Legal
Privacy Policy
This policy explains what Keyra collects, why it collects it, and what we do with it. Keyra is operated by Alta Vision (Pvt) Ltd, Colombo, Sri Lanka.
Last updated: 16 September 2026
1. Who this policy is for
Keyra is a private credential vault for staff of Alta Vision and the partner companies we work with. It is not a public product and it is not sold to anyone. Every account starts in a pending state and stays there until a company admin or super admin approves it.
If you are not one of those people and you have reached this page, Keyra holds no data about you.
2. What we collect
- Account details. Your email address, the company group you requested, the role you asked for, your approval status, and the date your account was created.
- Google Sign-In details. If you sign in with Google, we receive your name, email address, profile picture, and Google account ID. Section 4 covers this in full.
- Passkey details. If you register a passkey, we store its public key, credential ID, signature counter, the label you give the device, and the date it was added. We never receive your fingerprint, face, or device PIN.
- Vault content. The credentials you or your admins save: titles, usernames, URLs, notes, and the secret itself, which is stored encrypted.
- Access records. Which credentials a company admin has granted you, and when access changed.
- Technical logs. Our hosting provider records request metadata such as IP address, timestamp, and user agent for security and reliability.
Keyra has no advertising, no tracking pixels, and no third-party analytics that profile you.
3. How we use it
We use the data above only to run the service:
- Authenticate you and keep your session valid.
- Route you to the workspace that matches your company and role.
- Let admins review, approve, and revoke access requests.
- Store and release the credentials you are permitted to see.
- Investigate security incidents and keep the service available.
We do not sell personal data, we do not share it with advertisers, and we do not use it to train machine-learning models.
4. Google user data and Limited Use
Signing in with Google is optional. You can use an email address and password instead. When you choose Google, Keyra requests only the basic sign-in scopes: openid, email, and profile.
Keyra does not request access to Gmail, Google Calendar, Google Drive, Contacts, or any other Google API. We cannot read your mail, your files, or your calendar, because we never ask for permission to do so.
Keyra's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to identify you and create or match your Keyra account.
- We do not transfer Google user data to others except as needed to provide Keyra, to comply with applicable law, or as part of a merger or acquisition with your notice.
- We do not use Google user data for advertising of any kind.
- We do not allow humans to read Google user data unless you ask us to for support, we need it for a security investigation, or the law requires it.
You can withdraw Keyra's access at any time from your Google Account permissions page. Doing so stops future Google sign-ins; it does not delete your Keyra account, which you can request separately under section 8.
5. Passkeys and biometrics
Keyra supports passkeys so you can sign in with the fingerprint reader, face unlock, screen lock, or hardware security key you already use on your device.
Your biometric data never leaves your device and is never sent to Keyra. Your device verifies you locally, then proves it holds a private key by signing a one-time challenge. Keyra stores only the matching public key, which cannot be used to impersonate you. Delete a passkey from your Keyra settings and the public key is removed from our database.
7. Storage, security, and location
All traffic to Keyra is served over HTTPS. Stored secrets are encrypted with AES-256 before they are written to the database, using a per-account data encryption key that is itself encrypted with a master key held only by the server and never present in the browser. Responses carry strict transport and framing headers, and every vault request is re-authorised against your role and your company on the server.
To be precise about what this is not: Keyra is not zero-knowledge. Decryption happens on our servers so that approvals and admin recovery can work, which means an administrator of the hosting environment could in principle reach stored secrets. We tell you this rather than claim a guarantee we cannot keep.
Data is processed and stored on Google Cloud and Vercel infrastructure, which may be located outside Sri Lanka, including in the United States and the European Union.
8. Retention and deletion
We keep your account and vault records for as long as your account is active. When an admin removes you from a company, your membership and access records are deleted. When a credential is deleted, it is removed from the database.
You can ask us to delete your account and everything attached to it by emailing irushia@altavision.lk or deeghayus@altavision.lk. We action deletion requests within 30 days, subject to any records we are legally required to keep.
9. Your choices
- Use email and password instead of Google Sign-In, or the reverse.
- Revoke Keyra's Google access from your Google Account permissions page.
- Add or remove passkeys from your Keyra settings at any time.
- Change your password from your Keyra settings.
- Ask us to correct or delete your records by email.
10. Children
Keyra is a workplace tool and is not directed at anyone under 16. We do not knowingly collect data about children.
11. Changes to this policy
If we change this policy, the date at the top changes with it. If a change materially affects how we handle your data, we will tell you inside the application before it takes effect. Continuing to use Keyra after that means you accept the updated policy.
12. Contact us
Alta Vision (Pvt) Ltd
Colombo, Sri Lanka
irushia@altavision.lk
deeghayus@altavision.lk