Privacy Policy
Last updated: July 15, 2026
1. Who this policy covers
This Privacy Policy explains how Keylime ("we", "us", or "our") collects, uses, stores, and shares information when you use our website, dashboard, APIs, and SDKs (the "Service").
It applies to sellers and developers who create Keylime accounts, and to end-user validation data that Seller applications send to our APIs when a license is redeemed, verified, or session-checked.
2. Information we collect
We collect information to operate, secure, and verify licensing for software that integrates Keylime:
Developer data
Account email, hashed passwords, display name, plan and billing metadata, application configurations, webhook endpoints, upload metadata, and dashboard activity logs.
End-user validation data
Hardware identifiers (HWID), session tokens, IP addresses, timestamps, license and subscription identifiers, ban status, and verification results from our APIs.
We may also collect request paths, status codes, user agents, and browser fingerprint signals used during login and signup abuse checks.
3. How we use information
We use collected data to:
- Create and authenticate seller accounts and dashboard sessions.
- Verify licenses and run client sessions in real time.
- Enforce HWID locks, bans, reseller mint balances, and other controls you configure.
- Deliver webhooks, store app files, and show stats such as keys and live sessions.
- Limit abusive login attempts, investigate misuse, and keep the Service available.
- Email you about account security, billing, outages, and material policy updates.
We do not use end-user HWID or session data to build advertising profiles or sell audience segments.
4. Data security
Traffic to Keylime is protected with TLS in transit. Seller passwords are stored hashed, not in plain text. Dashboard GraphQL access may require signed requests and session cookies.
We log security-relevant account and licensing events so we can investigate abuse. No system is perfectly secure. If you think credentials were exposed, rotate API keys and contact security@keylime.cc.
5. Cookies and local storage
We use cookies and browser storage for session login, device identifiers used in auth checks, UI preferences, and dashboard caches. Timing and fingerprint signals may be used during login and signup to resist bots and credential stuffing, together with tools such as hCaptcha and FingerprintJS.
Those vendors process data under their own policies. Details: Cookie Policy.
6. Data sharing
Keylime does not sell or lease developer or end-user information to advertising networks. We share data only when needed to run the Service:
- Vendors we need to run the Service (email delivery, plan payments, captcha and fingerprinting during login), under their contractual terms.
- Seller-configured webhook endpoints, when events fire for that seller's apps.
- Auth helpers such as captcha or fingerprinting vendors during login and signup.
- Authorities when required by law, or to protect rights and safety of the Service.
7. Data location
Account and licensing data is processed and stored on our systems and the third-party services we use to operate Keylime. That may include regions outside where you live.
8. Retention
We keep account data while your account is active. License keys, sessions, and validation logs may stay for the life of the related app, or longer when needed for fraud review, billing disputes, or law.
Sellers can delete applications and manage keys, users, and HWID resets in the dashboard. Full account closure is handled by emailing support (see section 10). We remove or de-identify records within a reasonable time after closure, except where retention is required.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal data. Sellers can export license data and change many records in-product. EU/EEA details: GDPR.
10. Children
The Service is for businesses and software vendors. We do not knowingly collect personal information from children under 16. If you believe a child provided data, contact us and we will delete it.
11. Changes
We may update this policy when the product or law changes. We revise the date at the top and may notify you in the dashboard for material changes.
12. Contact
Privacy: privacy@keylime.cc. Security: security@keylime.cc. Support / account closure: support@keylime.cc.