Privacy
Last updated 3 October 2026
The short version
Keyzforge has no accounts, no analytics, no cookies and no tracking. Everything you do with your security key happens in your browser and goes straight to the USB device. We never see your key, its settings, its serial number or your passkeys.
What stays on your device
- USB and serial communication. Flashing, configuration and the serial monitor use WebUSB and Web Serial. The data moves between the browser tab and your board only.
- Device permissions. When you allow a device, your browser remembers that choice. You can revoke it in your browser's site settings.
- Theme preference. Your light or dark choice is saved in local storage under the key
kf-theme. - Saved files. Logs you export are created in the browser and saved where you choose.
Network requests
Keyzforge only contacts two places, and only when you open the Flash page or download firmware:
- GitHub's API (api.github.com), to list firmware releases. GitHub receives your IP address and browser details as with any website, under GitHub's privacy statement.
- Our firmware route (/api/firmware), which fetches the release file you picked from GitHub and passes it to your browser. It is limited to public firmware repositories and does not store or log what you download.
Fonts and all other assets are served from this site. No third-party scripts are loaded.
Server logs
Like any web server, our hosting provider may keep short-lived access logs (IP address, time, requested path) to keep the service running and to stop abuse. We do not use them to identify or profile anyone.
Children
Keyzforge is a developer tool and is not directed at children. It does not knowingly collect any personal data from anyone.
Changes and contact
If this policy changes, the date at the top changes too, and the history is visible in the public repository. Questions: [email protected].