FinalKey ("we," "our," or "us") operates the website finalkey.polsia.app. This Privacy Policy explains how we collect, use, disclose, and protect information about users of our service. By using FinalKey, you agree to the practices described in this policy.
If you have questions, reach out at privacy@finalkey.polsia.app.
1. Data We Collect
We collect the following categories of data:
| Data Type | How It's Collected | Purpose |
|---|---|---|
| Account information | Registration form | Creating and managing your vault access |
| Encrypted vault entries | You add data to your vault | Storage and family access after death |
| License key & purchase status | Stripe checkout or key redemption | Granting vault unlock access |
| Gmail scan results | Email Scanner (via OAuth) | Discovering accounts & subscriptions |
| Designated contacts | You add contact details | Family/estate contact access workflow |
| Browser & device info | Automatic (server logs) | Analytics, fraud prevention |
2. Gmail Data — What We Access & Why
FinalKey's Email Scanner connects to Gmail via Google's OAuth2 API. Here is exactly what we access and why:
What we access
- Email headers and sender addresses — to identify which services you've created accounts with
- Subject lines — to detect subscription, welcome, and account-confirmation emails
- Sender domain patterns — to group emails by service and extract account names
What we do NOT access
- Email body content (we read headers only)
- Attachments of any kind
- Drafts, sent mail, or other Gmail folders
- Google Drive, Calendar, or any non-Gmail Google service
How scan results are stored
Discovered accounts and subscriptions appear as vault entries in your account. Each entry contains the service name, account identifier, and scan date — no raw email content is stored. You control whether to keep or delete these entries at any time.
3. How We Use Your Data
- Providing the vault service — storing and managing your encrypted vault entries
- Account discovery — scanning Gmail to surface accounts you may have forgotten
- License management — verifying purchase and unlocking vault access
- Family access — delivering vault access to your designated contacts when access is triggered
- Service improvement — understanding usage patterns to improve the product
- Security — detecting and preventing unauthorized access or fraud
We do not sell your personal data to anyone, for any reason.
4. Data Security
We take the following technical and organizational measures to protect your data:
- AES-256-GCM encryption — all vault entries are encrypted client-side before transmission. Decryption keys never leave your browser.
- TLS encryption in transit — all data transmitted to and from FinalKey is encrypted using TLS 1.2 or higher.
- Hashed passwords — your account password is hashed using a modern, salted hashing function before storage.
- Encrypted OAuth tokens — Gmail OAuth tokens are encrypted at rest before database storage.
- Access controls — database access is restricted to the application layer; direct database access is limited to authorized personnel.
- Regular security review — we periodically review our security practices and dependencies.
While no system is completely immune to breach, we design our architecture to minimize the impact of any single point of failure. If a security incident occurs, we will notify affected users within 72 hours of discovery.
6. Data Retention
We retain your data as long as your account is active. When you delete your account:
- Account data is deleted within 30 days.
- Vault entries are deleted within 30 days.
- Gmail connection records and OAuth tokens are revoked and deleted within 30 days.
- Purchase and license records are retained for tax and legal compliance (up to 7 years).
Family contacts who have been granted access retain whatever vault data they received before account deletion — this is the intended outcome of the access workflow.
7. Your Rights
You have the following rights regarding your personal data:
- Access — request a copy of your personal data held by FinalKey.
- Correction — update or correct your account information at any time from within the app.
- Deletion — delete your account and all associated personal data (except records required for legal compliance).
- Portability — export your vault entries as a structured file at any time.
- Revoke Gmail access — disconnect your Gmail account from the Email Scanner at any time from your account settings. This revokes our OAuth access to your Gmail and deletes stored scan results.
- Object to processing — contact us if you believe we are processing your data in a way that violates applicable law.
To exercise any of these rights, email privacy@finalkey.polsia.app. We will respond within 30 days.
California & EU Residents
If you are a California resident under the CCPA or an EU resident under the GDPR, you have additional rights including the right to know what data we hold, the right to deletion, and the right to non-discrimination. Contact us at the address above to exercise these rights.
8. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make a material change, we will:
- Update the "Last updated" date at the top of this page
- Post a notice in our application for 30 days before the change takes effect
- Email registered users at least 14 days before the change takes effect if the change reduces your privacy rights
Continued use of FinalKey after a policy update constitutes acceptance of the revised policy.
9. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or your personal data:
- Email: privacy@finalkey.polsia.app
- Website: https://finalkey.polsia.app
We aim to respond to all privacy-related inquiries within 30 days.