Privacy and user data
Privacy Policy
This policy transparently explains how the MYKEYNEST service and browser extension process your data to secure, synchronize and fill your credentials.
1. Data controller
OptiWebSolutions operates the MYKEYNEST service. For questions about your personal data or to exercise your rights, contact us at the address below.
2. Extension single purpose
The MYKEYNEST extension lets an authenticated user access their vault, identify credentials matching the website being visited, and fill or submit a login form at their request. It also lets users manage authorized credentials from the extension interface.
3. Data collected or processed
Depending on the features you use, MYKEYNEST may process the following categories:
- Account data: name, email address, organization, teams and information required for sharing.
- Authentication data: extension access token, technical installation identifier and temporary pairing codes. The website session cookie is not sent to the extension.
- Vault data: service name, domain, username and password for entries your account is authorized to access.
- Browsing data required for the feature: active tab URL or domain and login-form structure. The extension locally detects login fields and does not read values you type.
- Technical and security data: browser and version, operating system, extension version, IP address, user-agent, pairing events and technical errors.
4. How data is used
- Authenticate the extension, associate an installation with the correct account and maintain the extension session.
- Find authorized credentials for the current domain, display them on request and perform autofill.
- Apply access rights, sharing rules and subscription-plan limits.
- Prevent unauthorized access, secure the service, investigate errors and detect abuse.
- Provide support, send communications essential to the service and comply with legal obligations.
5. Extension permissions
These permissions are used only for the disclosed MYKEYNEST features.
| Permission | Why it is needed |
|---|---|
storage | Store the connection token, installation identifier and extension preferences locally. |
tabs | Identify the active tab, determine its domain and open MYKEYNEST pages requested by the user. |
notifications | Notify the user when a pairing step requires attention and the extension popup cannot be opened. |
<all_urls> | Locally detect login forms and fill credentials on websites where the user chooses to use MYKEYNEST. |
key-nest.com | Communicate with the official MYKEYNEST API for authentication, vault access, authorization and extension pairing. |
6. Storage and transmission
The connection token, technical installation identifier and preferences are stored in the Chrome extension's protected local storage. During autofill after navigation, an entry identifier and username may be held in session memory for no more than two minutes.
Account and vault data are hosted on the service infrastructure. Production communications between the extension and MYKEYNEST use HTTPS.
Vault passwords are encrypted at rest on the server. The extension does not persist passwords: it retrieves them only when an authorized reveal or autofill action requires them.
7. Recipients and service providers
We do not sell or rent your data, use it for personalized advertising, or transfer it to data brokers.
- o2switch for technical hosting and service storage.
- Brevo for transactional and security emails.
- Stripe for payments and subscription management; MYKEYNEST does not store full payment-card numbers.
- Google Chrome and the Chrome Web Store for extension distribution and execution according to browser settings.
The extension itself contains no advertising or audience analytics. The public website may use separate audience measurement; this privacy page does not load it.
8. Data retention
We retain data only for as long as necessary to operate the account, maintain security and meet legal obligations. The local token is deleted when the extension is disconnected; local installation data can also be removed through Chrome. Account data can be deleted on request, subject to retention required for law, billing or fraud prevention.
9. Security
We apply appropriate technical and organizational safeguards, including encrypted communications, encryption at rest for vault secrets, access controls, installation pairing and restricting local storage to trusted extension contexts. No system can guarantee absolute security.
10. Chrome Web Store – Limited Use
Data obtained by the extension is used solely to provide or improve its user-facing single purpose. It is not sold, used for advertising, transferred for credit assessment, or accessed by humans except with your consent, for security, support, legal compliance, or where the data is aggregated and anonymized.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
11. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction or portability of your data and object to certain processing. You may also lodge a complaint with the competent data-protection authority.
12. Changes to this policy
This policy may change when the service, extension or legal requirements evolve. The date displayed at the top of the page identifies the version currently in effect.