MoatKey Privacy Policy
Effective October 1, 2026. Updated October 5, 2026 (section 6: optional "Offer to save logins").
MoatKey is a password manager made by G3NO SYSTEMS LLC ("G3NO SYSTEMS", "we", "us"). This policy explains what we collect, what we cannot see, and what you can do about it. It covers the MoatKey browser extension for Google Chrome and Microsoft Edge and the MoatKey Android app (package com.g3nosystems.moatkey). There is no web vault. Our website is covered by the separate G3NO SYSTEMS Privacy Policy.
1. The short version
- Your master password never leaves your device. We never receive it.
- Your passwords, usernames, website addresses, notes and authenticator codes are encrypted on your device before they are sent to us. We store only the encrypted form, and we cannot read it.
- We do store some things we can read: your email address, your Castle names and members, plan details and basic facts about your records (such as when they changed). Section 4 lists all of it.
- We don't sell your data, show ads or use your data to train AI. MoatKey has no analytics or advertising SDKs. The one exception to know about is Google's on-device barcode scanner in the Android app (section 7).
- If you forget your master password and lose your recovery kit, we cannot get your data back.
2. How the encryption works
- When you create an account, your device turns your master password into an account key with Argon2id. This happens on your device.
- The account key locks (wraps) your vault key. We store only the locked version.
- Each record is encrypted on your device with XChaCha20-Poly1305 before upload.
- Castles are shared vaults. Each Castle has its own key, sealed separately for each member with a hybrid of X25519 and ML-KEM-768. We store the sealed copies and never hold a Castle key in a form that can open your data.
- When a Castle's key changes (for example after someone is removed), the owner signs the change with ML-DSA-65, and members' apps refuse a key change the owner didn't sign.
- Safety numbers let members check they have the right key for each other. Your device remembers the numbers it has seen, on your device.
No software is perfect. Our Security page describes the current state of security review.
3. Data we cannot read
We never receive these, or only ever receive them encrypted:
- your master password;
- your saved passwords, usernames and website addresses;
- secure notes and account-info contents;
- authenticator (two-factor) secrets;
- your vault key and Castle keys in usable form;
- your private sharing keys (we store them only encrypted).
4. Data we store and can read
Our servers run on Supabase (database, sign-in and server functions), hosted in the United States. We store:
Account. Your email address; a hash of a sign-in secret that your device derives from your master password with a separate one-way step (it cannot unlock your vault); and an optional display name.
Encryption envelopes. Your encrypted account-key envelope (ciphertext, salt and key-derivation settings), your public sharing keys (others use them to share with you), and your private sharing keys, encrypted.
Castles. Castle names are not encrypted, so please don't put secrets in a Castle name. We also store whether a Castle is personal or shared and what it's for (personal, family or business), who the members are and their roles, the sealed copies of the Castle key, and the owner-signed log of key changes.
Records. The encrypted record, plus a few facts about it that are not encrypted: its type (login, secure note or account info), when it was created, updated or deleted, which account created or last updated it, and a revision number.
Activity log. Events such as "record created" or "member added", with the time and the account that did it. They never include item titles or secrets.
Invitations. The invited person's email address, the role offered, the status and when the invitation expires.
Subscription. Your plan, its status, the number of seats and the end of the current billing period. For plans bought in the browser, the Stripe customer and subscription IDs that link your account to Stripe. For plans bought on Android, the Google Play product and plan, the subscription state, and a one-way hash of the purchase token (never the token itself).
Technical logs. Our hosting providers keep standard server logs (such as IP address, time and request type) for security and operations, for a limited time.
5. Data kept on your device
- Encrypted session tokens, so you stay signed in.
- A device-only memory of other members' safety numbers.
- Optional quick-unlock material if you turn it on: in the browser extension, a passkey; on your phone, the phone's secure keystore and biometrics (fingerprint or face). Your biometric data stays with your phone's operating system; we never receive it.
6. How the browser extension reads web pages
The extension reads a web page only when you ask it to save that page's login, from the right-click menu or with the Alt+Shift+S shortcut. It uses the browser's "activeTab" permission for this and has no standing access to the sites you visit. What it reads (username, password and page address) is encrypted on your device before upload.
Offer to save logins (optional, from version 0.7). If you turn on "Offer to save logins", you allow the MoatKey extension to read secure (https) web pages you visit. MoatKey looks at a page only at the moment you submit a sign-in form there: it reads the username and password you just entered and offers to save them. That login stays in your browser's memory for at most three minutes and is deleted when you save it, dismiss the offer or close the browser. Nothing is sent to us unless you press Save, and saved logins are encrypted on your device before they leave it, so we cannot read them. You can turn this off at any time in Settings, Saving logins, which also gives the website access back to your browser. The list of sites you chose "Never for this site" for is kept only on your device. This setting is off unless you turn it on.
7. Camera and QR scanning in the Android app
When you scan a two-factor setup QR code, the Android app uses your camera and Google's ML Kit barcode scanner. The code is read on your phone. Google's ML Kit library may send Google diagnostic and usage information about the scanner (for example device type, app version and performance), under Google's own terms. We don't receive the camera image. You can always type the setup key instead of scanning.
8. Payments
In the browser extension, payments are processed by Stripe. When you upgrade or manage billing, a Stripe page opens in a new tab. Stripe receives your email address, billing details and payment method. We never see or store your full card number. See Stripe's privacy policy.
In the Android app, subscriptions are sold and billed by Google Play. Google handles your payment details under its own privacy policy. To link the purchase to your MoatKey account, the app passes your MoatKey account ID to Google Play, and we check the purchase with Google.
From either, we receive only what we need to run your plan (see "Subscription" in section 4).
9. Why we use your data
- to create and run your account;
- to sync your encrypted vault between your devices;
- to let you share Castles with people you invite;
- to send account emails, such as sign-in emails and Castle invitations;
- to process your subscription;
- to keep the service secure and prevent abuse;
- to meet legal obligations.
Legal bases (EU/UK users): performing our contract with you (running the service), our legitimate interests (security and abuse prevention), and legal obligations (for example tax records).
10. What we don't do
- We don't sell or rent your personal data.
- We don't share your data for advertising.
- We don't add analytics, advertising or tracking SDKs (see section 7 for Google's scanner library).
- We don't use your data to train AI models.
11. Who we share data with
We use a small number of service providers that handle data on our behalf:
- Supabase (database, sign-in, server functions; US): everything in section 4.
- Stripe (browser payments): billing details, payment method, email address.
- Google Play (Android payments): your purchase and your MoatKey account ID, as described in section 8.
- Resend (sign-in and invitation emails): the recipient's email address and the email content. Invitation emails include the inviter's name and the Castle name, never any secret.
- Google ML Kit (Android QR scanning): scanner diagnostics, as described in section 7.
We may also disclose data if the law requires it, for example a valid court order. Even then, we can only hand over what we have: your vault contents are encrypted and we cannot decrypt them. If the company is sold or merged, your data may transfer to the new owner under this policy, and we will tell you first.
12. How long we keep data
- While your account is open, we keep your data so the service works.
- When you delete your account, we delete your account, your encrypted vault data, your keys and your Castle memberships. Database backups are overwritten on their normal schedule. Details are on the Delete your account page.
- Shared Castles: items you saved in a Castle someone else owns stay there for its other members, without your name attached.
- Billing records: Stripe, Google and we may keep billing records as long as the law requires (for example for tax).
13. Your choices and rights
- Export your vault. After re-entering your master password you can save one backup file with everything you can open. It is encrypted on your device with a backup passphrase you choose; we never receive the file or the passphrase. The browser extension can also save an unencrypted CSV for moving to another password manager, after a warning; delete that file once imported.
- Cancel your subscription at any time: in the browser through the Stripe billing page, or on Android in Google Play.
- Ask for a copy of the personal data we hold about you, or ask us to correct it.
- Delete your account in the app or by email. See Delete your MoatKey account.
Depending on where you live (for example the EU, UK or California), you may have more rights, such as objecting to processing or complaining to a data protection authority. We do not sell or share personal information as those terms are defined under California law. To make a request, email support@g3nosystems.com from the address on your account.
14. Children
MoatKey is not for children under 13. If you are under 18, you need a parent's or guardian's permission to use it. If we learn that a child under 13 has an account, we will delete it.
15. Where data is processed
G3NO SYSTEMS is based in South Carolina, USA, and MoatKey's data is stored in the United States. If you live elsewhere, your data is processed outside your country.
16. Security
We designed MoatKey so that we cannot read your vault, and we use access controls on our database. No system is perfectly secure. MoatKey has had internal review only; an independent security review has not happened yet. To report a problem, see our Security page.
17. Changes to this policy
If we change this policy, we will update the date at the top. If a change is significant, we will tell you in the app or by email before it takes effect.
18. Contact
G3NO SYSTEMS, LLC
777 Lowndes Hill Rd, Bldg 2, Ste 300 #213
Greenville, SC 29607
support@g3nosystems.com