Privacy Policy
Last updated 15 September 2026.
Who we are
KalmPass is operated by KalmForge. For UK GDPR and EU GDPR purposes we are the data controller for the information described below. Contact: privacy@kalmpass.net.
The short version
We cannot read your vault. It is encrypted on your device with a key derived from a master password we never receive. What we hold is ciphertext plus the small amount of account data needed to run a subscription service. We do not sell data, we do not run advertising, and we do not use third-party analytics or tracking cookies.
What we collect
| Vault contents | Stored only as ciphertext. We hold no key capable of decrypting it. Lawful basis: performance of our contract with you. |
|---|---|
| Email address | Stored encrypted, plus a keyed hash used for lookup. Used to identify your account, send service and security notices, and confirm ownership. Lawful basis: contract, and our legitimate interest in securing accounts. |
| Authentication data | A peppered hash of a verifier derived from your master password, never the password itself. Optional two-factor secrets, stored encrypted. Lawful basis: contract. |
| Account activity | Sign-ins, password changes, recovery events and plan changes, with a coarse device description (for example "Chrome on Windows"), stored encrypted and shown to you in the app. Lawful basis: legitimate interest in detecting unauthorised access. |
| Billing data | If you subscribe, Stripe processes your payment and we store only their customer and subscription identifiers, encrypted. We never see your card details. Lawful basis: contract, and legal obligation for tax records. |
| Technical logs | Cloudflare processes request metadata, including IP addresses, to deliver and protect the service. Rate-limit counters store only keyed hashes of addresses, never the addresses themselves. Lawful basis: legitimate interest in security and abuse prevention. |
Cookies
One cookie: a session token, set when you sign in. It is strictly necessary to operate the service, HttpOnly, Secure and SameSite=Strict, and it expires within twelve hours. We use no analytics, advertising or tracking cookies, which is why you were not shown a banner.
Who we share it with
- Cloudflare, Inc. for hosting, database and email delivery. Data is held in Cloudflare's network; the database region is Western Europe.
- Stripe, Inc. for payment processing, subscribers only. Stripe is the controller of your payment details.
- Have I Been Pwned, only if you run a breach check, and only a five-character hash prefix, proxied through our servers so your IP is not disclosed.
We do not sell personal data, and we do not share it for advertising. International transfers to the above processors rely on the UK IDTA and EU standard contractual clauses.
How long we keep it
- Vault items: until you delete them. Trashed items are purged after 30 days.
- Account data: until you delete your account, then removed immediately.
- Activity log: 180 days.
- Sessions and email links: until they expire, then removed.
- Billing records: as long as tax law requires, typically six years.
Your rights
Under UK and EU GDPR you may request access, correction, erasure, restriction, portability, or object to processing. In practice:
- Access and portability. Settings, then Backup, exports your entire vault in a standard encrypted file, immediately and without asking us.
- Erasure. Settings, then About, then Delete account removes everything at once.
- Anything else. Email privacy@kalmpass.net and we will respond within 30 days.
Note that we cannot correct or produce a readable copy of your vault contents, because we cannot read them. You can do both yourself from within the app.
If you are unhappy with how we have handled your data you may complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EU.
Breach notification
If we suffer a breach affecting personal data we will notify the ICO within 72 hours where required, and tell affected users directly. Because vault contents are encrypted with keys we do not hold, a breach of our systems would not expose them, but we will say plainly what happened rather than minimise it.
Children
KalmPass is not directed at children under 13, and we do not knowingly hold their data.
Changes
If we change this policy materially we will email account holders before it takes effect. Previous versions are archived and available on request.