EverKey
Privacy Policy
This policy covers the EverKey web vault (everkey-prod.web.app) and the EverKey Chrome extension (together, “EverKey”, “we”, “us”). EverKey is a zero-knowledge password manager: your vault is encrypted and decrypted on your own device, and we can’t read it.
The short version
- Your master password never leaves your device. We can’t see it, reset it or recover it.
- Everything in your vault, including item names, website addresses, usernames, passwords, notes and files, is encrypted on your device before it is sent to us.
- We store your email address and the encrypted vault, plus some metadata we need to run the service (listed below).
- No ads, no analytics or tracking tools, and we never sell your data.
What we store
Account
- Email address and whether you have verified it. We use it to sign you in, to send verification and password-reset emails, and so other EverKey users can share items with you by typing your address.
- A sign-in credential derived from your master password. Your device turns your master password into two independent keys: one to sign in and one to encrypt your vault. Only the sign-in key is sent, and our authentication provider stores it only as a salted hash. It can’t be used to decrypt your vault.
- Encrypted key material: your vault key, encrypted with your master password and separately with your recovery code, and your encrypted private key for sharing.
- Your public key, which other signed-in EverKey users can read so they can share items with you.
- Sign-in records kept by our authentication provider, such as when the account was created and when it last signed in.
Vault
- Encrypted items (logins, cards, bank accounts, identities, recovery codes, secure notes and documents) and encrypted document files. We can’t read their contents, names, types or website addresses.
- Metadata we can see: how many items you have, when each was created, last changed and last used, a revision counter, and approximate encrypted sizes (padded so they don’t reveal exact lengths).
- Encrypted contacts: public keys of people you have shared with, encrypted so we can’t read or change them.
Sharing
- When you share an item, we store a record with your email address, the recipient’s email address, which item it is (by random ID), the permission level (view or edit) and the item’s key, encrypted so only the recipient can open it. Both of you can see this record.
- To stop people from guessing which email addresses have accounts, recipient lookups are limited, and we keep a per-account count of recent lookups.
Service logs
Like any web service, our hosting and cloud providers automatically record technical request logs, such as IP address, browser type and time of request, to operate and protect the service. These logs never contain your master password or vault contents.
The Chrome extension
The extension exists so you can save and fill your logins on websites. To do that:
- It looks for login forms on pages you visit. This check runs entirely in your browser. We don’t collect your browsing history or the pages you visit.
- When you submit a login form, the username and password you typed are held in your browser’s memory for up to 2 minutes so EverKey can ask whether to save them. They are encrypted and sent to us only if you click Save.
- The website address of the current tab is used on your device to suggest matching logins. When you save a login, its address is stored inside the encrypted item.
- It fills logins only when you ask, by clicking Fill or pressing the keyboard shortcut, and only into the site the login belongs to.
- Stored in your browser: the last email address you signed in with, the sites you chose “Never for this site” on, and a sign-in token. Your unlocked vault key is kept in memory only. It is erased when you lock EverKey, when your computer’s screen locks, after 15 minutes of inactivity and when you close the browser.
- Clipboard: when you copy a password, EverKey clears the clipboard 30 seconds later.
EverKey’s use of information received through the extension follows the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this information only to provide EverKey’s password-management features, and we don’t transfer it to anyone for other purposes.
How we use your data
Only to run EverKey: to sign you in, store and sync your encrypted vault across your devices, deliver items you share, send account emails (verification and password reset) and protect the service from abuse. We don’t use it for advertising, profiling or credit decisions, and we don’t sell it.
Who processes it
EverKey runs on Google Firebase and Google Cloud, which host our servers and process data on our behalf: Authentication, Cloud Firestore, Cloud Storage, Cloud Functions and Hosting. Your vault, files and sharing records are stored in Google Cloud’s asia-south1 (Mumbai, India) region. Authentication and the delivery network that serves the website run on Google’s global infrastructure. We share data with no one else, unless the law requires it. Even then, we can only hand over what we hold, and your vault stays encrypted.
Retention and deletion
- Items you delete are removed from our database immediately, and their document files are deleted along with them.
- We keep your account data for as long as you have an account.
- To delete your account, email dreamyphobicstudio@gmail.com from the address you signed up with. Within 30 days we will delete your account, vault, files, public key and sharing records. People you shared items with lose access to them.
- Our providers may keep service logs for a limited time under their own retention policies.
Security
Vault data is encrypted on your device with XChaCha20-Poly1305. Your master password is stretched with Argon2id, and all traffic uses TLS. Because we never have your keys, we can’t recover your vault if you lose both your master password and your recovery code. No system is perfectly secure, and your data is only as safe as the device you unlock it on.
Your rights
You can see everything in your vault while it is unlocked, and change or delete it at any time. To ask what account data we hold, correct it or delete it, email dreamyphobicstudio@gmail.com. Depending on where you live, you may have additional rights under local data-protection law, and we’ll honor them.
Children
EverKey isn’t intended for children under 13, and we don’t knowingly collect data from them.
Changes
If this policy changes, we’ll post the new version here with a new effective date.
Contact
Questions about privacy: dreamyphobicstudio@gmail.com