KalmPass

Privacy Policy

Last updated 15 September 2026.

Who we are

KalmPass is operated by KalmForge. For UK GDPR and EU GDPR purposes we are the data controller for the information described below. Contact: privacy@kalmpass.net.

The short version

We cannot read your vault. It is encrypted on your device with a key derived from a master password we never receive. What we hold is ciphertext plus the small amount of account data needed to run a subscription service. We do not sell data, we do not run advertising, and we do not use third-party analytics or tracking cookies.

What we collect

Vault contents Stored only as ciphertext. We hold no key capable of decrypting it. Lawful basis: performance of our contract with you.
Email address Stored encrypted, plus a keyed hash used for lookup. Used to identify your account, send service and security notices, and confirm ownership. Lawful basis: contract, and our legitimate interest in securing accounts.
Authentication data A peppered hash of a verifier derived from your master password, never the password itself. Optional two-factor secrets, stored encrypted. Lawful basis: contract.
Account activity Sign-ins, password changes, recovery events and plan changes, with a coarse device description (for example "Chrome on Windows"), stored encrypted and shown to you in the app. Lawful basis: legitimate interest in detecting unauthorised access.
Billing data If you subscribe, Stripe processes your payment and we store only their customer and subscription identifiers, encrypted. We never see your card details. Lawful basis: contract, and legal obligation for tax records.
Technical logs Cloudflare processes request metadata, including IP addresses, to deliver and protect the service. Rate-limit counters store only keyed hashes of addresses, never the addresses themselves. Lawful basis: legitimate interest in security and abuse prevention.

Cookies

One cookie: a session token, set when you sign in. It is strictly necessary to operate the service, HttpOnly, Secure and SameSite=Strict, and it expires within twelve hours. We use no analytics, advertising or tracking cookies, which is why you were not shown a banner.

Who we share it with

We do not sell personal data, and we do not share it for advertising. International transfers to the above processors rely on the UK IDTA and EU standard contractual clauses.

How long we keep it

Your rights

Under UK and EU GDPR you may request access, correction, erasure, restriction, portability, or object to processing. In practice:

Note that we cannot correct or produce a readable copy of your vault contents, because we cannot read them. You can do both yourself from within the app.

If you are unhappy with how we have handled your data you may complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EU.

Breach notification

If we suffer a breach affecting personal data we will notify the ICO within 72 hours where required, and tell affected users directly. Because vault contents are encrypted with keys we do not hold, a breach of our systems would not expose them, but we will say plainly what happened rather than minimise it.

Children

KalmPass is not directed at children under 13, and we do not knowingly hold their data.

Changes

If we change this policy materially we will email account holders before it takes effect. Previous versions are archived and available on request.