Privacy Policy

What Keystring collects, why we use it, who receives it, and the choices you have.

Effective and last updated 27 August 2026

Who we are

Keystring is operated by Damiano Carradori, Via Antonio Milani 19, 37124 Verona, Italy. For the processing described in this policy, Damiano Carradori is the data controller unless this policy explains that Keystring is processing information on an organization's behalf.

Questions, requests, and legal notices can be sent to legal@keystring.dev.

Scope and our roles

This policy applies to keystring.dev, the Keystring web application, transactional emails, and the hosted MCP endpoint. Keystring is built for business use by people aged 18 or older and is not directed to children.

We act as controller for account identity, authentication, service administration, security, waitlist communications, billing, and legal compliance. An organization controls what its members put into its projects. If project content contains personal data, the organization normally determines why that data is used and Keystring processes it to provide the service on the organization's behalf. Requests about personal data in project content should usually be directed to that organization first.

Data we process

  • Account and identity data: name, email address, Google account identifier, profile image, email-verification state, and OAuth account information supplied during Google sign-in.
  • Session and device data: session identifiers, login and expiry times, IP address, user agent, active organization, and authentication-security state.
  • Organization and collaboration data: organization names, slugs and logo URLs, memberships, roles, invitation email addresses, invitation status, and inviter details.
  • Project content: project and file names, language choices, JSON keys, translation values, import/export content, timestamps, and identifiers of members who created or updated content.
  • API and MCP data: API-key name, prefix, one-way hash, creation and last-used times, and the content and parameters needed to perform MCP requests. The full API token is displayed once when created and is not stored in recoverable form by Keystring.
  • Waitlist and communications data: the account name and email copied when a member joins the Simple-plan waitlist, membership in that waitlist, invitation and welcome-email delivery details, and information you send when contacting us.
  • Billing data when paid billing launches: organization and Stripe customer identifiers, subscription and price identifiers, subscription status, current-period end, and cancellation state. Stripe receives and handles payment credentials; Keystring does not store complete card details.
  • Operational data: request, error, and security logs that may contain timestamps, technical identifiers, and limited request context needed to diagnose or protect the service.

We receive this data from you, your Google account, other members who invite or collaborate with you, your MCP client, and Stripe after paid billing becomes available.

How and why we use data

PurposeLegal basis
Create accounts, authenticate users, provide organizations, projects, editing, import/export, email, API keys, and MCP access.Performance of our contract and steps requested before entering that contract.
Secure, troubleshoot, maintain, and improve the reliability of the service; prevent abuse; and support users.Our legitimate interests in operating a safe, dependable, and useful service, balanced against your rights.
Record your Simple-plan interest and contact you when the plan opens.Your affirmative request when joining the waitlist. You can withdraw that request at any time.
Process subscriptions, payments, accounting, tax, disputes, and fraud prevention after billing launches.Contract performance, legitimate interests, and compliance with legal obligations.
Respond to lawful requests and establish, exercise, or defend legal claims.Legal obligations and legitimate interests.

Cookies and local storage

Keystring currently uses only storage needed to authenticate users, protect the sign-in flow, and remember interface preferences. We do not use advertising, profiling, or analytics trackers. Because these technologies are technical or strictly necessary, we disclose them here rather than showing a consent banner.

StoragePurposeDuration
Better Auth session cookieKeeps you signed in and carries the session identifier.Up to 7 days, or removed on sign-out.
OAuth state cookieProtects and completes the Google OAuth redirect.Up to 10 minutes.
sidebar_state cookieRemembers whether the application sidebar is expanded.7 days.
Theme preference in local storageRemembers system, light, or dark appearance.Until you change it or clear browser storage.

If we add non-essential analytics, advertising, or profiling tools, we will update this policy and introduce consent controls where required. More detail is available in the Italian Garante's cookie guidance.

Who receives data

We disclose data only as needed for the purposes above:

  • Google provides identity and OAuth sign-in.
  • Neon hosts the PostgreSQL database containing account, organization, project, and billing records.
  • Resend sends welcome and organization-invitation emails and, when used, waitlist or service communications.
  • Stripe will process checkout, payment, subscription, and billing-portal activity when paid billing is enabled.
  • Hosting and infrastructure providers process data needed to serve and protect Keystring.
  • Organization members can see and change shared project content according to their access. Owners and administrators can manage members, invitations, project settings, and billing.
  • Authorities and advisers may receive data when required by law or reasonably necessary to protect rights, users, or the service.

We do not sell personal data or share it for cross-context behavioral advertising.

International transfers

Some providers may process data outside Italy or the European Economic Area. Where the receiving country is not covered by an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where required, supplementary measures. You can contact us for information about the safeguard relevant to a particular transfer.

How long we keep data

We keep personal data only for as long as necessary for the purpose for which it was collected, including providing the service, resolving disputes, enforcing agreements, and meeting legal obligations.

  • Account and organization records remain while the account or organization is active and for a limited period needed to complete deletion requests or legal obligations.
  • Project content remains until an authorized member deletes a project or organization, or the organization requests deletion.
  • API-key records remain until the key is revoked or the account is deleted.
  • Waitlist data remains until Simple launches, you withdraw from the waitlist, or it is no longer needed to contact interested users.
  • Billing and transaction records may be retained for the periods required by tax, accounting, anti-fraud, and legal rules.
  • Security and operational logs are retained for a limited period proportionate to troubleshooting and abuse-prevention needs.

Deletion from active systems may not immediately remove data from restricted backups; backup copies age out under the applicable backup schedule and are not used for ordinary product activity.

Your rights

Subject to the conditions in the GDPR, you may ask to access, correct, erase, restrict, or receive a portable copy of your personal data, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.

Send requests to legal@keystring.dev. We may need to verify your identity and clarify whether a request concerns your Keystring account or data controlled by an organization. You can also complain to the Garante per la protezione dei dati personali or another competent supervisory authority.

Security

We use technical and organizational measures designed to protect data, including database-backed sessions, restricted organization access, one-way API-key hashing, and signed Stripe webhooks when billing is enabled. No online service can guarantee absolute security. Keep Google and API-key credentials confidential, revoke exposed keys promptly, and contact us if you suspect unauthorized access.

Changes and contact

We may update this policy when the service, providers, or legal requirements change. Material updates will be communicated through the service or by email when appropriate. The effective date above shows when this version began to apply.

Damiano Carradori
Via Antonio Milani 19
37124 Verona, Italy
legal@keystring.dev

The transparency requirements that inform this notice are set out in Articles 12–14 of the General Data Protection Regulation.