Privacy Policy

Last updated: 3 October 2026

1. Who we are

Keyed is an independent tool for distributing game review keys between two kinds of user: developers, who upload keys and review requests, and content creators, who verify a channel and request keys. This policy covers both.

Keyed is operated by a sole trader based in the United Kingdom, who is the controller of the personal data described below. You can contact us at any time about anything in this policy: support@keyed.id.

2. The short version

  • We store as little as we can get away with. No analytics, no tracking pixels, no advertising, no profiling.
  • Creators: your OAuth sign-in with Google or Twitch confirms you own your channel. We read your public channel stats (handle and subscriber/follower count) at the moment you request a key — and nothing more.
  • Developers: the game keys you upload are stored encrypted, never in plaintext, and we never resell, resurface, or share them.
  • Payments are handled entirely by Polar as merchant of record; we never see your card details.
  • You can delete your account (and everything in it) yourself from your dashboard at any time.

3. What we collect and why

Different data is stored depending on which side of the product you use.

Everyone (sign-in)

  • Email address — your account identifier and how we contact you about your requests, deliveries, or billing. Comes from the sign-in method you choose (email, Google, or Twitch).
  • Public profile pieces from your OAuth provider (e.g. display name, channel handle) — only if you sign in that way.

Content creators

  • Channel verification data — the platform (YouTube or Twitch), your channel ID/handle, URL, and a snapshot of your subscriber/follower count taken at the time of each request. This exists so developers can see you are a real, verified creator, and is shown only to the developer you request from.
  • Request details — your display name, the email you want the key delivered to, the platform you request for, and any message you write.
  • What we never receive or store: your OAuth access tokens are used in the moment to read your public channel stats and are then discarded. We do not keep them, we do not read private messages, videos, drafts, contacts, or anything else from your Google or Twitch account. We read your public subscriber or follower count and nothing else.

Developers

  • Project details — title, description, banner, supported platforms, subscriber threshold.
  • Game keys you upload — stored encrypted at rest; the plaintext exists only long enough to email the key to an approved creator. We cannot read them casually, and they are never visible to other users.
  • Billing linkage — when you top up credits, our payment provider gives us a customer reference and the number of credits purchased. That is all; card details never reach us.

Small technical data (everyone)

  • A salted, one-way hash of your IP address — used only to rate-limit request submissions and prevent abuse. The hash is not designed to be reversible, and we make no attempt to recover your IP from it.
  • Essential cookies only — a session cookie so you stay signed in, plus a short-lived token from our bot-check provider. There are no advertising or analytics cookies of any kind.
  • Server error logs — when something breaks, our error tracker (Sentry) receives a technical report (stack trace, error message). These reports are scrubbed of emails, keys, and IP addresses before they leave our systems, and are used only to fix bugs.

4. What we deliberately do NOT collect

  • No analytics or product-tracking scripts (as of the date above).
  • No advertising pixels or cross-site tracking of any kind.
  • No behavioural profiles, ad targeting, or audience selling — and never any.
  • No precise location, contacts, or device fingerprinting.
  • Your game keys in plaintext (stored encrypted, and only revealed to fulfil an approved delivery).

5. Who else processes your data

Keyed could not run everything itself; we use a small, fixed set of specialist providers. We do not share your data with anyone else, and we never sell it.

ProviderWhat they doWhat they don't get
SupabaseDatabases, accounts, and sign-ins (hosting our backend). Game keys are additionally encrypted at the application layer.—
VercelRuns this website and API.—
CloudflareTurnstile bot-check on public request forms. Receives enough to verify humans only.—
ResendDelivers emails (key deliveries, decisions). Receives your email address and the email content only.—
PolarMerchant of record for paid credits. Handles checkout, payment, VAT/sales tax, and receipts. We receive only a customer reference — your card details never touch Keyed.—
SentryBug reports, scrubbed as described above.—
Google / Twitch (OAuth)Verify your channel ownership when you connect one; we receive your public channel identity and stats only.Private account data, videos, or messages.

Some of these providers may process data outside the UK. Where that happens, they are responsible for providing an equivalent level of protection (e.g. standard contractual clauses).

6. Who sees what

  • Creators: the developer you submit a request to sees your channel handle, its public subscriber/follower count, your display name, and your request text. That is the entire point of the product. Developers you never request from see nothing about you.
  • Developers: your project details are visible on your public request page. The keys you upload are never shown to creators until an approved request is fulfilled, and never shown to other developers at all.
  • Nobody — including us — sees your payment card details.

7. How long we keep things

  • Account data: until you delete your account.
  • Requests and channel snapshots: kept so you and the developer have a record of the request; delete your account and they go too. There are no standing OAuth permissions to revoke — we never retained access tokens in the first place.
  • Rate-limit IP hashes: short-term (hours, at most days) and pruned automatically.
  • Error logs: kept by Sentry briefly, per their default retention, then deleted.
  • Emails we send you: held in your mailbox, which is outside our control; we keep delivery records only for as long as your account exists.
  • Payment records: Polar, as merchant of record, retains transaction receipts for its own legal/tax obligations regardless of account deletion. We hold only the credited amounts, which go when your account does.
  • Delivered keys: we cannot unsend an email, so an emailed key is outside our control the moment it is delivered. Deleting your account will not retract emails already sent.

8. Your choices

  • Delete your account any time from the "Danger zone" on your dashboard. This permanently removes your account, requests, channel verifications, projects and their remaining keys (for developers), and any unused paid credits are forfeited. Already-sent emails cannot be retracted.
  • Disconnect a channel to remove a verification.
  • You can also contact us at support@keyed.id to exercise data rights (access, correction, deletion, complaint) — under UK GDPR, we respond within one month.
  • You have the right to complain to the UK Information Commissioner's Office (ico.org.uk) if you believe we have mishandled your data.

9. Changes to this policy

If we ever add or change what we collect (for example, if we introduce optional product analytics in future), we will update this page and the date above, and — for anything material — tell signed-in users by email before the change takes effect. We will never quietly widen what we collect.

Questions about anything above? Email support@keyed.id.