Skip to content
Keymark keymark/legal/privacy.md
EN ES
Download↓

Outline

  1. §1Read
  2. §2AI included
  3. §3Since you last read
  4. §4Run sheet
  5. §5Workspace
  6. §6Editor
  7. §7Privacy
  8. §8How it works
  9. §9Download
  10. §10FAQ
↓Download Keymark
EN ES

Outline

  1. The short version
  2. §1Who is responsible for your data
  3. §2Legal framework
  4. §3What stays on your device
  5. §4When Keymark connects to the internet
  6. §5Data that reaches Key Lab
  7. §6The Keymark website
  8. §7What we never do
  9. §8Providers and international transfers
  10. §9Your rights
  11. §10Additional rights in the EU/EEA, UK and Switzerland
  12. §11How to exercise your rights: queries and complaints
  13. §12Security
  14. §13Changes and effective date
← Back to Keymark

Keymark Privacy Policy

Personal Data Processing Policy (Política de Tratamiento de Datos Personales) for Keymark · Version 1.0 · Effective October 7, 2026

This policy explains what happens to your data when you use the Keymark desktop app and the Keymark website (the landing page from which you download the app). It complements the general data policy of Key Lab, available at https://keylab.tech/es/privacidad, which covers Key Lab's corporate website and its other services. If the two differ on something specific to Keymark, this policy prevails for Keymark.

The short version

  • Your documents never leave your device because of Keymark. Reading, search and the built-in AI all run on your computer. We don't receive your files, your questions or the AI's answers.
  • No account. You don't sign up, and we don't know who you are.
  • Usage statistics are off unless you turn them on. If you do, they are anonymous: a few events such as "app started" or "document opened (size between 1 and 10 MB)", never file names, paths or content.
  • You can see and stop the traffic. The Privacy Center in the app lists the requests Keymark makes, and offline mode turns them off.
  • Crash logs stay on your computer. Nothing is sent unless you choose to send it to us.
  • The website has no analytics, no advertising cookies and no trackers.
  • We don't sell your data, show ads or use your documents to train AI.

1. Who is responsible for your data

The data controller (Responsable del Tratamiento) is:

KEY LAB TECHNOLOGY S.A.S. ("Key Lab", "we") NIT 902.055.710-1 Calle 28 No. 84-195, Medellín, Antioquia, Colombia Phone: +57 317 293 5244 Email: [email protected] Website: https://keylab.tech

Requests about personal data are handled by Key Lab's data protection team through the email above.

2. Legal framework

We process personal data in accordance with Colombia's Ley Estatutaria 1581 de 2012 and Decreto Único Reglamentario 1074 de 2015 (which compiles Decreto 1377 de 2013), the guidance of the Superintendencia de Industria y Comercio (SIC), and the principles of legality, purpose, freedom, truthfulness, transparency, restricted access, security and confidentiality.

If you are in the European Union, the European Economic Area, the United Kingdom or Switzerland, we also apply the General Data Protection Regulation (GDPR) and equivalent laws as described in Section 10.

Definitions. Personal data is any information linked or linkable to an identified or identifiable person. The titular (data subject) is the person the data is about. Processing (tratamiento) is any operation on personal data, such as collecting, storing, using or deleting it.

3. What stays on your device

Keymark is a local-first app. The following is created and kept only on your computer. Key Lab does not receive, access or control it, so it is not processed by Key Lab:

  • the documents and folders you open, and the copies you save or export;
  • search indexes of your workspaces;
  • your recent files, favorites and reading positions, and the "since you last read" snapshots used to show what changed;
  • your conversations with the AI, Run sheet progress and AI answers;
  • the built-in AI model and any model you install;
  • settings (including the address of any AI server you configure);
  • the network activity log shown in the Privacy Center;
  • application logs, AI runtime logs and crash logs.

How to delete it:

  • Privacy Center → Delete local data removes your history, reading state, conversations, Run sheet progress, network log and search indexes.
  • Uninstalling the app removes the app itself. Settings, downloaded models and logs remain in the app's data folders until you delete them: on macOS, ~/Library/Application Support/dev.keylab.keymark and ~/Library/Logs/dev.keylab.keymark; on Windows, %APPDATA%\dev.keylab.keymark and %LOCALAPPDATA%\dev.keylab.keymark.

4. When Keymark connects to the internet

Keymark works offline. It connects to the internet only in the cases below. Offline mode (Settings → Privacy) turns all of them off, except opening a link, which simply hands the link to your web browser. The Network activity list in the Privacy Center shows the requests Keymark makes, with the date, the server's name and the purpose (not the full address or any content).

Every internet connection reveals your device's IP address and basic technical information (such as the app version in the request headers) to the server you connect to. Keymark does not add identifiers of its own.

4.1 Anonymous usage statistics (optional, off by default)

If you turn on Anonymous usage statistics in Settings → Privacy, Keymark sends a small number of events to Aptabase, an analytics service built for privacy, on its servers in the European Union.

  • Events: app started; document opened (size range only); view mode used (read, edit or split); AI action used (which action, and whether the AI ran on your device, on your local network or in the cloud); model installed (size tier); export (HTML or print); and error (a fixed error code). The current list is published in Keymark's telemetry documentation.
  • With each event: the time, the app version, the operating system and its architecture, whether it is a development build, and a session identifier that changes every time you open the app and is never stored.
  • Never sent: names of files or folders, paths, document content, questions, AI answers, search terms, your IP address as part of the event, or any identifier that persists across launches.
  • Purpose: to understand, in aggregate, which features are used and where the app fails, so we can improve it.
  • Basis: your consent, which you give by turning the option on and can withdraw at any time by turning it off. Keymark works exactly the same with statistics off.
  • Retention: events are kept for no more than 24 months and used only in aggregate.

Because these events don't identify you, we usually cannot link them to you to answer access or deletion requests; we can delete everything associated with a session only if you give us information that identifies it, which normally you won't have.

4.2 Updates

When Keymark checks for updates — when you click Check for updates in Settings and, if automatic checks are enabled, periodically — it downloads a small file from Key Lab's release server (https://keymark.keylab.tech, hosted on Railway behind Cloudflare), which tells it whether a new version exists for your channel (stable, beta or nightly). If you install an update, the app downloads it from the same server or its content delivery network. Updates are signed, and Keymark verifies the signature before installing.

The release server and its hosting provider see your IP address, the app version (in the request headers) and the channel. Purpose: to deliver updates and keep the service secure. Key Lab does not use this data to identify you, and server logs, if kept, are deleted after no more than 90 days.

4.3 Optional AI models from Hugging Face

The built-in AI model is included in the app, so no download is needed to use AI. If you choose to install an additional model, Keymark downloads it directly from huggingface.co, operated by Hugging Face, Inc. (United States). Hugging Face sees your IP address and which file you download, under its own privacy policy (https://huggingface.co/privacy). Key Lab does not receive this data. Model files are verified against Keymark's signed catalog before use.

4.4 Images from the web inside your documents

If a document you open contains images hosted on the internet, Keymark loads them, as a web browser would. The server hosting each image sees your IP address and may log the request. You can stop this with Settings → Remote images → Block or with offline mode. These image requests are made by the system web view and currently do not appear in the Network activity list. Images in AI answers are never loaded from the internet.

4.5 AI servers that you configure (optional)

Keymark can use an AI server that you choose, such as Ollama or LM Studio, instead of its built-in model. When you use it, Keymark sends that server the text needed to answer you — for example, your question, the relevant parts of the document, your selection or the list of changes.

That server's operator — you, your organization or a provider you chose — is responsible for that data, under its own terms and privacy policy. Key Lab does not receive it.

4.6 Opening links

When you click a web link in a document, Keymark asks your web browser to open it. From then on, your browser and the website you visit are responsible for your data.

5. Data that reaches Key Lab

Key Lab only receives personal data in these cases:

When Data Purpose Basis Kept for
You write to us (support, privacy, legal, security) Your name and email address, your message and anything you attach (for example, a log file you choose to send) Answer you, solve the problem, keep a record of the request Your authorization when you write to us; our legitimate interest in handling requests; legal obligations Up to 24 months after the conversation ends, or longer if the law requires it
You ask us to tell you about something new (for example, the Windows version or the WhatsApp integration) Your email address and your message Let you know when it is available Your consent when you write to us Until we let you know, or until you ask us not to
You turn on usage statistics See Section 4.1 See Section 4.1 Consent See Section 4.1

We will update this policy and the app before any new kind of collection starts.

6. The Keymark website

  • No analytics, no advertising cookies and no trackers. The Keymark website does not use analytics or advertising cookies, tracking pixels, social media plugins or third-party scripts or fonts. If it ever stores a technical preference on your device (such as your language), it is only to make the site work, and it is never used to track you.
  • Hosting. The website is hosted by Railway (Railway Corporation, United States) and delivered through Cloudflare (Cloudflare, Inc., United States). To deliver pages and downloads and to protect the site, both process technical data from your connection (IP address, browser, the page requested and the time). The Keymark site does not keep its own access logs; Railway and Cloudflare keep their technical logs for a limited time, under their own policies.
  • Downloads are served from a private storage service through short-lived links.
  • Links to other sites (for example, Key Lab's corporate site, GitHub or Hugging Face) are governed by those sites' policies.
  • Contact. If you write to us from the website, Section 5 applies.

7. What we never do

  • We don't sell, rent or share your personal data for advertising or commercial purposes.
  • We don't use your documents, questions or AI answers to train AI models — we don't receive them.
  • We don't build profiles or make automated decisions about you.
  • We don't ask for sensitive data (datos sensibles). Your documents may contain it, but they stay on your device.
  • Keymark is not directed at minors under 18, and we don't knowingly collect data from children or adolescents. If you believe a minor has sent us personal data, write to us and we will delete it.

8. Providers and international transfers

To run Keymark we rely on the following providers, which act on our behalf (encargados) under their own security commitments:

  • Aptabase — anonymous usage statistics (European Union), only if you turn them on;
  • Railway — hosting of the website, downloads and release server (United States);
  • Cloudflare — delivery and protection of the website (United States);
  • Apple (iCloud Mail) — Key Lab's email, to receive and answer your messages (United States).

Some of these providers are outside Colombia, in countries that the SIC may not consider to offer an adequate level of data protection. We transfer or transmit data to them only as needed for the purposes in this policy, under contracts that require them to protect it, and with your authorization, which you give by using these features after reading this policy. For users in the EU/EEA, transfers outside it rely on an adequacy decision or on the European Commission's Standard Contractual Clauses.

Hugging Face (Section 4.3), the operators of AI servers you configure (Section 4.5) and the websites hosting images in your documents (Section 4.4) are not our providers: you connect to them directly, and they act under their own policies.

9. Your rights

As a titular, under Ley 1581 de 2012 you have the right to:

a) know, update and correct your personal data; b) request proof of the authorization you gave us, unless the law does not require it; c) be informed, on request, of how we have used your data; d) file complaints with the Superintendencia de Industria y Comercio (SIC) for violations of data protection law, after first contacting us (Section 11); e) revoke your authorization and/or ask us to delete your data, when there is no legal or contractual duty to keep it; f) access your personal data free of charge.

10. Additional rights in the EU/EEA, UK and Switzerland

If the GDPR or a similar law applies to you:

  • Legal bases: consent (usage statistics and the news you ask us to send you), performance of the license agreement (supporting the app), legitimate interests (answering your messages, keeping our services secure) and legal obligations.
  • Your rights: access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent at any time without affecting earlier processing.
  • Complaints: you can complain to the data protection authority of the country where you live or work.
  • Representative: Key Lab has no establishment in the European Union. If Article 27 GDPR comes to require it, we will appoint a representative and publish their details here.

11. How to exercise your rights: queries and complaints

Write to [email protected] with the subject "Datos personales" / "Personal data", or send a letter to Calle 28 No. 84-195, Medellín, Antioquia, Colombia. Please include your name, your contact details, a description of what you request and, if you act for someone else, proof that you can represent them. We may ask for information to verify your identity before answering.

  • Queries (consultas) — for example, what data we have about you: we answer within 10 business days from receipt. If we cannot, we will tell you why and answer within the following 5 business days.
  • Complaints (reclamos) — to correct, update or delete data, revoke authorization, or report a breach of the law: we answer within 15 business days from the day after receipt. If we cannot, we will tell you why and answer within the following 8 business days. If your complaint is incomplete, we will ask you to complete it within 5 days; if you don't do so within 2 months, we will consider it withdrawn. While a complaint is pending, we will mark the data as "reclamo en trámite".

You can file a complaint with the SIC (https://www.sic.gov.co) only after completing this process with us (requisito de procedibilidad).

12. Security

Keymark is designed to need as little data as possible. We also protect what we process with reasonable technical, human and administrative measures: encrypted connections (HTTPS), signed updates and model catalog, restricted access to our systems, and providers with recognized security standards. On your device, Keymark limits file access to the folders you open, and its local AI runtime only listens on your own computer with a random key. No system is completely secure; if a security incident affects your personal data, we will notify you and the authorities as the law requires. To report a vulnerability, see Keymark's security policy or write to [email protected].

13. Changes and effective date

We will publish any change to this policy on the Keymark website, with a new date, and tell you in the app when the change is important. If a change requires your authorization (for example, a new purpose), we will ask for it before applying it.

This policy takes effect on October 7, 2026. The databases described in Section 5 are kept for as long as needed for their purposes and the periods stated there, and while Key Lab offers Keymark.

This policy is available in Spanish and English. If they differ, the Spanish version prevails.

<!-- end of legal/privacy.md -->

Keymark

The private, local-first Markdown reader for macOS and Windows, with AI that runs on your computer. A product of Key Lab, Medellín, Colombia.

Contact [email protected]

Product

  • Features
  • On-device AI
  • Privacy
  • Download
  • FAQ

Legal

  • Privacy Policy
  • EULA

Key Lab

  • keylab.tech
  • [email protected]
  • Español
© 2026 Key Lab Technology S.A.S. · Made in Medellín, Colombia Back to top ↑