Aelyna® Keys, home page

Privacy notice

This notice explains which data the Aelyna® Keys website, update server and customer area process (Article 13 GDPR). In short: as little as possible, and never your passwords.

Last updated: 7 October 2026.

In short

  • The vault and your passwords stay encrypted on your computer: they never reach us, not even if you have an account or Premium.
  • The website uses no cookies, analytics, advertising or third-party resources.
  • The server does not store IP addresses: it only uses them in memory, for a few minutes, against abuse.
  • Updates are counted in aggregated form; unless you turn it off, the app adds a random installation code (it identifies neither you nor your computer).
  • If you create a customer area account or buy Premium, we process your email, billing details, subscription, payments and licenses: we need them to provide the service and issue invoices.
  • Payments go through PayPal, an independent controller: we never see your card or account details.

Data controller

[TITOLARE DEL MARCHIO], [INDIRIZZO], VAT no. [P.IVA]. For any privacy question: [email protected].

When you visit the website

Like any website, the server receives your IP address and the page requested. The IP address is used only in memory to limit excessive requests (windows of a few minutes, then forgotten) and is never written to logs or databases.

Legal basis: legitimate interest in the security of the service (Article 6(1)(f) and Recital 49 GDPR). Technical logs contain only the type of request, the page in generic form, the outcome, the duration and a random request code.

When the app checks for updates

The app sends the update server the operating system, architecture, installed version, package type, channel (stable or Beta) and language. The server counts these requests per day, in aggregated form, and counts the downloads of each file per day.

These aggregated counts do not relate to identifiable people (anonymous data, Recital 26 GDPR) and only serve to know how many installations remain on old versions and which systems to support. The IP address is handled as for the website.

App installation statistics

When the app checks for updates it sends, unless you have turned the option off, a random installation identifier generated by the app (it is not derived from your computer and contains nothing that identifies you), along with the check data above. We keep this data with dates only (never the time) of the first and last check, for 13 months after the last check; individual days of activity for 90 days. We do not store your IP address, which we only use in memory for a few minutes to protect the service from abuse.

It tells us how many installations are active and how quickly security fixes are installed (legitimate interest, Article 6(1)(f) GDPR). You can object at any time by turning off Settings → Privacy and network → Send an anonymous installation identifier: the app asks the server to delete the data of that identifier. Settings also show the code, should you prefer to ask for its deletion by email.

Breached-password check

It is optional and off by default. If you turn it on and start it, the app contacts the Have I Been Pwned service directly (a third party, independent controller): only the beginning (5 characters) of each password's fingerprint is sent, shared by thousands of different passwords. The service sees the request's IP address; we see nothing.

Account, subscription and licenses

If you create an account or buy Premium, we process your email, name, country, language, the billing details you give us, the subscription status, payments (amount, date, PayPal identifiers) and the devices your license is active on. Of the devices we only know a random code generated by the app and the name you choose, if you give one: not the computer's name or system.

We use them to provide the account and Premium (contract, Article 6(1)(b) GDPR) and for tax and accounting obligations (legal obligation, Article 6(1)(c)). When you buy, we also record the date and version of the terms of sale you accepted and your request for immediate activation, as proof of the contract and of the waiver of the right of withdrawal.

Customer area

You sign in to the customer area with your email and password. We store the password only in non-reversible form (Argon2id) and, if you turn on two-step verification, the authenticator app's secret in encrypted form and the recovery codes in non-reversible form.

For each session we only record the type of browser and system (for example "Firefox on Windows") and the dates, to show you where you're signed in and let you sign sessions out; we do not record your IP address. The full license key stays encrypted until you view it the first time, for 30 days at most; after that, the database only keeps a non-reversible fingerprint.

The customer area is separate from your vault: no vault data passes through our server and your master password is never sent to us.

Payments with PayPal

Payments and subscriptions go through PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, which processes your account and payment method details as an independent controller, under its own privacy statement. When you approve the subscription you are on PayPal's website, not ours.

From PayPal we only receive what we need to manage the subscription: subscription and transaction identifiers, amounts, dates, outcomes and, possibly, the name and email of the PayPal account. We never receive or store card numbers, IBANs or PayPal credentials.

The emails we send you

We only write to you about your account: address confirmation, security (password changes, new sign-ins, two-step verification), subscription, payments, invoices and license key. They are service emails, needed for the contract: they are not newsletters and we don't use them for advertising.

We send them through [FORNITORE DELLA POSTA], our processor (Article 28 GDPR). The emails contain no remote images, tracking pixels or click-tracking links. Of each email we only keep the type of message, the date and the outcome, for 12 months; never the text or the address.

Providers and recipients

The server is hosted by [FORNITORE DELLA VPS], [SEDE DEL FORNITORE], and emails are sent by [FORNITORE DELLA POSTA], [SEDE DEL FORNITORE DELLA POSTA]: both act as processors (Article 28 GDPR). PayPal is an independent controller for payments. Billing details and invoices may be shared with the controller's accountant and with the Italian Revenue Agency (Sistema di Interscambio) to meet tax obligations. We neither sell nor share data. [TRANSFERS OUTSIDE THE EU: TO BE CHECKED WITH THE PROVIDERS]

How long

  • IP addresses: in memory only, for a few minutes.
  • Aggregated update statistics: [RETENTION PERIOD].
  • Random installation identifier: 13 months after the last update check (days of activity: 90 days), or until you turn the option off.
  • Account, customer area credentials and billing profile: as long as you have the account. An unconfirmed account is deleted automatically; an account with no subscription and no sign-ins for 3 years gets a notice and is deleted after 30 days.
  • Customer area sessions: 14 days at most. Links sent by email: only a fingerprint is kept, until 7 days after they expire.
  • Payments, billing details recorded with each payment and invoices: 10 years, as required by law (Article 2220 of the Italian Civil Code), also after the account is deleted.
  • Acceptance of the terms of sale and request for immediate activation: as long as the payments they refer to.
  • Licenses: for the life of the account and up to 1 year after they expire; freed devices: 90 days.
  • Log of emails sent (type, date and outcome only): 12 months.
  • Emails you send us: for as long as needed to answer and handle the request.

Your rights

You can ask for access, rectification, erasure, restriction, objection and portability of your data (Articles 15–22 GDPR). In the customer area you can do it yourself: download your data, correct your billing details, email and language, delete the account (with 30 days to change your mind). For anything else write to [email protected]: we answer within one month.

When you delete the account we erase your data, except what the law requires us to keep (payments and invoices). Since we keep no IP addresses for the website and updates, we will often hold no data relating to you.

You can also lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali, garanteprivacy.it) or the authority of your country.

No profiling

We make no automated decisions about you and do no profiling or targeted advertising.

Changes

If we change this notice in a significant way, account holders get an email before the changes take effect. The date of the last update is at the top of the page.