Keystone

Privacy Policy

Last updated: 7 September 2026

Keystone is made by TOCLOCO LTD and is built to keep your information private. This policy explains what we do — and, mostly, don't — do with your data.

The short version

We don't collect anything unless you ask us to. Keystone has no user accounts, no advertising, and no servers run by us. It connects only to Amazon Web Services, using your own credentials, or to a local endpoint you configure.

What we collect

Nothing by default. Keystone does not gather personal information, usage analytics, device identifiers, or location. There is no sign-up and no login to any Keystone service, because there is no Keystone service.

Two diagnostics are available and are off until you turn them on in Settings → Privacy:

  • Crash reports — the app's own call stacks and the OS and app versions, as provided by Apple's MetricKit. They cannot contain table data, attribute names or credentials.
  • Usage analytics — counts of events from a fixed list (a query was run, an export was made) under a random installation identifier you can reset. There is no field for anything else.

The app shows you exactly what each holds before you enable it. In the current release neither is transmitted; both are kept on your device.

Where your data lives

Your connections, query history, saved queries, column layouts and entity-type definitions are stored on your device, inside the app's own sandboxed container. They contain table and attribute names, never the contents of an item. None of it is transmitted anywhere.

Access keys, secrets and session tokens are stored in the Keychain, protected by your device's own security. They are never written to a configuration file and never leave your device except to authenticate to AWS. If iCloud Keychain is on, Apple syncs them between your devices end-to-end encrypted; we cannot see them.

On the Mac, Keystone reads shared AWS profiles from your ~/.aws folder only after you have granted it access to that folder, and only from there.

Your AWS account

Keystone makes network connections only to AWS endpoints for the account and region you configure, and to any local endpoint you point it at. It reads and writes the tables you ask it to. We have no visibility of which accounts you use, what you query, or what your tables contain.

What happens to your data once it reaches AWS is governed by Amazon's terms and by your own account's configuration.

The operation log

Keystone keeps a record of every request it makes in a session — the operation, its request body, duration and consumed capacity — so you can see exactly what happened. This log is held in memory on your device for the session, is never uploaded, and is discarded when the app quits.

Third parties

None. Keystone does not include third-party advertising, analytics, or tracking SDKs, contains no third-party libraries, and does not share your data with anyone.

Children

Keystone does not collect personal data from anyone, including children under the age of 13.

Your rights

Because we hold no personal data about you, there is nothing for us to access, correct, export, or delete. Your connections, credentials and history are yours: you can remove a connection and its stored credentials from within the app, clear the history, or delete the app entirely.

This website

This site sets no cookies and runs no analytics.

Changes to this policy

If this policy changes, we'll post the updated version on this page with a new date.

Contact

Questions about privacy? Email support@tocloco.com.

TOCLOCO LTD, registered in England & Wales (company no. 09950859), 71-75 Shelton St, London, WC2H 9JQ.