Privacy
This page describes what this website, your Key Expander account and the app do with your information. You need a Key Expander account to use the app at all, on the free plan as well as on a paid one, so this page describes information we hold about every person who uses Key Expander and not only about people who buy something. If we start doing something new with your information, we will change this page before we do it.
Last updated 16 September 2026.
Who this is about
Key Expander is a small software project, and the developer behind it is responsible for the information described on this page. The easiest way to reach us is the contact form, or by email at support@keyexpander.com.
The Key Expander app itself
Your snippets are stored on your own machine. On the free plan they stay there and nowhere else: the free plan has no sync, so no snippet you write ever reaches our servers. With sync switched off, the app does not send your snippet content to us, and expanding text never needs a working connection either way. It does not keep a copy of your clipboard, and it does not record what you type beyond the moment it needs to spot a trigger. We never store passwords in a readable form; a password you set is kept only as a hash that cannot be turned back into the password.
What the app does talk to our server about is your account and your license: signing in, confirming your email address, activating and removing devices, and checking which plan you are on and what it allows. When it activates a device, it sends a one-way code derived from an identifier for that machine, together with a name for the device so that you can recognise it in your device list. We never receive the identifier itself. The one-way code cannot be turned back into it, and we do not use it to work out where you are.
Syncing your snippets between your devices is a paid feature and needs an active paid license. If you have one and you are signed in, sync is on, and you can switch it off in the app's settings whenever you like. While it is off, nothing about your snippets leaves your machine. While it is on, we store each snippet on our servers so that your other devices can pick it up: the text it expands to, its label, its trigger, the group you filed it under, and the few settings that have to match everywhere, such as whether it is switched on and whether its trigger is case sensitive. Each device also sends the name it has been given, so that you can tell your devices apart in your device list, and the sign-in token for that device is kept only as a hash that cannot be turned back into the token. Snippet content is never written to our logs, and we do not sell it or share it with anyone.
Every change is kept as a new version rather than written over the last one, which is what lets a snippet survive a bad edit on another device. We do not keep those versions forever. A nightly job keeps the newest 50 versions of each snippet and anything changed in the last 90 days, and removes the rest; the version your devices are actually using is never removed. When you delete a snippet, we erase its text from our servers after 90 days and keep only a small record that it was deleted, with no snippet text in it, so that your other devices know to remove it too. If you ask us to delete your account, your synced snippets and everything we hold about them go with it.
Your account
For your Key Expander account we store your email address, a hash of your password, whether you have confirmed your address and when, which plan you are on together with the state of your subscription and the license that goes with it, and a record of each device you have activated. A device record holds that one-way machine code, the device name, a sign-in token for that device kept only as a hash, and the dates it was activated and last seen. We also keep ordinary timestamps such as when the account was created.
Two more records go with an account. Each time you sign in we store a session, which is what keeps you signed in: when it was created, when it expires and whether it has been ended. And we keep an administration record of things that happen to an account, such as a device being activated or a subscription changing, each entry holding what happened, when, and where a device was involved its one-way machine code. It is how we can answer a question about what happened to your account, and how we notice a license being used in a way it should not be.
When you start a purchase from the app, we record which button you pressed (for example the Account tab or the menu bar) alongside that purchase, and use it only to learn which prompts lead to a sale.
We use this to run the product: to let you sign in, to keep your plan working on the number of devices it covers, and to answer you when you write to support. We do not sell it, and the only outside parties that see any of it are Paddle, which handles payments, and the mail service that delivers our emails to you. Google sees nothing about your account: its spam check runs on the forms on this website and nowhere else, and neither the app nor your account data goes near it.
If you buy a subscription
Payments are handled by Paddle, which acts as the seller of record for your purchase. Your card details and your billing address go to Paddle and never to us. Paddle tells us that a payment succeeded, what you bought and when it renews, so that we can keep your license valid. Paddle describes its own handling of your information in its privacy policy on its website.
If you sign up for the newsletter
When you use the signup form on this site, we store four things:
- your email address;
- the date and time you signed up;
- the exact wording you agreed to, saved as it was written on the day you signed up rather than as it reads today;
- the IP address your browser was using at that moment. We keep it as proof that the request to subscribe came from a real person and a real device, so that we can answer the question of who asked for these emails if it is ever put to us. It is not used for anything else, and we do not use it to work out where you are.
Nothing is sent to you until you click the link in the confirmation email. If you never click it, the pending request is deleted automatically and you hear nothing further from us. We do not sell, share or pass your address to anyone.
Getting out of the newsletter
Every newsletter has an unsubscribe link, and one click on it is enough. There is nothing to log in to and nothing to confirm. You can also ask us to delete your address entirely through the contact form, and we will.
Signing in, and confirming your address
You need a Key Expander account to use the app at all, on the free plan as well as on a paid one. There is no anonymous mode: the free plan is tied to your account, which is how the one device it covers is counted and how your plan follows you if you move to another machine. This is the part of the product that means we hold something about you from the moment you install it rather than from the moment you buy anything, and it is why this page is written the way it is.
When you sign up we ask you to confirm your email address, so that an account cannot be created with an address nobody reads. Until it is confirmed you cannot activate a device, so the app cannot be used, and if the address is never confirmed we delete the account automatically after 30 days.
If you use the contact form
Your name, your email address, your subject line and your message are sent to our own inbox so that we can read and answer them. Your address is used to reply to you and for nothing else. Using the contact form does not add you to the newsletter or to any other list.
The spam check
The signup form and the contact form are protected by reCAPTCHA v3, which is a service run by Google. To make it work, this site loads a script from google.com on the two pages that carry a form, which means Google receives information about your visit to those pages, including your IP address, and may read and set its own storage in your browser for that purpose. That is how the check tells a person from a script.
Google is the only third party this site loads anything from. The privacy page, the confirmation page and the unsubscribe page do not load it, and on those pages nothing about your visit reaches Google. Google describes its own handling of this data in its privacy policy at policies.google.com/privacy.
What we do not do
There is no analytics on this site, of any kind, privacy-preserving or otherwise. There are no advertising trackers and no social media pixels. We set no cookies of our own, which is why there is no cookie banner: the only browser storage involved is reCAPTCHA's, and it is there to make the spam check work rather than to follow you.
How long we keep things, and deleting your account
Newsletter details are kept until you unsubscribe or ask us to delete them. A newsletter signup that is never confirmed is deleted automatically. An account whose email address is never confirmed is deleted automatically after 30 days. Account details are kept while the account exists, and payment records are kept by Paddle and by us for as long as tax and accounting rules require. We also keep a register of the mail we have sent you, holding the address it went to, the subject and what kind of message it was, so that we can tell whether something we sent actually went out. Those entries are deleted automatically after 13 months.
You can ask us to delete your account, and we will. When we do, your email address, your password hash, your sign-in sessions, your devices, your subscription record and any snippets we hold for you go with it. Three things outlive the account, and we would rather say so than let you find out later.
The first is the administration record of what happened to the account. It is not deleted; it is detached, so it no longer names you. What it still holds is the one-way machine code of a device that was activated, and, on the entry recording the deletion itself, a one-way hash of the address that was deleted. We keep the hash so that we can answer the one question an erasure raises later: whether we ever held a particular address and whether it was deleted. Neither value can be turned back into your address or into anything that identifies your machine to anyone else.
The second is the register of mail already sent. Your address is removed from those entries, and what stays is the fact that a message of some kind was sent on some date. Those entries are deleted on the ordinary 13-month schedule.
The third only applies if you are also on the newsletter: your subscription to it is separate from your account and is not cancelled by deleting the account, so your address stays on that list until you unsubscribe. Write to us and we will remove it.
Your rights
You can ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted, and you can withdraw your consent to the newsletter at any time without giving a reason. Use the contact form and we will deal with it.
