Legal
Privacy policy
How KeyCare Pass handles your data.
Last updated 6 October 2026
KeyCare Pass is a password manager made by GovPAM. This policy covers the KeyCare Pass web vault at vault.keycarepass.com, the KeyCare Pass browser extension and the KeyCare Pass apps, and this website at keycarepass.com. When your organization runs its own KeyCare Pass server, that organization holds your data and its own policy applies too.
Your vault is encrypted before it leaves your device
Passwords, notes, cards and everything else in your vault are encrypted on your device with keys derived from your master password. The server stores only the encrypted result. GovPAM cannot read your vault, and we never receive or store your master password.
What we hold
- Your account: email address, optional name and account settings.
- Your encrypted vault data, attachments and Sends.
- Security data: the devices you sign in from (type, name and an identifier), sign-in times, and the IP addresses of requests, which we use to protect accounts and to stop abuse.
- Organization data: memberships, groups, policies and, when enabled, event logs.
- Billing data: your plan, its seats, and your payments (amounts, dates and PayFast's references). PayFast holds your card or bank details, not us.
What the browser extension does
The extension reads the forms on the page you are using so it can fill or save a login when you ask it to. It does not collect or send your browsing history. It talks only to your KeyCare Pass server. Website icons in your vault are fetched through your KeyCare Pass server, which means that server sees the domains of the websites you save.
What we do not do
- We do not sell or rent your data.
- We do not show advertising.
- We do not use third-party analytics or tracking in the vault, extension, apps or this website.
Services involved
- Hosting: KeyCare Pass at vault.keycarepass.com runs on servers operated by GovPAM in the European Union.
- Email: account and security emails are sent through Cloudflare Email Service.
- Payments: plans are paid through PayFast, by card or Instant EFT.
- Optional checks you start yourself: the exposed passwords report uses Have I Been Pwned's Pwned Passwords service. Your browser sends only the first five characters of a hash of each password, never the password.
- Two-step login with Duo or YubiKey, when you turn it on, uses those providers.
This website
- keycarepass.com is served by Cloudflare Pages. Like any web host, Cloudflare processes the IP address and other details of your requests to deliver and protect the site.
- The website sets no cookies and uses no analytics. It remembers in your browser's storage whether you closed the announcement bar or the plan helper; that information stays on your device.
- When you send a form (a quote request, partner application or message), its contents go to our support mailbox at support@keycarepass.com, hosted in Microsoft 365, through Cloudflare. We use them only to answer you.
- The free tools run in your browser. The breached password checker sends only the first five characters of a SHA-1 hash to Pwned Passwords; the other tools send nothing.
Keeping and deleting data
Your data is kept while your account exists. You can delete your account at any time from the web vault under Account settings, which deletes your vault and account data from the server.
Contact
Questions about privacy: support@keycarepass.com. Security issues: security@keycarepass.com.