DeadKey Privacy Policy

Last updated: July 26, 2026

DeadKey is an encrypted Android vault provided by Korelis Labs LLC. DeadKey is designed to keep vault contents under the user's control.

Information DeadKey handles

DeadKey stores vault contents, encrypted vault metadata, app settings, and encrypted thumbnail cache files locally on the user's device. DeadKey does not require a Korelis Labs account.

When a user voluntarily connects a cloud-backup provider, DeadKey may access the selected provider account identifier or account label, authorization credentials, backup-folder identifiers, and encrypted DeadKey backup files. These details are used only to show the connected account and to create, list, upload, download, and restore DeadKey backups.

Optional cloud backups

Cloud backup is optional and is disabled until the user chooses a provider and authorizes DeadKey. DeadKey encrypts a backup on the device before uploading it. Vault PINs and unencrypted vault contents are not sent to Korelis Labs or to the cloud provider. A backup contains encrypted vault data and the encrypted key-wrapping material needed to restore that data with the user's PIN or backup passphrase.

Google, Microsoft, and Dropbox process account authorization and store backup files under their own terms and privacy policies. Korelis Labs does not operate an intermediary backup server and does not receive a copy of a user's backup or cloud-account authorization data.

Google API data

Information received from Google APIs is used only to provide the user-requested Google Drive backup and restore features. It is not used for advertising, analytics, profiling, or sale, and it is not transferred to Korelis Labs servers or other third parties.

DeadKey's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements.

Authorization data

Provider authorization is managed on the device by the provider's authorization software or by DeadKey. Where DeadKey must retain a Dropbox refresh credential for scheduled backups, it is encrypted using a key held by the Android Keystore. DeadKey does not include provider authorization data in a vault backup.

Analytics, advertising, and tracking

DeadKey does not include advertising, third-party analytics, or user tracking, and Korelis Labs does not sell personal information. Google Play and an optional cloud provider may independently process information as described in their own privacy policies.

Permissions

Retention and deletion

Local DeadKey data remains on the device until the user deletes it, resets the vault, clears app data, or uninstalls DeadKey. Disabling scheduled backups stops future scheduled uploads and removes DeadKey's locally retained Dropbox refresh credential.

Cloud backups remain in the user's cloud account until the user deletes them there. A user can revoke DeadKey's access through the security or connected-app settings of Google, Microsoft, or Dropbox.

Security

DeadKey uses authenticated encryption and Android platform security controls to protect local vault data and cloud-backup authorization material. No security method can guarantee absolute protection, so users should keep Android and DeadKey up to date and protect access to their device and cloud accounts.

Children's privacy

DeadKey is not directed to children under 13. Korelis Labs does not knowingly collect personal information from children through DeadKey.

Changes to this policy

Korelis Labs may update this policy when DeadKey's features or legal requirements change. The effective date above identifies the latest revision.

Contact

Questions about this policy may be sent to scott@korelislabs.com.

Third-party privacy policies