KeyRotate privacy policy

Effective 22 September 2026

KeyRotate is an API key manager for Mac, published by Enfour, Inc. This policy explains what it stores, what leaves your Mac and what Enfour receives.

What Enfour collects

Nothing. KeyRotate does not create an Enfour account, has no sign-in, and sends Enfour no analytics, usage statistics, crash reports or advertising identifiers. Enfour does not receive your keys, the names of the services you use, your spending figures or any record that you ran the app.

Where your keys are kept

Every key value is stored in the macOS Keychain as an item belonging to KeyRotate alone. Key names, labels, tags, accounts, plan costs, usage readings and settings are stored in the app's own container on your Mac. Nothing is stored on a server operated by Enfour.

The vault unlocks with Touch ID once per session and re-locks when KeyRotate goes to the background. Copying a key marks the clipboard as concealed and clears it after 30 seconds, unless you have copied something else in the meantime.

What leaves your Mac

KeyRotate contacts a service provider only when you ask it to verify, rotate, or read the usage and billing figures for a key you have stored. Those requests go directly from your Mac to that provider, carrying the credential the operation needs. Each provider applies its own privacy policy. There is no intermediary server, and Enfour is not a party to those requests.

If you configure notifications to an ntfy or Gotify server, KeyRotate sends alerts to the server address you enter. All requests use HTTPS and refuse redirects. Plain HTTP is accepted only for an address on your own machine or network.

Files KeyRotate writes

KeyRotate can reach only the files and folders you have picked yourself, remembered as macOS security-scoped bookmarks. When it updates a file it matches your variable by name and rewrites that line. It does not parse, copy or retain anything else in the file, and it keeps a local backup so a change can be undone.

Servers and other machines

If you add a server, KeyRotate connects over SSH to the host you specify, using credentials you supply, to read and update the files you have listed there. Those credentials are stored in the Keychain. Connections are made only to hosts you have configured.

If you pair KeyRotate with FrontierStack on the same Mac, the pairing lets KeyRotate hand a credential to FrontierStack over a local authenticated connection. This is a link between two apps on your own machine and does not reach Enfour.

Subscription

KeyRotate is sold as an auto-renewing subscription through the App Store. Apple processes payment, renewal, cancellation and refunds under its own terms. Enfour does not process your payment and does not see your payment details.

Backups

An encrypted backup you export contains your key values and the vault's settings, sealed with a key derived from a passphrase you choose. The file goes wherever you save it. Enfour cannot read it and cannot recover it if the passphrase is lost.

Children

KeyRotate is a developer tool and is not directed at children.

Retention and your choices

Because Enfour holds no data about you, there is nothing for you to request access to, correct or delete from us. Deleting the app removes its container data. Keychain items may remain until removed by the operating system or a later installation; you can delete them yourself in Keychain Access.

Support

If you contact support, we receive what you choose to send and use it to answer your request. Do not include key values or other secrets in a support message.

Contact and changes

Questions about this policy can be sent to support at frontierstack dot app. We may update this policy as the app or legal requirements change; the effective date above shows the latest revision.