Skip to content
KeyBond
How it worksPricingHonesty
Get KeyBond

KeyBond Privacy Policy

Last updated: 2026-09-03

KeyBond keeps your account and your keyholder's answers on our server so an unlock ask can reach them; which apps you block never leaves your phone, and we sell nothing about you.

Seller: WaveApp LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA

Checkout: Apple · Google

Contact: support@keybond.app

Product domain: keybond.app

1. What never happens

  • Which apps you block stays on your phone. The iOS app selection token and the Android package names are never uploaded, and no server, keyholder or vendor ever sees them.
  • No password: you sign in with a login link sent to your email.
  • Your keyholder installs nothing and signs up for nothing. They get a one-time link and see one ask at a time: how long, and the reason you typed.
  • KeyBond never claims it cannot be uninstalled or that a permission cannot be revoked. If protection is revoked, your keyholder is told; if your phone goes silent, the server says only that protection cannot be confirmed.
  • No advertising, no ad SDKs, no sale of data, no padded "hours saved" statistics.

2. Data we touch

2.1 Your account

Data: your email address, a display name, sign-in sessions and registered devices, and push tokens for your own devices.

Used to: sign you in, keep your devices in sync and send you notices.

Who: WaveApp LLC and its hosting and security providers in the United States. Resend delivers the login link; Firebase Cloud Messaging delivers the push.

Basis: performing the contract with you.

Kept: until you delete the account (section 5). A login link works for 15 minutes; only a hash of it is stored.

2.2 Your keyholder and your asks

Data: your keyholder's name and email address or phone number, stored encrypted; the state of the bond; each unlock ask with its duration and the optional reason you typed, and the answer. Also your schedule time windows and the protection check-ins from your phone.

Used to: send the invitation, deliver each ask, record the answer, and show your ask history.

Who: our server. Resend sends the emails; Twilio sends an SMS when you reach the keyholder by phone.

Basis: performing the contract; for the keyholder, our legitimate interest in delivering the ask you sent, bounded by section 3.

Kept: an invitation link works for 72 hours and an answer link for 10 minutes. The reason text is deleted 30 days after the answer. The rest stays until you remove the keyholder or delete the account.

2.3 Purchase and entitlement

Data: the store receipt and transaction identifiers for the keyholder subscription, tied to your account identifier.

Used to: unlock the keyholder set, restore it, and keep it working.

Who: Apple App Store or Google Play takes the payment; RevenueCat confirms the entitlement and receives your account identifier for that. We never see your card number.

Basis: performing the purchase contract.

Kept: by the store under its own terms; by RevenueCat while KeyBond is on sale, so Restore purchase keeps working.

2.4 Usage analytics

Data: a fixed list of counted events. From the app: protection setup completed, access request started, paywall viewed, purchase started. From our server: access request resolved, invite accepted, subscription activated. Each event carries an anonymous identifier that changes when you sign out and is cleared when you delete the account, plus product, platform and release. Never an app name, a reason, a keyholder detail, a schedule, an account identifier or free text. Crash reports carry a failure code only, no error text and no screen content.

Used to: know whether protection works and whether the paywall converts. There is no switch for this; this page is the disclosure.

Who: PostHog, United States. For app events, PostHog receives your IP address and derives an approximate location from it.

Basis: our legitimate interest in running the product.

Kept: by PostHog under its terms.

2.5 Support email

Data: what you write to support@keybond.app, and your address.

Used to: answer you.

Kept: 12 months after the thread closes.

2.6 The website

keybond.app uses PostHog for anonymous page analytics: page views, exits, selected navigation, campaign tags and referring site. Its anonymous browser identifier lasts 365 days; session recording, heatmaps and location lookup are off. Hosting and security providers process your IP address to deliver the site; KeyBond keeps no separate access log.

When a keyholder opens a one-time link, api.keybond.app sets one strictly necessary cookie for 15 minutes to hold that action session. It is not used for analytics.

3. Keyholders

Your keyholder did not sign up. So we hold only the name and contact you entered, and we use them only to deliver your asks. Through the link they see only the current ask, your display name and whether protection is confirmed. They can decline the role at any time, and they can write to support@keybond.app to have their details removed. You must have their agreement before you add them.

4. Processors

  • Apple App Store and Google Play — payment, receipts and subscription management (United States).
  • RevenueCat — entitlement verification (United States).
  • Resend — email delivery (United States).
  • Twilio — SMS delivery, only for a keyholder reached by phone (United States).
  • Firebase Cloud Messaging — push notifications to your own devices (United States).
  • PostHog — app, server and website analytics and crash diagnostics (United States).
  • Hosting and security providers — delivery and protection of site, server and database traffic (United States).

Each acts on our instructions under its data processing terms. Nobody else receives data from KeyBond. Data from the EU or the UK reaches the United States under the transfer safeguards each processor provides.

5. Deleting your account

In the app, open Settings and choose Delete account. The account is closed at once: sessions end, the keyholder bond ends, and no further ask is delivered. Thirty days later every account record is purged: asks, leases, tokens, check-ins, schedules, push tokens, entitlement events and the analytics identifier. If you cannot sign in, write to support@keybond.app from the account's email address; we send a confirmation link that works for 24 hours. Deleting the account does not cancel a store subscription; cancel it in the store. The app selection on your phone is yours to clear.

6. Your rights

If you are in the EU, the UK or another place with data-protection rights, you can ask us to show, correct, delete, restrict, export, object to or stop using data about you. You can also complain to your local supervisory authority. Write to support@keybond.app from the account's email address; we answer within one month.

7. Children

KeyBond is a self-control tool for adults, not a parental-control product. It is not directed at children under 13, or the local minimum age where you live, and we knowingly collect nothing from them.

8. Security

Encrypted transport, an encrypted local store on your phone, keyholder contact sealed on the server with a key kept outside the database, hashed tokens, and server-signed timed leases. No service guarantees absolute security. Report suspected unauthorised access to support@keybond.app, and never forward a login, invitation or answer link.

9. Changes

If a change would affect what data we touch, we email account holders before it takes effect.

10. Contact

support@keybond.app — WaveApp LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA

KeyBond

Scheduled app locks with a trusted keyholder.

Product

FeaturesPricingDownload

Legal

PrivacyTermsRefundDelete account

Help

Supportsupport@keybond.app

© 2026 WaveApp LLC