Hosted in Germany 🇩🇪
All cloud data lives on servers physically located in Germany. German and EU data-protection law applies in full. Your data never leaves the EEA.
Privacy & Data Protection
We built Keestash in Germany because European privacy standards are the world's strongest. Here is every detail about how we handle your data — in plain language.
Our Commitments
All cloud data lives on servers physically located in Germany. German and EU data-protection law applies in full. Your data never leaves the EEA.
Your vault is encrypted on your device before anything reaches our servers. We have no technical ability to read your passwords — not now, not ever.
The Keestash application contains no trackers and no advertising scripts. On this marketing website we use Google Analytics only after you opt in — nothing is loaded and no cookies are set until you accept. You can decline or withdraw consent at any time.
Data protection by design and by default is not an afterthought for us — it is the foundation the product was built on. We collect the minimum data required to operate the service.
Export your complete vault at any time in an open, encrypted format. Your data is yours — we make it easy to take it with you.
Delete your account and all associated data at any time from your account settings. No retention periods, no dark patterns — deletion is instant and complete.
Last updated: September 2026
Keestash is an open-source password manager developed and operated in Germany. For cloud services, the data controller is Keestash (see Impressum for full legal details). For self-hosted deployments, you are the data controller.
For cloud accounts: your email address (for authentication and support), encrypted vault data (which we cannot decrypt), and technical server logs (IP address, timestamp, HTTP status) retained for 30 days for security purposes.
We do not collect: browsing history, device fingerprints, advertising identifiers, or any data from third-party sources.
Your email: to send account-related notifications and respond to support requests. Vault data: stored encrypted on German servers, synced to your devices, never accessed by us. Server logs: used solely for debugging and security monitoring.
Processing is based on performance of a contract (Art. 6(1)(b)) for account data and legitimate interests (Art. 6(1)(f)) for security logs.
We do not sell your data. We do not share it with advertisers. We use a minimal set of infrastructure sub-processors (hosting provider in Germany) who are bound by GDPR-compliant DPAs.
Under GDPR you have the right to access, rectification, erasure, restriction, portability, and objection. To exercise any right, contact us at our contact form. We respond within 30 days.
Strictly necessary cookies: this website always sets a session cookie and a CSRF-protection cookie. These contain no personal data and are required for the site (and the contact form) to function.
Analytics (consent-based): if you accept analytics in our cookie
banner, we load Google Analytics 4 (provider: Google Ireland Ltd.). It sets the
_ga and _ga_* cookies (lifetime up to 2 years) to measure
aggregate, pseudonymous site usage. This may involve transferring data to Google
LLC in the USA on the basis of the EU Standard Contractual Clauses. No analytics
script runs and no analytics cookie is set before you give consent.
Legal basis: your consent (Art. 6(1)(a) GDPR / § 25(1) TTDSG). You can withdraw consent at any time with effect for the future via the “Cookie Settings” link in the footer — withdrawal is as easy as giving consent and does not affect the lawfulness of prior processing.
For privacy questions: contact us.
Supervisory authority: Landesbeauftragte für Datenschutz und Informationsfreiheit (LfDI),
relevant to the state where Keestash is registered.