Who we are
Keystring is operated by Damiano Carradori, Via Antonio Milani 19, 37124 Verona, Italy. For the processing described in this policy, Damiano Carradori is the data controller unless this policy explains that Keystring is processing information on an organization's behalf.
Questions, requests, and legal notices can be sent to legal@keystring.dev.
Scope and our roles
This policy applies to keystring.dev, the Keystring web application, transactional emails, and the hosted MCP endpoint. Keystring is built for business use by people aged 18 or older and is not directed to children.
We act as controller for account identity, authentication, service administration, security, waitlist communications, billing, and legal compliance. An organization controls what its members put into its projects. If project content contains personal data, the organization normally determines why that data is used and Keystring processes it to provide the service on the organization's behalf. Requests about personal data in project content should usually be directed to that organization first.
Data we process
- Account and identity data: name, email address, Google account identifier, profile image, email-verification state, and OAuth account information supplied during Google sign-in.
- Session and device data: session identifiers, login and expiry times, IP address, user agent, active organization, and authentication-security state.
- Organization and collaboration data: organization names, slugs and logo URLs, memberships, roles, invitation email addresses, invitation status, and inviter details.
- Project content: project and file names, language choices, JSON keys, translation values, import/export content, timestamps, and identifiers of members who created or updated content.
- API and MCP data: API-key name, prefix, one-way hash, creation and last-used times, and the content and parameters needed to perform MCP requests. The full API token is displayed once when created and is not stored in recoverable form by Keystring.
- Waitlist and communications data: the account name and email copied when a member joins the Simple-plan waitlist, membership in that waitlist, invitation and welcome-email delivery details, and information you send when contacting us.
- Billing data when paid billing launches: organization and Stripe customer identifiers, subscription and price identifiers, subscription status, current-period end, and cancellation state. Stripe receives and handles payment credentials; Keystring does not store complete card details.
- Operational data: request, error, and security logs that may contain timestamps, technical identifiers, and limited request context needed to diagnose or protect the service.
We receive this data from you, your Google account, other members who invite or collaborate with you, your MCP client, and Stripe after paid billing becomes available.
How and why we use data
| Purpose | Legal basis |
|---|---|
| Create accounts, authenticate users, provide organizations, projects, editing, import/export, email, API keys, and MCP access. | Performance of our contract and steps requested before entering that contract. |
| Secure, troubleshoot, maintain, and improve the reliability of the service; prevent abuse; and support users. | Our legitimate interests in operating a safe, dependable, and useful service, balanced against your rights. |
| Record your Simple-plan interest and contact you when the plan opens. | Your affirmative request when joining the waitlist. You can withdraw that request at any time. |
| Process subscriptions, payments, accounting, tax, disputes, and fraud prevention after billing launches. | Contract performance, legitimate interests, and compliance with legal obligations. |
| Respond to lawful requests and establish, exercise, or defend legal claims. | Legal obligations and legitimate interests. |
International transfers
Some providers may process data outside Italy or the European Economic Area. Where the receiving country is not covered by an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where required, supplementary measures. You can contact us for information about the safeguard relevant to a particular transfer.
How long we keep data
We keep personal data only for as long as necessary for the purpose for which it was collected, including providing the service, resolving disputes, enforcing agreements, and meeting legal obligations.
- Account and organization records remain while the account or organization is active and for a limited period needed to complete deletion requests or legal obligations.
- Project content remains until an authorized member deletes a project or organization, or the organization requests deletion.
- API-key records remain until the key is revoked or the account is deleted.
- Waitlist data remains until Simple launches, you withdraw from the waitlist, or it is no longer needed to contact interested users.
- Billing and transaction records may be retained for the periods required by tax, accounting, anti-fraud, and legal rules.
- Security and operational logs are retained for a limited period proportionate to troubleshooting and abuse-prevention needs.
Deletion from active systems may not immediately remove data from restricted backups; backup copies age out under the applicable backup schedule and are not used for ordinary product activity.
Your rights
Subject to the conditions in the GDPR, you may ask to access, correct, erase, restrict, or receive a portable copy of your personal data, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.
Send requests to legal@keystring.dev. We may need to verify your identity and clarify whether a request concerns your Keystring account or data controlled by an organization. You can also complain to the Garante per la protezione dei dati personali or another competent supervisory authority.
Security
We use technical and organizational measures designed to protect data, including database-backed sessions, restricted organization access, one-way API-key hashing, and signed Stripe webhooks when billing is enabled. No online service can guarantee absolute security. Keep Google and API-key credentials confidential, revoke exposed keys promptly, and contact us if you suspect unauthorized access.
Changes and contact
We may update this policy when the service, providers, or legal requirements change. Material updates will be communicated through the service or by email when appropriate. The effective date above shows when this version began to apply.
Damiano CarradoriVia Antonio Milani 19
37124 Verona, Italy
legal@keystring.dev
The transparency requirements that inform this notice are set out in Articles 12–14 of the General Data Protection Regulation.