Privacy

Last updated 16 September 2026

What we store

Your account email, the organisations and projects you create, the names and metadata of your credentials, and the encrypted credentials themselves.

The last four characters of each secret are stored unencrypted so that a list of credentials is legible. Everything else is ciphertext.

What we do not store

We do not store the content of any response from a provider. Health checks record a status code, a latency, and an error category — never a response body.

We do not place credentials in logs, analytics, error reports, URLs, or any prompt sent to a language model.

Who can read your credentials

Row level security scopes every query to your own organisation. Administrators of MyAPIKeys do not have a mechanism for reading your credentials through the product.

The server can technically decrypt your credentials, because rotating a key at a provider and deploying it to your infrastructure both require plaintext. This trade-off is described in full on the security page.

Export and deletion

You can export your metadata and delete your credentials, projects, or entire account at any time from Settings.

Deleting a credential destroys its encrypted versions. Audit records of the actions taken against it are retained, without the secret, because an audit trail that can be edited is not an audit trail.

Contact

privacy@myapikeys.com