Rekey
Privacy Policy
Last updated: September 16, 2026
Rekey tells you whether a password has turned up in public breach data, then turns that answer into an ordered cleanup plan. It is built so that the password you type never leaves your device — not to us, and not to anyone else. This policy explains exactly what happens to it.
What we collect
Rekey has no account system, analytics SDK, crash reporter, or advertising code. Pinnacle Path LLC does not operate a server that receives your password checks or locally saved app data. Password breach lookups go directly to the third-party service described below, and Apple handles subscription purchases.
If you email hello@pinnaclepath.ai, you provide your email address and anything you include in your message. Please never send passwords or payment details. This support correspondence is separate from the app's locally stored data.
Your password never leaves the device
When you check a password, Rekey computes a SHA-1 fingerprint of it on your device. Only the first five characters of that 40-character fingerprint are ever sent anywhere. The remaining 35 characters — and the password itself — never leave your iPhone. Rekey processes the password in memory and clears the password entry field when a check starts. It does not save the plaintext password to disk, the keychain, or logs. Session reuse detection retains derived fingerprints in memory, not the plaintext password. You can clear those fingerprints using Clear session memory in Rekey's Settings.
Password breach lookup
Rekey sends the first five characters of the SHA-1 fingerprint to the public Pwned Passwords range API at api.pwnedpasswords.com. The service returns candidate fingerprint suffixes, and Rekey performs the final comparison on your device. This is a k-anonymity range lookup: the request does not include your plaintext password, the full fingerprint, or an indication of which returned entry matched.
No API key, no account, no device identifier, and no name is attached to that request. The Pwned Passwords corpus contains passwords only — no email addresses, no usernames, nothing tied to a person. As with any internet request, the operator of that service and its CDN necessarily see the originating IP address; Pinnacle Path LLC does not, and receives no part of this exchange. Their handling of requests is governed by their own privacy policy at haveibeenpwned.com.
Where your data lives
Rekey saves your cleanup-plan items, account labels, priority accounts, completion status, and associated result information, such as exposure counts, on your device. Plan records use the device's keychain. Preferences, onboarding state, and Learn reading progress use local app storage. Plaintext passwords and session fingerprints are not saved with those records. Rekey does not implement its own cloud-sync service.
Notifications
Rekey requests exactly one permission, notifications, and only if you turn on the monthly re-check reminder. That reminder is scheduled locally on your device. We operate no server that sends you messages and use no remote push notification service. No other permission is ever requested.
In-app subscriptions
Subscriptions are processed entirely by Apple via StoreKit 2. Pinnacle Path never sees your payment details, billing information, or Apple ID. Rekey uses Apple's StoreKit to display products and localized prices, check offer eligibility, and verify purchases and subscription access. Apple processes payments; Rekey does not receive your payment-card details.
Third-party SDKs
None. Rekey has zero third-party frameworks, tracking libraries, crash reporters, or analytics integrations.
Your rights
Your password checks and saved app records are not held on a Pinnacle Path server for us to retrieve or delete. You can manage local records in the app. For privacy requests concerning information you have emailed us, contact hello@pinnaclepath.ai.
Deletion: To reset your local app data, open Rekey → Settings → Reset all local data, then confirm Reset everything. This resets the cleanup plan, priority account labels, reading progress, preferences, session memory, and local reminders. Use this control before uninstalling rather than relying on uninstalling alone to clear keychain records. Deleting local app data does not cancel an Apple subscription or delete support emails.
Notifications: Turn off the reminder inside Rekey, or manage notification permission in iOS Settings → Notifications → Rekey.
California residents (CCPA): Pinnacle Path LLC does not sell or share your personal information, as those terms are defined under the California Consumer Privacy Act. There is no data to opt out of selling because no sale or sharing occurs.
GDPR: If you are in the European Economic Area, you may contact hello@pinnaclepath.ai about privacy rights relating to information you have provided to us. Local app records are managed on your device as described above.
Children
Rekey is intended for adults, consistent with our Terms of Use. Please contact hello@pinnaclepath.ai if you believe a child has provided personal information to us through support correspondence.
Not a security guarantee
Rekey reports whether a password appears in a public breach corpus. A password that is not found has not been proven safe — it may appear in breaches that are not public, or become exposed later. Rekey is a hygiene tool, not a guarantee that an account is secure.
Changes to this policy
If we update this policy, we will revise the Last updated date and provide any notice or obtain any consent required by applicable law. The current password-check flow sends only the first five characters of the SHA-1 fingerprint, not the plaintext password, full fingerprint, or remaining 35 characters.
Contact
Questions about this policy: hello@pinnaclepath.ai