Keyrook Authenticator

Privacy Policy

Last updated: 8 October 2026

Keyrook Authenticator works without an account, and then nothing leaves your computer. Sync between your browsers is optional. If you turn it on, your two-factor accounts are encrypted on your device before they are uploaded, with a key the server never receives: we store them, but we cannot read them. We keep your email address and what is needed to run the account, use it for nothing else, and sell nothing. You can sign in with a password, or with Google or GitHub, which tell us who you are and nothing more.

Keyrook Authenticator is made by BRICK IT ALL LLC ("we"). Sync is available from version 0.2.0.

Without an account

What the extension stores

All of this lives in your browser's local extension storage. Without an account none of it is sent anywhere.

What the extension can see

Nothing seen this way is stored or transmitted. Screenshots of the page, camera frames and the pictures you choose are decoded in memory and discarded — none of them is recorded, kept or uploaded, with or without an account.

With an account (optional sync)

What we receive and keep

What the service sees in passing

Emails we send

Only what the account needs: the code that confirms your address when you sign up, and a notice if someone tries to sign up with an address that already has an account. An account made with Google or GitHub gets no email from us at all. No newsletters, no marketing.

Who processes it for us

They handle the data only to provide those services to us. Some of them are in the United States, so your data may be processed outside your country.

How long we keep it

How we use it

Only to provide sync and to keep the service and your account secure. We do not sell your data, use it for advertising, share it except with the processors above, or use it to decide anyone's creditworthiness. Nobody at BRICK IT ALL LLC reads your two-factor accounts, because nobody can.

What Keyrook Authenticator never does

Data you export yourself

The backup and export features write files to wherever you choose, or show QR codes on your screen for another app to scan. All of it is made on your device and sent nowhere. An encrypted backup is protected by the password you set for it. Everything else — a QR code, a printed sheet of them, an Aegis or Bitwarden file, a plain-text otpauth:// export — is not encrypted and contains your secrets in readable form: whoever sees or holds it can generate your codes. Delete files, and destroy paper copies, as soon as you have finished with them.

Your choices and rights

By creating an account you agree to this processing for the purposes above; you can withdraw by deleting the account. If you believe we handle your data wrongly, you may also complain to the data protection authority where you live.

Keyrook Authenticator is not directed at children under 13, and we do not knowingly hold data about them.

Changes

When this policy changes, the date at the top changes with it. A change in what we collect or who processes it is also named in the extension's release notes before it takes effect.

Contact

BRICK IT ALL LLC — brickitall.hi@gmail.com