Privacy

An account stores your name, email address, and — for email registration — a password hash. Sign-in with Google or X stores the identity those providers return. Sessions use httpOnly cookies.

Key history stores the size, label, time, SHA-256 fingerprint, public PEM, and private PEM. Only you can read the private PEM through the application. Administrators can see account records, public keys, fingerprints, and the activity log. They cannot open your private key from the admin bench.

Verification codes are written to your in-app mailbox rather than sent through an external mail provider. Contact messages are appended to the activity log.

You may delete individual key pairs from your history. An administrator can delete an account, which removes that account’s keys, notices, and profile.