Privacy policy
In one paragraph
The Access databases you open in Keyfield stay on your device: their contents and their names are never sent anywhere. Keyfield works with no internet connection, has no accounts and shows no ads. It does send anonymous usage statistics and crash reports, fetches app configuration, and talks to Google Play (through RevenueCat) for the Keyfield Pro purchase. All of this is described below, with how to have it deleted.
What stays on your device
- The databases you open. When you open a file, Keyfield copies it into the app’s private cache on the device and reads it there, read-only. The original is never changed. Keyfield holds no storage permission: it sees only the files you choose to open.
- Your Recent list (which files you opened) and your settings are stored in the app’s private storage.
- Exports and saved attachments (Keyfield Pro) are written where you choose to save them. They leave the device only if you share them yourself, and then they go wherever you send them.
Android’s automatic cloud backup is switched off for this app, so none of this is copied to your Google Drive either.
What leaves your device
Keyfield uses Google Firebase (Analytics, Crashlytics, Remote Config and App Check) to understand whether the app works and which features are used, and RevenueCat with Google Play Billing for the Keyfield Pro purchase. These send:
- Usage events — for example that a database was opened, with its Access version, its number of tables, whether it had a password and where the open started (Open with, share, the picker, Recent or the sample); that a file could not be opened and the reason; that an export was tapped, started, finished or failed, with its format, row count and whether it was filtered; how many attachment files were saved; and paywall and purchase events. File names, table names and database contents are never part of an event.
- Crash and performance data — the technical details of a crash, the device model, the Android version and the app version.
- App configuration — Remote Config fetches settings for the app, and App Check uses Google Play Integrity to confirm those requests come from the real app.
- Device and installation identifiers that these services use to tell one installation from another. They are not linked to your name or email. The Advertising ID is removed from this app and is not collected.
- Purchase status — handled by Google Play and RevenueCat under an anonymous app user ID, so the app knows whether Keyfield Pro is active and you can restore it. We never see your payment details.
This data is used to fix faults and to decide what to improve. It is not sold, and it is not used for advertising. The app has no ads.
Processors
- Google LLC — Firebase Analytics, Crashlytics, Remote Config and App Check, Play Integrity, and Google Play Billing (Firebase privacy, Google privacy policy).
- RevenueCat, Inc. — manages the Keyfield Pro purchase and its status (RevenueCat privacy policy).
- Cloudflare, Inc. — serves this website.
Deleting your data
Data on your device (copies of opened databases, recent files, settings): clear it from Settings → Apps → Keyfield → Storage → Clear storage, or by uninstalling the app. Exports you saved elsewhere are yours to delete. There is no copy anywhere else.
Data held by our processors (usage events, crash reports, installation identifiers and purchase records): email machadowg@gmail.com with the subject “Keyfield data deletion”. Because the app has no account, it helps to say roughly when you used it; we delete the analytics data we can associate with your request and confirm by reply within 30 days. Firebase Analytics data is also deleted automatically after the project’s retention period. Purchase records that Google Play and RevenueCat must keep for tax, fraud-prevention and accounting reasons are kept as long as the law requires, then deleted.
Children
Keyfield is a tool for reading database files and is not directed at children. It does not knowingly collect information from anyone under 13.
Your rights
Depending on where you live, you may have rights under the GDPR, the LGPD or the CCPA to access, correct, delete or export your data, and to complain to your data protection authority. Write to the address below; requests are answered within 30 days.
This website
This site runs no JavaScript — its content security policy forbids scripts entirely — and sets no cookies. Fonts are loaded from Google Fonts, which receives the request and the IP address that made it, as any web request does.
Changes and contact
If this policy changes, the date at the top changes with it, and earlier versions remain in the public repository this site is built from. Contact: machadowg@gmail.com.