Draft — not yet reviewed by counsel. Published early because we’d rather show our thinking than hide behind a “coming soon.” Last updated July 2026.

Privacy policy

The short version, which is also the long version’s spine: nothing you type ever leaves your Mac, and nothing derived from your typing — keystrokes, shortcut usage, scores, streaks — is ever sold or shared, for any purpose. Account details like your username and email are different: we may share or sell those, but only if you separately opt in, and saying no changes nothing about how the app works. Section 5 has the whole arrangement.

1. What Keycito processes on your Mac (and we never receive)

Keycito observes keyboard events for one purpose: to check, in memory, whether a keystroke matches a known shortcut in the app you’re using. It also reads the menus of the apps you choose to track, to learn which shortcuts exist, and notices when you click a menu item that had a shortcut.

What is stored — locally, in a database on your Mac that you can open yourself:

  • Counts of shortcut use per app per day (e.g. “⌘D in Finder, 3 times today”)
  • Counts of missed shortcuts (menu clicks that had a shortcut)
  • Your learning queue, streak, and settings

What is never stored, sent, or even assembled, anywhere:

  • The text you type — no key logs, no characters, no words
  • Per-keystroke timestamps
  • Window titles, document names, file paths, or screenshots

Passwords: when you type in a password field, macOS enables Secure Input, which blocks keystroke observation for all apps at the operating-system level. Keycito cannot see password entry and never attempts to work around Secure Input.

We describe this local processing here even though we never receive any of it, because “the data stays local” is a design commitment you deserve to see written down — not a loophole to avoid explaining ourselves.

2. What syncs if you join a league (opt-in)

Keycito works fully offline with no account. If you opt into leagues, these things leave your Mac and reach our servers:

  • Account data: your email address (for sign-in), a display name you choose, and your league membership.
  • One daily score payload, exactly this — shown here verbatim and published as a schema that every release is tested against:

That payload is a hard whitelist of eight fields: five score components (usage, diversity, learning, mastery, streak), the day, the client version, and a nonce plus an Ed25519 signature used to authenticate the upload. It carries no per-shortcut data, no per-app data, and no per-hour data. Two points of honesty: the day is the finest resolution in the payload itself, but our server does record the exact time each submission arrives, to detect replays and automated abuse — so submission times are not day-only server-side. And if a future update ever needed to change this payload, this page and the published schema change with it, before the update ships.

Two further records are created when your app first registers with us:

  • A device record: the public half of your device’s signing key, the client version, the OS version, and a per-install device identifier. That identifier is deliberately persistent — it survives the app’s own “reset all state,” so a single install can’t re-register endlessly to farm prizes. It’s tied to the install rather than to you personally, but it is a stable identifier and we treat it as one.
  • A referral link, if you used one: if you join through someone’s referral, we store a permanent record joining your account to theirs, and note the referrer on your account’s fraud-check row. That is a direct, lasting account-to-account connection; it’s removed only when either account is deleted.

Registering also derives fraud-prevention hashes from the IP address your app connects from — never the raw IP. Section 3 explains exactly what that is, why, and how long we keep it.

3. Fraud and abuse prevention: IP hashes and automated limits

Leagues carry prizes, so we have to stop one person registering hundreds of fake accounts. When your app registers a device, our server reads the IP address the request comes from and, in memory, turns it into two keyed hashes (HMAC-SHA256): one that rotates every week, and one that is week-invariant, so the same network maps to the same value over time. The second is what lets us spot bulk-signup abuse.

Your raw IP address is never stored — only these hashes, and the raw value is discarded the moment they’re computed. We should be precise, though: because the hashes are keyed with a secret we hold, they are pseudonymous, not anonymous — someone with that secret could in principle test IP addresses against a hash. So we treat them as personal data, keep them for no longer than 30 days and then delete them (a scheduled database job is set up to remove expired rows), and use them for nothing but abuse detection. The lawful basis is our legitimate interest in preventing fraud (GDPR Art. 6(1)(f)); you can object to this processing at the address in section 11.

Two automated limits run on top of this, and you deserve to know they exist and how to reach a human if one catches you unfairly:

  • A signup cap: a limited number of new accounts per IP-hash per week; past that, registration returns an error. On a shared network — a university, an office, or carrier-grade NAT — this can occasionally block someone legitimate. If that’s you, email us and we’ll sort it out.
  • Automated exclusion: if our checks flag an account on more than one distinct ground within a short window, it is automatically excluded from leaderboards and prize draws, without a separate notice. We won’t publish the exact rules — that would just be a manual for gaming them — but the restriction is automated, it is reversible, and you can contest it with us, where a person reviews the appeal.

4. What we don’t do

  • We never sell or share anything you type or anything derived from your typing — keystrokes, shortcut usage, daily scores, streaks, learning progress. Not to anyone, not for any purpose.
  • We never share or sell your account data unless you have switched that on yourself — see section 5. It is off by default and stays off until you act.
  • No advertising trackers, no third-party analytics SDKs, and no cross-site or advertising fingerprinting — in the app or on this site. (The one thing we derive from your network is the keyed IP hashing in section 3: salted, single-purpose, deleted after 30 days, and never used to track you across sites or build an ad profile.) Site analytics, when enabled, are cookieless and aggregate.
  • No dark-pattern consent flows: the app asks for exactly the OS permissions it needs, explains each one first, and works (in a reduced mode) if you decline.

5. Sale and sharing of account data — only if you opt in

If you have an account, we may share or sell a narrow slice of your account data with partners — but only under an explicit opt-in that you control. Plainly:

  • What it can include: your username, email address, and whether you take part in leagues.
  • What it can never include: anything you type or anything derived from your typing — keystrokes, shortcut usage, daily scores, streaks, or learning progress. That exclusion is absolute and survives any future version of this policy.
  • Who can receive it: partners in the keyboard, productivity-software, and developer-tools space, and their marketing service providers. We will list the current categories of recipients on this page whenever sharing is active.

How the opt-in works — built to be valid consent under the GDPR (Art. 6(1)(a)) and UK GDPR, including for users in Germany:

  • It is a separate, unticked switch in the app. It is never bundled into account creation, league sign-up, or acceptance of the terms of use, and it is never a condition of any feature.
  • Saying no — or saying nothing — changes nothing. Leagues, leaderboards, and every other feature work identically either way.
  • You can withdraw at any time, in the app or by email, with effect from that moment (GDPR Art. 7(3)). We stop all further sharing and notify recipients of your withdrawal and of any erasure request (GDPR Arts. 17(2), 19).
  • Consent covers sharing from the moment you give it. Data collected before you opted in is not sold retroactively.
  • We never sell or share data of anyone under 16 (accounts require 16+), and waitlist emails are never sold or shared, ever.
  • If a recipient is outside the UK or the European Economic Area, the transfer is covered by an adequacy decision or standard contractual clauses.

One clarification about country: Keycito doesn’t hold a country for your account, and country is never part of what can be shared or sold. The only place we collect a country is from prize winners, who provide it so we can actually deliver or ship the prize — and it’s used for that fulfilment alone.

6. Who processes your data on our behalf

We don’t run all of our own infrastructure, so a few carefully chosen providers process account, device, and waitlist data as our processors. They act on our instructions and may not use your data for their own purposes:

  • Supabase — our database, authentication, and server-side functions. Everything in sections 2, 3, and 5 (account data, the daily score, the device record, the IP hashes, referral links) lives here.
  • Vercel — hosts this marketing site and runs the waitlist sign-up endpoint.
  • Resend — sends waitlist mail; it receives the email address you give the waitlist so it can deliver the welcome message.

7. Your rights and controls

  • Local data: it’s yours, on your machine. Deleting the app and its data folder removes everything; there is no server copy of your shortcut activity.
  • Account deletion: request it in-app or by email; we delete your account and everything attached to it — scores, league membership, device records, referral links, and fraud-check rows — within 30 days. Deletion cascades completely; nothing is kept behind.
  • Export: you can request a copy of the account data we hold — your profile, display name, league membership, daily scores, referrals, and device records. In keeping with GDPR Art. 15(4), this export deliberately leaves out our fraud-detection signals (the flag/anomaly records and the signup IP hashes) and doesn’t reveal whether an account has been automatically excluded, because handing those over would help bad actors evade the checks that protect prize draws. Everything else we hold is included.
  • Consent withdrawal: if you opted into account-data sharing (section 5), you can withdraw in the app or by email at any time; withdrawal is as easy as opting in was.
  • EU/UK users: you additionally have rights of access, rectification, portability, and objection under the GDPR (including objecting to the fraud-prevention processing in section 3); the same mailbox handles all of them within 30 days. You also have the right to complain to your supervisory authority — the ICO in the UK, or in Germany the data-protection authority of your state (Land).

8. Waitlist emails

If you join the waitlist, we store your email address to send you an invite and occasional build updates. To stop one person or bot flooding the form, the sign-up endpoint also keeps a salted hash of your IP address for rate-limiting — never the raw IP — for no longer than one day. Your email is passed to Resend (section 6) to send the welcome mail.

Every email has a working unsubscribe link. To be accurate about what it does: unsubscribing marks your entry as unsubscribed and stops all mail, but it keeps the row, so we don’t accidentally re-add you. If you’d rather your waitlist email were actually deleted than just silenced, email us and we’ll remove it — no “preference centers,” no re-adds.

9. Age

Accounts (needed only for leagues) require you to be 16 or older. We store only a plain yes/no that you confirmed you meet that age — never a birth date. The local-only app has no age gate because it collects nothing.

10. Changes

If this policy changes materially, we’ll say so plainly on this page with a dated changelog — not bury it. The payload shown in section 2 is a standing commitment: it changes only alongside the published schema, never silently.

July 2026: replaced the earlier blanket “we never sell or share your personal data” commitment with the opt-in framework for account data in section 5. What changed: account details (username, email, league membership) can now be shared or sold, but only with your separate, revocable opt-in consent. What did not change: anything you type, and anything derived from your typing, is never sold or shared — and waitlist emails are never sold or shared.

July 2026 (transparency update): expanded this policy to describe processing that always happened but wasn’t spelled out — the device record and referral links that sync with a league (section 2), the fraud-prevention IP hashing and automated limits (section 3), the providers who process data for us (section 6), and the honest limits of the data export (section 7). We also corrected two earlier overstatements: account data never included a “country” field (country is collected only from prize winners, for fulfilment), and submission times are recorded server-side for abuse detection, not kept only to the day. None of this changed what the app does; it changed what we disclose.

11. Contact

Privacy questions and requests, including deletion requests: jkdev222@gmail.com. A person reads it, usually within a day.

Keycito is currently run by its founder as an individual, not a company. The responsible legal entity will be named here when the operating company is formed, which happens before any paid features go live.