MoolKey is a deterministic, stateless password and PIN manager. The whole product is designed around a single idea: the less we hold, the less there is to leak. Your Master Key and every password or PIN it derives are computed on your device and never transmitted to us. This policy explains the account metadata and security records that we do process.
The short version
- We never receive your Master Key or any generated password or PIN.
- Account email or phone identifiers are masked on your device before they leave it; your login email is stored for authentication.
- We don’t sell your data or run advertising or retargeting campaigns.
- The marketing site may use Google Analytics 4 and Microsoft Clarity for aggregate usage and UX measurement. Analytics events contain page and interaction metadata only; passwords, PINs, passphrases, identifiers, hashes, and generated credentials are never sent.
- Derivation works fully offline — when it does, no request is sent at all.
What we store
When you use the hosted MoolKey backend with an account, we store only the minimum needed to authenticate you and sync your account metadata:
- Your login email address.
- A bcrypt hash of your login password (never the password itself).
- Masked identifiers, e.g.
[email protected]. - Canonical app names you’ve saved, such as
googleorgithub. - A per-account version integer and password length.
- For couple sharing: a link between two accounts, and a flag marking which accounts are shared.
- Partner notifications, created and updated timestamps, audit records, and session-security data.
What we never store
- Your Master Key.
- Your Shared Key.
- Any generated password or PIN.
- The plaintext of your MoolKey login password.
- Anything secret-shaped inside session tokens or audit logs.
- Secrets in
localStorage, caches, or on disk.
There is no encrypted vault of generated credentials. MoolKey recreates passwords and PINs from inputs you already know instead of decrypting a stored list.
Couple sharing keeps this promise. When you share an account with a partner, both of you derive it from a Shared Key you agree on and type yourselves. We store the link between your two accounts and a shared on/off flag, not the Shared Key or generated credential.
How we use what we store
We process the limited data above to:
- Authenticate you and keep your session secure.
- Sync the account metadata that lets you re-derive the right password on any device.
- Operate, maintain, and protect the service against abuse and fraud.
- Comply with legal obligations where they apply.
Our lawful bases (where the GDPR applies) are performance of our contract with you, our legitimate interest in operating a secure service, and compliance with legal obligations.
Marketing analytics
The marketing site is delivered through Google Tag Manager. Its configured Google Analytics 4 tags measure page views, navigation, content selection, tool usage, and visits to the separate MoolKey app. Microsoft Clarity may measure clicks, scrolling, page performance, and session behavior on all marketing and free-tool pages.
Clarity input and output areas are explicitly masked, including the homepage demonstration and every password, PIN, passphrase, strength-check, breach-check, and generated-value area. Masked content is not uploaded to Clarity. Analytics tags should be configured with the applicable consent requirements for the visitor’s location.
Cookies
The hosted app uses strictly necessary cookies for authentication and security. The marketing site may also use analytics cookies or similar storage when the configured GA4 and Clarity tags are allowed. We do not use advertising or retargeting cookies. See ourCookie Policy for the details.
Data retention
Account metadata is retained for as long as your account is active. When you delete your account, we remove the associated metadata from production systems promptly and from backups within 30 days. Security and audit logs are retained for a limited period for fraud prevention and then deleted.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your data, and to object to or restrict certain processing. Because we hold so little, most of this is self-service from the operator console — but you can always reach us at[email protected] and we’ll help.
Children
MoolKey is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data.
International transfers
We may process the limited metadata described above in countries other than your own. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
Changes to this policy
We’ll update this page when our practices change and revise the “last updated” date above. Material changes will be communicated through the app or by email.
Contact
Questions about privacy? Email[email protected].