Keypeur

Privacy Policy

Last updated: 2026-07-15

Keypeur is a local-only password manager. It collects no data, transmits no data, and makes no network requests. Everything you store in Keypeur stays on your device, encrypted.

Data collection

Keypeur does not collect, transmit, sell, or share any data, personal or otherwise. There is:

This website

The points above describe the Keypeur browser extension, which collects and transmits nothing. This website (keypeur.com) is a separate surface: it uses Google Analytics to measure anonymous, aggregate traffic (pages viewed, approximate region, referring site), which relies on cookies and a random identifier stored in your browser. It tells us how many people discover Keypeur, never who they are.

Audience measurement runs only if you accept it in the consent banner: as long as you have not accepted, nothing is loaded and no request is sent to Google. Your choice, whether acceptance or refusal, is kept for six months, after which the banner asks again. You can change your mind at any time through the Manage cookies link in the footer of every page; withdrawing consent stops the measurement and deletes its cookies.

The legal basis for this measurement is your consent (Article 6(1)(a) GDPR). The data controller is the publisher of this site, a private individual acting in a non-professional capacity, reachable at contact@keypeur.com (see the legal notice). Google Analytics is operated by Google LLC in the United States; Google LLC is certified under the EU-US Data Privacy Framework, which covers this transfer.

For the data processed by this website, you have the rights of access, rectification, erasure, restriction, objection and portability, and the right to withdraw your consent at any time. To exercise them, write to contact@keypeur.com. You can also lodge a complaint with the French supervisory authority, the CNIL.

The website and the extension share no data: Google Analytics never sees your vault, your master password, or anything you store in Keypeur. The extension itself stays free of any analytics or third party, as stated above.

Where your data lives

Your vault (logins, passwords, notes, TOTP secrets, and passkeys) is stored exclusively on your device, in the browser's local extension storage, encrypted at rest. The encryption key is derived from your master password.

Your master password never leaves your device. It is never stored, never transmitted, and used only in memory to derive the encryption key. As a consequence, it is not recoverable: if you forget it, neither we nor anyone else can decrypt your vault.

Passkeys you create through Keypeur are stored in the same local vault. Their private keys are generated and used only on your device: signing happens locally and the private key never leaves the extension. No passkey data is transmitted.

Quick unlock is optional. If you turn it on, you can reopen your vault with your device's built-in unlock, such as Touch ID or Windows Hello, instead of retyping your master password. Your operating system performs the check; the extension never sees or stores any biometric data, and nothing sensitive is written to disk. Your master password always remains available as the primary way in.

Site icons shown in the extension popup are served from the browser's own local favicon cache; the extension does not fetch them from the network.

When you copy a password, the extension schedules an automatic clipboard wipe. To decide whether to wipe, it compares a one-way fingerprint of the current clipboard content against a fingerprint of what it copied; the secret itself is never stored for this purpose.

To import a two-factor (TOTP) secret by scanning an on-screen QR code, the extension captures the visible browser tab and decodes the image locally, in memory. The capture is never transmitted and is discarded once decoded.

Automatic 2FA QR detection. On pages that show signs of a two-factor-authentication setup (2FA-related keywords), and only when your vault is unlocked and contains a login for that site without a 2FA secret yet, Keypeur may examine square images on the page locally to detect a 2FA setup QR code. The pixels are processed entirely inside the extension, never leave your device, and are discarded immediately after decoding. Nothing happens if the vault is locked or no matching login exists. Nothing is saved unless you explicitly accept the banner.

Data deletion

Because all data is local, uninstalling the extension permanently deletes the vault it stores, and only that: data outside Keypeur, including exported backup files, is not affected. The deletion itself cannot be undone. If you want to keep your data, export an encrypted backup from the extension before uninstalling, and keep backups regularly as a matter of habit.

Changes to this policy

Any change to this policy will be published with the extension. Since the extension makes no network requests, no change can silently introduce data collection without a new version being released and reviewed.

Contact

Questions about this policy: contact@keypeur.com