Last updated: July 28, 2026
Cool Apps LLC ("we," "us," or "our") operates KeyScan.io. This Privacy Policy explains what information we collect, how we use it, who it is shared with, and your rights regarding your data when you use the KeyScan.io website or scanning service (collectively, the "Service").
KeyScan exists to find exposed credentials. That means we necessarily handle sensitive material, and we would rather describe exactly how than leave you to assume. Sections 3 and 4 are the important ones.
Findings are stored in full. When a scan detects a credential, the complete value is written to our database along with its location, line number, and the surrounding code from the scanned target. We do not truncate or mask the stored value. Doing so would make the report useless — you need to know precisely which key is exposed and where in order to rotate it.
Before purchase, findings are withheld. Results shown prior to payment are gated server-side; the full values are not delivered to the browser.
Findings are purged on the schedule in Section 9. Unpurchased scans are deleted after 30 days. Purchased reports remain available for 90 days, after which the report file, including all credential values, is purged.
We do not share findings with anyone except as described in Section 4. They are not sold, not used for research, not published, and not shared with any party other than the automated verification step described below. Access within Cool Apps LLC is limited to personnel who require it to operate the Service.
What you should do regardless. A credential that has been exposed publicly should be treated as compromised and rotated, whatever any scanner subsequently does with it. Rotation is the only reliable remedy, and it is the first step in every Fix Kit we produce.
Raw pattern matching produces false positives — example keys in documentation, placeholder strings, and test values that look like real credentials. To filter these out, each scan's findings are submitted to Anthropic's Claude API for classification.
What is sent to Anthropic:
What is not sent: your email address, your account details, your payment information, or your IP address. Anthropic receives no information identifying who requested the scan.
Limited use. This data is submitted solely to classify each finding as real or a false positive. Under Anthropic's commercial API terms, content submitted through the API is not used to train their models; refer to Anthropic's privacy policy for their current terms. We do not use this data for any other purpose.
If the verification step is unavailable, the scan proceeds without it and all findings are reported unfiltered. Verification never causes a real finding to be withheld from you.
We record the IP address associated with each scan request. We do this on the basis of our legitimate interest in operating the Service securely: preventing abuse, enforcing rate limits, and identifying the party responsible for a scan request in the event of a dispute regarding unauthorised scanning.
Because KeyScan actively fetches and inspects a target you nominate, a record of who requested each scan is a necessary safeguard — both for the owners of scanned properties and for us. IP addresses are retained as described in Section 9 and are not used for advertising, profiling, or any purpose unrelated to security and abuse prevention.
You may object to this processing by contacting us, though we may be unable to provide the Service without it.
We may disclose information we collect, including IP addresses, scan request metadata, and account information, when we believe in good faith that disclosure is required by law, subpoena, court order, or other legal process, or that disclosure is necessary to investigate, prevent, or address fraud, unauthorised scanning, security incidents, or violations of our Terms of Use.
These apply to KeyScan and to every product operated by Cool Apps LLC:
Unpurchased scans — including all findings — are purged after 30 days.
Purchased reports remain available for download for 90 days from the date of purchase or the most recent re-scan, whichever is later. After that the report file, including every detected credential value, is purged.
Scan request metadata is retained for up to 5 years for security, abuse-prevention, and legal purposes. This consists of the IP address, the timestamp, the normalised URL or Chrome Extension ID, the associated account email, payment status, and the Stripe transaction reference. It does not include credential values, which are purged on the schedules above.
Server logs kept by our hosting provider are retained for 30 days and then deleted automatically.
When a Certificate of Secure Credentials is issued, a permanent record is created containing only non-sensitive, public-facing information: the certificate identifier, the domain or extension scanned, and the scan date. This record is retained indefinitely to support the permanent verification page and site badge associated with the Certificate. It contains no credential findings and no sensitive scan data. Certificate records may be removed in the event of revocation, as described in our Terms of Use, or on request under Section 14.
We use your email address for three things:
Every follow-up email contains an unsubscribe link, and unsubscribing takes effect immediately. You may also email support@coolapps.llc to opt out. Report delivery and sign-in links are necessary to operate the Service and are not affected by unsubscribing.
You may request deletion of your account and associated personal data at any time by emailing support@coolapps.llc from the address associated with your account, with the subject line "Delete my account."
On receipt we will delete your account record, your stored scan reports and findings, and your email address from our mailing list. This is completed within 30 days.
Two exceptions, both described above: scan request metadata under Section 9 is retained for its stated period for security and legal purposes, and any issued Certificate record under Section 10 persists unless you also ask for it to be revoked. Billing records held by Stripe are retained for the period tax and accounting law requires.
KeyScan.io is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Residents of the European Economic Area and the United Kingdom have these rights under the GDPR; residents of California have comparable rights under the CCPA, including the right not to be discriminated against for exercising them.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
To exercise any of these rights, email support@coolapps.llc. We will respond within 30 days.
Because this Service handles exposed credentials, we set out our security practices specifically rather than generically:
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. As stated in Section 3, any credential that has been publicly exposed should be rotated regardless of what any scanner does with it.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the Service after changes are posted constitutes acceptance of the revised policy.
If you have any questions about this Privacy Policy, please contact us:
Cool Apps LLC
30 N Gould St, Ste N
Sheridan, Wyoming 82801
support@coolapps.llc