Privacy Policy
Effective Date: January 1, 2026 · Last Updated: January 1, 2026
Kevorax ("Kevorax," "we," "us," or "our") provides a project-based secrets vault that helps builders and vibe coders store API credentials, assign them to projects, and retrieve project-assigned secrets through project-scoped access controls and APIs (the "Service").
This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our website, applications, APIs, and related services. By using the Service, you agree to the practices described in this Privacy Policy.
If you do not agree with this Privacy Policy, do not use the Service.
1. Scope
This Privacy Policy applies to personal information we collect through:
- Our website
- Our hosted application
- Our APIs
- Customer support communications
- Billing and account management
- Other interactions with Kevorax related to the Service
This Privacy Policy does not apply to third-party websites, products, or services that you access through or in connection with the Service. Those third parties have their own privacy policies and terms.
2. Information We Collect
A. Information you provide directly
We may collect the following information you provide to us:
- Name
- Email address
- Login credentials
- Billing name and billing contact details
- Payment-related information provided through our payment processor
- Support requests and communications
- Account preferences and profile information
- Project names, notes, aliases, and related metadata
- Any other information you choose to submit through the Service
B. Secrets, credentials, and project data
Because Kevorax is a secrets vault, we may collect and process information you store in the Service, including:
- API keys
- Bearer tokens
- JSON credentials
- Project-scoped configuration data
- Secret names, aliases, masked previews, and related metadata
- Activity logs relating to creation, assignment, retrieval, rotation, reveal, copy, or deletion actions
We process this information solely to provide, secure, maintain, and improve the Service, subject to our Terms of Service and this Privacy Policy.
C. Automatically collected information
When you use the Service, we may automatically collect:
- IP address
- Device information
- Browser type and version
- Operating system
- Referring URLs
- Pages viewed
- Timestamps
- Approximate geolocation derived from IP address
- Log data
- API usage metadata
- Token and authentication event metadata
- Crash reports
- Diagnostic and performance data
D. Cookies and similar technologies
We may use cookies, local storage, pixels, and similar technologies to:
- Keep you signed in
- Remember preferences
- Maintain security
- Understand product usage
- Measure performance
- Improve the Service
You can usually control cookies through your browser settings, but disabling certain cookies may affect functionality.
3. How We Use Information
We may use personal information to:
- Provide, operate, and maintain the Service
- Authenticate users and secure accounts
- Encrypt, store, retrieve, and manage secrets and project assignments
- Generate and manage project tokens and access controls
- Process payments, subscriptions, renewals, and cancellations
- Provide customer support
- Communicate with you about your account, billing, updates, and service notices
- Detect, investigate, and prevent fraud, abuse, unauthorized access, and security incidents
- Monitor performance and troubleshoot issues
- Improve the Service, product experience, and website
- Comply with legal obligations
- Enforce our Terms of Service and other policies
We may also use aggregated or de-identified information for analytics, benchmarking, and product improvement, provided it cannot reasonably identify you.
4. Subscription, Billing, and Trial Information
Kevorax offers a 7-day free trial, followed by a subscription of $5 per month, unless you cancel before the trial ends.
If you subscribe, we or our payment processor may collect and process billing-related information such as:
- Billing name
- Billing email
- Payment method details
- Transaction history
- Subscription status
- Renewal dates
- Cancellation status
We do not intentionally store full payment card numbers on our own servers unless expressly stated otherwise. Payment processing is handled by our third-party payment processor (Stripe).
You may cancel your subscription at any time. If you cancel during the free trial, you should not be charged for the following monthly billing period. If you cancel after billing has started, your subscription will remain active through the end of the then-current paid period unless otherwise stated at checkout or required by law.
5. Legal Bases for Processing
If and to the extent applicable under law, we may process personal information based on:
- Your consent
- Performance of a contract with you
- Compliance with legal obligations
- Our legitimate interests, such as securing the Service, preventing fraud, improving the product, and communicating with users
6. How We Share Information
We do not sell your personal information for money.
We may share personal information with:
- Service providers that help us operate the Service, such as hosting, infrastructure, analytics, authentication, email delivery, customer support, and payment processors
- Professional advisors such as lawyers, accountants, auditors, and insurers
- Law enforcement, regulators, courts, or other parties when required by law or legal process
- Parties involved in a merger, acquisition, financing, sale of assets, reorganization, bankruptcy, or similar transaction
- Others with your direction or consent
We may also share aggregated or de-identified information that cannot reasonably identify you.
7. Data Security
We use reasonable technical, administrative, and organizational safeguards designed to protect personal information and secrets, including access controls, encryption measures, logging, and security monitoring.
However, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security.
You are responsible for safeguarding your own account credentials, project tokens, devices, and systems.
8. Data Retention
We retain personal information for as long as reasonably necessary to:
- Provide the Service
- Maintain your account
- Process subscriptions and billing
- Comply with legal obligations
- Resolve disputes
- Prevent fraud and abuse
- Enforce our agreements
We may retain backups, logs, and archived copies for a commercially reasonable period, even after account deletion, subject to legal and operational requirements.
9. Your Choices
You may be able to:
- Access and update certain account information through your account settings
- Cancel your subscription at any time
- Request deletion of your account, subject to legal and operational retention obligations
- Control cookies through your browser settings
- Opt out of certain non-essential communications by using unsubscribe links or contacting us
10. California Privacy Rights
If the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), applies to Kevorax, California residents may have rights that can include the right to know, access, correct, delete, and obtain information about how their personal information is collected, used, and disclosed, subject to legal exceptions.
If Kevorax is subject to the CCPA/CPRA, California residents may contact us at [email protected] to submit applicable privacy requests. We may need to verify your identity before responding.
If Kevorax does not meet the legal thresholds for the CCPA/CPRA, some of these rights may not apply at the present time.
11. Do Not Track
Some browsers offer a "Do Not Track" setting. Because there is not yet a universally accepted standard for responding to Do Not Track signals, Kevorax does not currently respond differently to such signals unless and until we state otherwise here.
12. International Users
Kevorax is operated from the United States. If you access the Service from outside that jurisdiction, your information may be transferred to, stored in, and processed in countries where privacy laws may differ from those in your jurisdiction.
By using the Service, you understand that your information may be processed in those jurisdictions, subject to applicable legal safeguards where required.
13. Children's Privacy
Kevorax is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without appropriate authorization, we will take steps to delete it.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last Updated" date and may provide additional notice where required by law.
Your continued use of the Service after an updated Privacy Policy becomes effective means you acknowledge the revised policy.
15. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us at:
Kevorax
[email protected]