Privacy Policy

Last updated on September 27, 2026.

This policy explains what information keyone (“keyone,” “we” or “us”) collects when you use getkeyone.com, the keyone dashboard and the keyone API (together, the “Service”), how we use it and the choices you have.

Information we collect

  • Account information: your name, email address and password (stored by our authentication provider, never in plain text), your agency name, and the teammates you invite.
  • Workspace information: the clients, projects, budgets, limits, alert settings and webhook URLs you configure.
  • API usage: for every call made through keyone, the time, client, project, key, tool, model, token counts or results, cost and status, and the request body you send (such as prompts and parameters), with credential fields redacted. We do not store the providers’ responses.
  • Payments: wallet top-ups are processed by Stripe. We never receive or store your full card details; we keep a record of each transaction.
  • Technical information: cookies that keep you signed in, fraud-prevention cookies set by Stripe on the payment page, and request counters per key used for rate limiting. We measure page views on our website and dashboard with Simple Analytics, which does not use cookies or collect personal data. We do not use advertising or tracking cookies.

How we use it

  • To run the Service: route your calls, enforce your budgets and limits, and charge your wallet.
  • To show you spend reports, exports and controller findings, and to send alerts, receipts and account emails.
  • To keep the Service secure, prevent abuse and investigate problems.
  • To answer your support requests and meet our legal, tax and accounting obligations.

Who we share it with

AI and data providers. When you call a tool through keyone, we forward your request to that tool’s provider (for example OpenAI, Anthropic, Perplexity, Apify or DataForSEO) so it can be fulfilled. Each provider processes it under its own terms and privacy policy.

Service providers. We rely on Supabase (database and authentication), Vercel (hosting), Stripe (payments), Resend (email), Upstash (rate limiting) and Simple Analytics (privacy-first website analytics). The controller agent sends your spend findings, including client and project names, to Anthropic to write its daily summary; it does not send your requests.

We do not sell your personal information.

How long we keep it

We keep account, workspace and usage records while your account is active, and afterwards for as long as we need them for billing, legal and accounting purposes. You can ask us to delete your account and its data at any time, subject to those obligations.

Your rights

Depending on where you live, including in the European Union under the GDPR, you can ask to access, correct, export or delete your personal data, or object to or restrict how we process it. Email support@getkeyone.com and we will reply within one business day. You can also complain to your data protection authority; in France, that is the CNIL.

Security

Connections to keyone are encrypted, project keys are stored as hashes rather than in readable form, and access to your workspace is limited to your agency’s members. No system is perfectly secure, so keep your keys private and revoke any key you think has been exposed.

Changes and contact

We will update this page when our practices change and revise the date above. For any question about this policy, email support@getkeyone.com.