 6(1)(f) GDPR).
Your license and PCs
When you activate a license, we store the license key only as a hash plus its last characters. For each PC we store one-way hashes of its hardware (hashed again with a server secret), its name, its Windows version and a device key. Raw hardware values never leave your PC. We use this to recognise the PCs your license is activated on and to let the app work offline for up to 72 hours.
Legal basis: performing our contract with you (Art. 6(1)(b) GDPR).
Using the app and its tools
Kenveil works only on accounts you prove are yours. There is no way to scan anyone else: every scan starts from accounts you verified and from your own account email.
- Verified accounts and your identity graph. When you verify an account on GitHub, GitLab, Reddit, DEV or Hacker News, our server reads that account’s public profile through the platform’s official public interface. For platforms our server cannot read itself (Instagram, TikTok, X, YouTube, Twitch, Pinterest and Steam), the browser extension reads the name, bio, links and picture address of your own profile in your browser and adds them to your account. From this, Kenveil builds your identity graph: reused usernames, links between profiles, bio mentions, email addresses and public details such as a location. All of it is encrypted with your account key.
- Scan history (Exposure Replay): an encrypted snapshot of each scan, thinned out over time as described under “How long we keep data”.
- Watch alerts: the title and details of each alert, encrypted with your account key.
- Canary: each address and the site’s domain as they are, so mail can be routed, with your label encrypted. For each incoming mail we record only the sender’s domain. A text-only copy of the mail, without images or trackers, is kept encrypted for seven days so you can read it in the app, up to 200 messages.
- Removals and look-alike accounts: the data broker and your description of each removal you track in Reborn, and the look-alike handles and links that Mirror finds, encrypted with your account key.
- Relay: each connection’s name, public key and tunnel address. The private key is created on your PC and never reaches us. The relay passes your traffic on and records only counts, not the sites you visit.
- Connected browsers: which browser and extension version, with the description encrypted and the extension’s pass kept only as a keyed hash.
Some data never leaves your PC: your sign-in, device key and license lease (in Windows Credential Manager), your settings and mail progress (in the Kenveil folder of your Windows profile), and app logs, which contain event names and counts only and are kept for 14 days.
Your score is calculated automatically from your own graph to help you decide what to fix. It is not used to make decisions about you.
Legal basis: performing our contract with you (Art. 6(1)(b) GDPR).
Mailbox connections
Connecting a mailbox is optional. If you connect one, the app reads message headers over an encrypted IMAP connection, read-only and on your PC; your PC talks directly to your mail provider. Your mailbox password or sign-in stays in Windows Credential Manager and is never sent to us.
Only what the app finds reaches our server: the mailbox address, encrypted, and for each finding the sender’s domain (encrypted), a category, dates and a count. Never subjects, and never message contents.
Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time by removing the mailbox, which deletes what was found in it.
Buying a license and getting support
You can ask for help in your account on this website or in the Kenveil Discord server.
Tickets on this website. When you open a ticket in your account, we store its number, category and status, your messages and our replies, and when each was written. The subject and the messages are encrypted on our server, and our staff read and answer them in our staff console. Our Discord server only receives a notice that a ticket was opened or answered, with its number and category, never what you wrote.
The Kenveil Discord. Discord is run by Discord Inc. in the USA. When you use Discord, its own terms and privacy policy apply, and Discord processes your data as its own controller. So that our staff can answer in one place, a ticket you open in Discord is also copied to our server: your Discord name and user ID, the category, and the messages, which are encrypted there like website tickets.
Tickets from both places are deleted from our server 180 days after they are closed. Website tickets are also deleted at once when you delete your Kenveil account; for a copy of a Discord ticket, ask us and we delete it.
When you open a ticket in Discord, our staff see your Discord name and what you write, and our Discord bot records:
- the ticket’s number and category, whether it is open or closed, and when it was opened and closed;
- for a purchase, the order: the license term, the number of keys, the price, the currency and any coupon or referral code used;
- the licenses delivered to you, identified only by a short key hint, with their term and expiry, and a one-way fingerprint that ties each key to your Discord account.
When a ticket is closed, the bot sends you a transcript by direct message and deletes the ticket channel. If you post a vouch (a short review), enter a giveaway or join the affiliate programme, the bot stores your Discord user ID with it, and for affiliates also your referral code, referrals and earnings. Payments are handled by the payment service you use, under its own terms.
If you ask support to reset your password, staff look up your account by its email address and give you a one-time code that works for one hour.
Legal basis: performing our contract with you and the steps before it, including the affiliate programme (Art. 6(1)(b) GDPR); keeping order records to meet tax and accounting duties (Art. 6(1)(c) GDPR); and, for vouches and giveaways, our legitimate interest in running our community (Art. 6(1)(f) GDPR).
Buying on this website
When you buy a license on this website, we store the order: your email address (or your account, if you are signed in), what you bought, the prices, currency and any coupon, the payment method, and for crypto payments the invoice from the payment service with the coin, amount, payment address and transaction IDs. The keys we deliver are encrypted until you open them once; keys nobody opened are deleted after seven days, and afterwards your licenses live only as keyed hashes and hints, like every Kenveil license.
Crypto payments go through the payment service you choose at checkout (BTCPay Server or NOWPayments). It receives the order number and the amount, and handles the payment under its own terms and privacy policy. Kenveil never holds your wallet or its keys. For bank transfers or other manual payments, our staff match your payment to the order number by hand.
Legal basis: performing our contract with you (Art. 6(1)(b) GDPR) and keeping order records to meet tax and accounting duties (Art. 6(1)(c) GDPR). Because of those duties, deleting your account does not delete your orders; they are only unlinked from it and kept for as long as tax law requires (in Germany up to ten years).
Who else receives data
We do not sell your personal data or use it for advertising. These are the only other parties involved, and what each of them receives:
- IONOS SE, Montabaur, Germany, our hosting provider. The Kenveil server runs on IONOS infrastructure in a data centre in Spain, inside the EU. IONOS processes data only on our behalf.
- Discord Inc., USA, for support and sales in the Kenveil Discord, as described above.
- Pwned Passwords, a service of Have I Been Pwned. When you set or change a password, our server sends only the first five characters of the password’s SHA-1 hash, never the password or the full hash. The service returns the list of breached hashes that start the same way, and our server compares the rest itself. The request comes from our server, so the service never sees your IP address.
- Quad9 or Cloudflare, only if you use Relay. Your Relay connection file names a DNS resolver: Quad9 for filtered profiles, Cloudflare for plain DNS. It answers the domain names your device looks up, under its own privacy policy.
- The platforms you verify accounts on. To read public profiles, our server sends requests to GitHub, GitLab, Reddit, DEV and Hacker News. Each request contains only the public username being looked up.
We disclose data to authorities only where we are legally required to.
Transfers outside the EU
Your data is stored on our server in the EU. What you share in the Kenveil Discord is processed by Discord in the USA under Discord’s own terms. When our server looks up public profiles on platforms based outside the EU, such as GitHub or Reddit, the request contains only the public username being looked up.
How long we keep data
- Your account, license and PCs, verified accounts and graph, Watch alerts, Canary addresses and Relay connections: until you delete your account, or earlier if you remove the item yourself.
- Sessions: removed 30 days after a session ends.
- Security activity: one year.
- Scan history: every scan for a week, then one a day up to 90 days, one a week up to a year, then one a month.
- Canary inbox: seven days, at most 200 messages.
- Mailbox findings: until you remove the mailbox or delete your account.
- Connected browsers: until you disconnect the browser, change your password or sign out everywhere else.
- Support tickets: 180 days after the ticket is closed.
- Orders: for as long as tax law requires (in Germany up to ten years); keys nobody opened are deleted after seven days.
- On your PC: app logs for 14 days; everything else until you sign out, remove it in Settings or uninstall.
- Discord records: for as long as we need them to support you and to meet legal duties, such as keeping order records for tax purposes.
The Ledger has the full table, with the protection used for each item.
Cookies
The public pages of this website set no cookies. When you sign in to your account on this website, we set one strictly necessary cookie, __Host-kv_rt, which keeps you signed in. Scripts cannot read it, it is only ever sent over HTTPS to this site, and it expires after 14 days or when you sign out. Because it is strictly necessary for a service you asked for, it needs no consent, and there is no cookie banner.
Security
- Passwords are stored only as Argon2id hashes, and known-breached passwords are refused.
- Your graph, alerts, Canary mail, removals and other personal records are encrypted with AES-256-GCM under a data key unique to your account, which is itself protected by a master key.
- Two-step sign-in is available with an authenticator app and single-use backup codes.
- The tokens that keep you signed in are stored only as keyed hashes and replaced every time they are used.
- IP addresses are shortened before they are stored, and logs leave out passwords, tokens, email addresses, handles and the contents of requests.
- The app installs for your Windows user only, with no kernel drivers, no background service and no admin rights.
More detail is on the Security page.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- restrict how we process it (Art. 18);
- receive your data in a portable format (Art. 20): Settings, then Account, in the app exports it as a JSON file;
- object to processing based on our legitimate interests (Art. 21);
- withdraw your consent at any time, for example by removing a connected mailbox, without affecting what happened before (Art. 7(3));
- complain to a data protection supervisory authority, in particular in the EU country where you live or work, or where you think an infringement took place (Art. 77).
Much of this you can do yourself in the app: export or delete your data under Settings, then Account, remove accounts and mailboxes, and end sessions. For anything else, contact us using the details under “Who is responsible”. We may ask you to confirm that the account is yours before we act on a request.
Deleting your account
You can delete your account at any time under Settings, then Account. Your encrypted data on our server can only be read with a key unique to your account, and that key is stored, wrapped by our master key, with your account. Deleting the account deletes the key, so every encrypted record becomes unreadable at once. This is known as crypto-shredding. Your account’s other records, such as your email address, license and PCs, are deleted with it. Security activity records are separated from your account and removed on their normal one-year schedule.
Data on your PC stays until you sign out or uninstall; the uninstaller offers to remove your sign-in and saved data. Deleting your Kenveil account does not delete records in the Kenveil Discord; ask us in a ticket if you want those removed.
Changes to this policy
When we change this policy, we update the version number and the date at the top of this page. If a change is significant, we announce it in advance on this website and in the Kenveil Discord.