KEYXE Privacy Policy.

This policy explains what information the KEYXE website collects, why, who processes it and how you can exercise your choices.

Effective date:

Who we are

KEYXE is a software product operated by ALDER HARBOR IMPORTS LLC, 30 N Gould St Ste N, Sheridan, WY 82801, US (“KEYXE”, “we”, “us”). We are responsible for the information described in this policy. You can reach us through the contact form or, for privacy requests, the data request form.

Scope

This policy covers the public website at keyxe.net, the interactive demo, and the contact, security-report and data-request forms. KEYXE does not currently offer customer accounts or live Amazon integrations; if that changes, this policy will be updated before any such service starts (see Future Amazon data).

Information we collect

Information you submit

  • Contact form: your name, email address, optional company name, the topic you choose and your message.
  • Security report form: optional name and email address, the report subject, category, your severity estimate, description, optional affected URL and reproduction notes.
  • Data request form: your email address, optional name, the request type and optional details.
  • Community ideas form (For Humanity): your email address, optional name, the topic you choose, your idea, and whether you agree to be contacted about it. Ideas are reviewed privately and are never published automatically.
  • For each submission we also store a case reference, timestamps, the version of the acknowledgment you accepted and an internal request identifier.

Information collected automatically

  • Request data processed by our hosting provider. When you visit the site or submit a form, Cloudflare processes technical data such as your IP address, browser user agent and request details in order to deliver and protect the service.
  • Bot protection. Pages with forms use Cloudflare Turnstile, which evaluates browser and device signals to tell people from automated abuse. Turnstile’s result is sent to our server and verified with Cloudflare.
  • Rate limiting. To limit abuse, our server stores a salted, one-way hash of your IP address combined with the form type, and a counter, for a short window. We do not store your raw IP address in our database.
  • Operational logs. Our API writes structured logs about request outcomes (for example, “accepted” or “validation failed”). Email addresses in logs are masked; message content, tokens and IP addresses are not logged.

We do not use analytics tools, advertising pixels or social-media trackers on this website.

The free learning tools (the Ads Metrics Calculator, the Break-Even ACoS Explorer and the MCP Learning Playground) run entirely in your browser. The numbers you type are not sent to KEYXE, to Amazon or to any AI provider. Display preferences such as reduced motion and high contrast are remembered only in your browser’s local storage.

Any open-source components KEYXE publishes in the future will contain only original code and fictional example data. They will never include personal information or data from Amazon accounts.

The interactive demo

The demo runs in your browser on synthetic, fictional data. It does not connect to Amazon and does not send the data you explore to KEYXE. If you save a demo bid proposal, it is stored only in your browser’s session storage for that tab and disappears when the tab is closed. Exports you download are generated in your browser.

How we use information

  • To respond to your message, report or request, and to keep a record of the correspondence.
  • To investigate and fix security issues you report.
  • To verify your identity and carry out privacy requests.
  • To protect the website and forms from abuse, fraud and spam.
  • To comply with legal obligations.

We do not sell personal information, use it for advertising, or use your submissions to train AI models. Where laws such as the GDPR apply, we rely on your request and our legitimate interests in responding and in keeping the service secure.

Service providers

  • Cloudflare, Inc. — website hosting (Pages), API hosting (Workers), the database that stores form submissions (D1), and bot protection (Turnstile).
  • An email delivery provider — once configured, used to send internal notifications of new submissions to the KEYXE team. Security-report notifications contain only the reference, category and severity estimate, not the report text. We will name the provider here when it is in use.

These providers process information on our behalf and under their own security and privacy commitments. We don’t share submissions with anyone else unless the law requires it.

Cookies and tracking

The KEYXE website does not set its own cookies. Cloudflare may use strictly necessary cookies or similar technologies for security and bot protection. The demo uses your browser’s session storage only for proposals you choose to save.

Retention

  • Rate-limiting records (hashed) are deleted automatically within about one day.
  • Duplicate-submission protection records are kept for 24 hours and then deleted automatically.
  • Form submissions are kept as long as needed to respond, handle follow-up and keep a record of security and privacy matters. A fixed retention period has not been set yet; when it is, this policy will state it. You can ask us to delete your submission at any time (see below).

Your choices and rights

You can ask to access, correct or delete personal information you submitted to KEYXE using the data request form. Depending on where you live, you may have additional rights, such as objecting to or restricting processing, or complaining to a data protection authority. We verify identity before acting on a request so that nobody else can obtain or delete your information, and we may keep limited records where the law requires it.

International processing

Cloudflare operates a global network, so your information may be processed in the United States and other countries where its infrastructure runs. Where required, such transfers rely on the safeguards our providers offer.

Security

We use HTTPS, server-side validation, bot protection, rate limiting, restricted database access and privacy-minded logging. No method of transmission or storage is completely secure. See the Security page for details, and report concerns through the security report form.

Children

KEYXE is a business tool and is not directed to children. We do not knowingly collect information from children. If you believe a child has submitted information, please contact us so we can delete it.

Future Amazon data

KEYXE does not currently access any Amazon seller or advertising account. If live integrations become available after the required Amazon approvals, they will work only with the account owner’s explicit authorization, separately for seller data and for advertising data. Before any such service starts, we will update this policy to describe what data is accessed, how it is used, stored and protected, how long it is kept, with whom it may be shared, and how it is deleted — including deletion after an account owner disconnects or revokes access, as Amazon’s policies require. We do not plan to request buyer personal information.

Changes to this policy

We will update this policy when our practices change and revise the effective date above. Material changes will be highlighted on this page.

Contact

Questions about this policy: use the contact form and choose “Security/Privacy”. Privacy requests: use the data request form.