Information we process
We process account identity, workspace membership, credential lifecycle metadata, essential session data, audit events, service logs, and messages you send to support. Pilot applications contain structured business contact and operational-fit details. Credential records are limited to identifiers, provider, environment, ownership, dates, policy intervals, and optional runbook URLs.
Information we do not request
Do not submit passwords, API keys, private keys, access tokens, certificate bodies, recovery codes, or other credential values. KeyGuardRail is a lifecycle monitor, not a secret vault.
How information is used
We use this information to operate and secure the service, calculate lifecycle status, deliver requested notifications, troubleshoot failures, prevent abuse, support users, and improve the private pilot.
Cookies and measurement
KeyGuardRail uses an essential, host-only session cookie for authentication. Public-site measurement is first-party and aggregate-only: daily page and request-flow counts contain no cookie, persistent visitor ID, raw IP address, or user-agent record. We do not sell personal information or use advertising cookies.
Retention and security
Pilot application details are retained for up to 12 months after the last interaction unless you request deletion or a longer relationship requires them. Customer retention depends on the workspace plan and operational need; backups may persist for their documented retention window. We use TLS, access controls, data minimization, and encrypted offsite backups, but no Internet service can promise absolute security.
Your choices
Workspace owners can request access, correction, export, or deletion of pilot data. Some audit or backup records may remain until their security and retention windows expire.
Contact
Questions and privacy requests can be sent to privacy@keyguardrail.com.