Privacy Policy

Last updated: March 25, 2026

1. Overview

KeyVault is an internal API key and OAuth token management tool operated by Contablix SRL ("we", "us"), a licensed accounting firm based in Mendoza, Argentina. KeyVault is not a public-facing consumer product. It is used exclusively by authorized team members and automated agents within the Contablix organization.

2. Data We Collect

When you authenticate via OAuth (Google, Meta, X/Twitter, TikTok), we store:

  • Your OAuth access token and refresh token (encrypted at rest with AES-256)
  • Token metadata: provider, scopes, expiration dates
  • Your email address (from the OAuth provider, for identification)
  • Access logs: timestamp, action type, accessor identity

We do not collect passwords, payment information, or personal data beyond what the OAuth provider shares during authentication.

3. How We Use Your Data

  • To authenticate API requests on your behalf (e.g., posting to social media, reading analytics)
  • To automatically refresh tokens before they expire
  • To audit who accessed which credentials and when
  • To alert administrators when token refresh fails

4. Data Security

All tokens are encrypted at rest using pgcrypto AES-256 with a master key stored in environment variables (never in code or database). Access to decrypted tokens requires a valid agent token with appropriate scope. All access is logged to an immutable audit trail.

5. Data Sharing

We do not sell, share, or transfer your data to any third party. Tokens are only used to make API calls to the platforms you authorized (Google, Meta, X, TikTok) on behalf of the Contablix organization.

6. Data Retention

OAuth tokens are retained while active. Revoked tokens remain in the database (encrypted) for audit purposes but are never used for API calls. Access logs are retained indefinitely for compliance.

7. Your Rights

You can revoke any OAuth connection at any time from the KeyVault dashboard. Revoking a connection immediately prevents any further use of your tokens. To request deletion of your data, contact us at the email below.

8. Data Deletion

To request deletion of your data, revoke the OAuth connection in KeyVault or contact framirez@contablix.ar. We will delete all associated tokens and metadata within 30 days.

9. Contact

Contablix SRL
Mendoza, Argentina
framirez@contablix.ar