Privacy policy
Effective September 22, 2026 · Initial policy, not reviewed by a lawyer.
This policy describes information processed by Keygen.lol and its assigned private Mail and Files services. We collect information needed to provide those services, secure accounts and respond to support requests.
Information we process
- Account email, password hash, verification state, permissions and account dates.
- Profile names, biographies, images, appearance choices, public addresses and links.
- Discord’s account identifier and verified email when you choose Discord sign-in; we do not request access to your Discord messages.
- For assigned private services, mailbox addresses, email content and attachments, uploaded files, file names, sizes, expiration dates and access settings.
- Session records, authentication timestamps, IP addresses, user agents, rate-limit events and administrative audit records.
- Support messages and information you choose to include in reports.
How we use information
We use information to authenticate you, publish your chosen profile, deliver messages and files, enforce limits, detect abuse, resolve support requests and maintain the service. Public profiles are intentionally visible. File links without passwords permit access to anyone with the link. Mail contents are not public; authorized operators may access information when necessary to maintain the service or investigate reported abuse.
Cookies and analytics
Essential cookies support secure sessions and protection against forged requests. We do not add advertising trackers or invasive analytics. Cloudflare’s challenge service may process device and network signals for abuse prevention when enabled.
Infrastructure providers
Keygen uses Oracle Cloud hosting and Cloudflare DNS/proxy services. Cloudflare R2 may store file objects when configured. An SMTP provider handles outbound email; the initial intended provider is SMTP2GO. Discord is involved only when its sign-in integration is used. Providers process relevant information under their own terms and policies and may operate in other countries.
Retention
Account and published content remains until changed or deleted, subject to moderation. Files expire on their configured date and are removed by scheduled cleanup. Trash and spam messages are removed after 30 days; mailbox quotas may require older messages to be removed sooner. Security and email delivery metadata is retained for 30 days by default, configurable from 7 to 90 days. Email bodies queued for delivery are encrypted at rest and removed after relay acceptance, terminal failure, or a maximum of 48 hours. Support requests are retained for up to 180 days; audit records for up to 365 days. Routine backups rotate after 14 days. Deletion may take that long to reach all backups.
Security and your choices
Passwords and API keys are stored as hashes. HTTPS protects connections, and access controls restrict private areas. No system is perfectly secure. You can edit your profile, unpublish it, disconnect Discord, rotate API keys, invalidate sessions or delete your account in settings. Do not include sensitive data in public profiles or unprotected file links.
Requests and contact
Contact [email protected] to request access, correction, export or deletion of information, or to ask about privacy. We may verify account ownership before responding. Available rights and response requirements depend on applicable law. Abuse and security reports may be sent to [email protected]. We will update this policy when practices change.