Keylane

Privacy Policy & GDPR Notice

Last Updated: August 18, 2026

Data Controller: Livotov Labs Ltd. (ID: 202346120, EU VAT: BG202346120)

Address: P.O. Box 99, Varna 9002, Bulgaria

Contact: legal@livotov.eu | labs@livotov.eu

Or use the contact form

1. Introduction

Welcome to Keylane. Livotov Labs Ltd. (“we”, “us”, “our”) believes that privacy is a fundamental human right. We have designed the Keylane application and the keylane.app public server with a strict “Zero-Knowledge” and “Zero-Log” architecture. We cannot read your messages, we do not know who you talk to, and we do not monetize your data.

2. Information We Do NOT Collect

To be clear about what we do not possess:

  • No Personal Identifiers: We do not ask for, require, or store your phone number, email address, or real name. Your account is entirely decoupled from your real-world identity. The one exception is outside the app: if you write to us through the website contact form, you give us a name and an email address for that conversation — see Website Contact Form in section 3.
  • No Plaintext Data: All messages, files, and media are End-to-End Encrypted (E2EE) locally on your device. We do not possess the decryption keys and cannot decrypt your data under any circumstances. We never obtain message content on our own initiative, and the app never transmits it in the background. The only exception is content you choose to hand us yourself by confirming a report — see Reports You Submit in section 3.
  • No Persistent IP Logs: Our network infrastructure processes connections in memory. We do not write IP addresses, connection logs, or routing metadata to disk. Routing data is processed and discarded without persistent storage.
  • Zero Analytics & Zero Cookies: We do not use cookies on our website. We do not use third-party tracking, crash reporting, or marketing SDKs in our client applications or on our server.

3. Information We Process (And Why)

Under the General Data Protection Regulation (GDPR), our lawful basis for processing the following minimal, strictly technical data is the performance of a contract (providing you with the Keylane secure routing service), unless a different legal basis is stated below:

  • Account Data (Cryptographic IDs): When you create an account, your device generates a random cryptographic ID and public keys. We store these public keys on our server solely to allow other users to encrypt and route messages to you. You have the option to claim an unoccupied custom tag/name for your ID; this tag is stored solely for routing purposes.
  • Encrypted Message Queue: If you receive a message while offline, our server temporarily holds the encrypted blob until your device connects and downloads it. Once downloaded, it is deleted from our server. If a message is not downloaded within 14 days, it is automatically and permanently deleted.
  • Push Notification Tokens: To wake up your mobile device when you receive a message, we must process an anonymous push token provided by your operating system (Apple APNs or Google FCM). This token contains no personal data, and its only function is to ping your device to connect to our server.
  • Reports You Submit (Only When You Ask): Keylane gives you two ways to report abuse: reporting a contact from their contact screen, which sends the last 10 messages of that conversation, and reporting a single message from its long-press menu, which sends that message only. If — and only if — you confirm such a report, your device decrypts the relevant content and sends it to us, together with the reported Keylane ID and your own. Nothing is transmitted unless you confirm it; the app never gathers, scans or uploads message content on its own initiative. Our legal basis here is legitimate interest (Art. 6(1)(f) GDPR): keeping the keylane.app public infrastructure free of abuse, and enabling you to have abuse acted upon. Our moderation team may read what you forwarded solely in order to assess your report. We keep it only for as long as that assessment and any resulting enforcement require, then delete it, and we use it for no other purpose. We do not sell, publish or share it, except where the content itself must be handed to competent authorities by law.
  • Website Contact Form (Only If You Write To Us): The form at keylane.app/contact asks for your name, your email address, the platform your enquiry concerns, and your description; a security report may also carry a phone or messenger handle you supply for an urgent reply. It posts to our own function on this domain — there is no third-party form service — and that function relays it to our inbox and sends you a confirmation, both through Postmark (Wildbit LLC), our transactional email processor, under a data processing agreement. We keep no database copy of your submission: nothing you wrote is stored on our infrastructure, and your IP address is written neither to the email nor to our logs. To keep the form from being abused as a spam relay we do count submissions against two limits, one per sender and one per day; the per-sender counter is keyed by a one-way, salted hash of your IP address, holds no other data, and is deleted automatically within an hour. Our legal basis for that counter is legitimate interest in the security of our own infrastructure (Art. 6(1)(f) GDPR). Our legal basis is legitimate interest (Art. 6(1)(f) GDPR) in answering people who contact us, or the performance of a contract where your enquiry is a commercial one. What you send lives in our mailbox for as long as the correspondence and any legal retention duty require, and is used to acknowledge your message, to reply to you, and for nothing else. The acknowledgement is automatic, plain text, carries no tracking pixel, and quotes nothing you wrote back at you. We never add you to a mailing list.

4. Law Enforcement & Government Requests

Livotov Labs Ltd. is a registered Bulgarian legal entity and complies with valid legal orders from recognized European authorities. Our compliance is limited by what our architecture actually retains. If we receive a subpoena or warrant, we can only provide what we have: any encrypted blobs still sitting in the 14-day delivery queue, and the public keys associated with a specific ID. We cannot decrypt your data, and we cannot provide historical IP connection logs, since they are not persisted to disk. The one further thing we may hold is a report you submitted yourself through the in-app Report function, for as long as it is still under assessment.

5. Your GDPR Rights

Under the EU GDPR, you have the right to access, rectify, port, and erase your data. Because Keylane accounts carry no personal identifiers, you can exercise your “Right to be Forgotten” instantly, directly within the Keylane app, by selecting “Delete Account.” This action immediately and permanently purges your cryptographic ID, tag, and public keys from our infrastructure.