Privacy Policy
Last updated 12 September 2026. This policy is in effect; a few areas are still being refined with counsel, and any material change is announced by email, as the Changes section describes.
Key (operated by White Noise in a Snow Storm, LLC, “Key”, “we”) is a marketplace connecting travelers with vetted local experts for video calls at key.new. This policy explains what we collect, why, and what your choices are. White Noise in a Snow Storm, LLC is a Delaware limited liability company and is the controller of the personal data described in this policy.
What we collect
Account data: your name, email address, and timezone. Experts additionally provide profile content (photos, videos, bios, pricing) that is published publicly by design.
Bookings and the digital desk: call times, the notes, links, places, and messages you share on a booking’s shared desk. Desk content is visible to both participants of that booking.
Call recordings and transcripts: calls on Key are recorded and transcribed so both participants can replay them and keep the list of places discussed, this is a core feature, signalled by the recording indicator in the call. If you don’t want a call recorded, don’t take the call and contact us instead. By joining a call you consent to being recorded; recordings and transcripts are used under the license described in the Terms of Service.
Payments: handled by Stripe. Your card number never touches our servers; we store only booking amounts, refund state, and Stripe’s references. Experts’ bank and identity details for payouts are collected by Stripe directly, we never see them.
Post-call check-ins and surveys: after a call we may ask how it went. Your answer can affect whether the expert’s payout proceeds or a support ticket is opened, and we keep it with the booking. Optionally you can tell us your trip date and agree to a single follow-up email asking how the trip went; we use that for nothing else.
Expert applications: if you apply to become an expert, we keep your application (name, email, links, and what you wrote), including applications we decline, so we can reach out when opportunities open up, as our reply says. Ask us to delete your application at any time and we will.
Support: messages you send us and issue reports you file stay attached to the booking they concern until resolved and for our records.
Usage: privacy-preserving, cookieless page analytics (Vercel Analytics) and, if you arrived via a marketing link, the campaign parameters on that link. We do not run advertising cookies or cross-site tracking, and there is no session-recording of your browsing.
Product analytics and aggregated insights
We analyze activity on Key in aggregate, de-identified form, meaning we remove or generalize the details that could reasonably be used to re-identify a person and do not attempt to reverse that process, to understand and improve the product, to understand travel market trends and behavior, and to build features and insights from it, for example, lists of the places experts recommend most. Where such a feature shows which expert recommended a place, that attribution is part of the expert’s public profile by design. Clients are never identified in these features or analyses.
Cookies
Only strictly necessary ones: keeping you signed in, and a short-lived one while an expert connects a calendar. Nothing for marketing or tracking, that’s why there’s no cookie banner. If you arrive via a marketing link, we hold the campaign name in memory only while you’re on the site and save it if you sign up.
Google does not run as a script on our public, signed-out pages. The map on a public shared-list page is a static image our own server generates and serves from our own domain; your browser never contacts Google to display it, and clicking it opens Google Maps in a new browser tab, an ordinary outbound link you choose to follow. Place photos on those pages are resolved on our server and rendered as plain images requested from Google’s image CDN, an image request rather than a script. The interactive map, where you can search and pin places during a call, loads only for signed-in users on logged-in pages of the product. We run a nightly automated check of our public pages as a logged-out visitor and are alerted if a third-party script ever appears there.
Who processes data for us
Supabase (database, authentication, file storage), Vercel (hosting and cookieless analytics), Stripe (payments and expert payouts), Daily.co (video calls, recording, and transcription, where Deepgram performs transcription as Daily’s sub-processor, not a vendor Key contracts with directly), Resend (email), and Google (the static map image and place photos on our public pages, and the interactive map available to signed-in users during a call, see “Cookies” above for how each is served). Each receives only what its function needs and acts on our instructions. We never sell personal data, and we don’t share, transfer, or disclose it to anyone beyond these processors, except where the law requires it.
For personal data transferred from the EEA, the UK, or Switzerland to the United States, each processor’s data processing agreement, on file with us or incorporated automatically into the service agreement we hold with it, relies on the European Commission’s Standard Contractual Clauses and the UK’s International Data Transfer Addendum, or on that processor’s own certified transfer mechanism, such as active status under the EU-U.S. Data Privacy Framework and its UK Extension, where one applies.
Calendar sync, Google and Microsoft user data
Experts can connect Google Calendar or Outlook so Key bookings never clash with their life. When you connect Google Calendar, Key accesses exactly two things: your free/busy windows (times only, we deliberately request a scope that cannot read event titles, attendees, or contents) and write access to add, update, or remove the calendar events for confirmed Key bookings. Free/busy times are read transiently to compute open slots and are never stored. What we do store: the email address of the connected account (so your dashboard can show what’s connected) and the OAuth tokens that keep the connection alive.
How this data is protected: the OAuth tokens are encrypted at rest with AES-256-GCM on top of the database’s own encryption, the decryption key lives only in the server environment, all transfers use TLS, and access is limited to the server-side code that computes availability and writes booking events.
Sharing: we do not share, transfer, or disclose Google user data to any third party. It is never sold, never used for advertising, and never used to train AI models. It resides only with the infrastructure processors listed above (Supabase stores the encrypted tokens, Vercel runs the code that uses them), acting under our instructions, or where disclosure is required by law. Key’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your control: disconnecting a calendar in your dashboard deletes the stored tokens immediately, and you can also revoke Key’s access at any time from your Google Account’s security settings (myaccount.google.com/permissions). Outlook connections work the same way, under Microsoft’s equivalent controls.
How long we keep things
Your account and its content persist until you delete your account. Recordings and desks persist so participants can revisit them, ask us to delete a specific recording and we will. Transactional records are retained as bookkeeping requires. Where we delete a recording or a departing participant’s portion of one, we keep it no longer than 90 days after the deletion request, solely to investigate an open dispute, fraud, or safety report; a transcript with identifying details removed can be kept longer, since text is far more reliably de-identified than video or audio.
Your rights
Wherever you are, we honour the substance of GDPR-style rights: ask us for a copy of your data, a correction, or deletion at hello@key.new and a human will handle it. Deleting your account removes your profile and personal data; recordings involving another participant may be retained for them with your identity removed where technically feasible.
If you are a California resident, you additionally have the right under the CCPA and CPRA to know what personal information we have collected about you, to delete it, and to correct it; we do not sell or share personal information for cross-context behavioral advertising, so there is no opt-out to exercise for that. Call recordings can include your voice, and voice recordings can meet California’s definition of biometric information, but we do not process them to extract a voiceprint or otherwise identify you from your voice, so they are not sensitive personal information under the CPRA; if that ever changes, we will update this policy and give you the added rights that come with it.
Where data lives
Our infrastructure runs in the EU and US, and email delivery routes through our email processor’s Asia-Pacific region (see processors above). By using Key you accept that your data crosses those borders under the processors’ standard safeguards. These transfers are made under the safeguards described above.
EU and UK representative
Key has no office or establishment in the European Union or the United Kingdom, but offers paid services to people there, so under Article 27 of the GDPR and the equivalent UK requirement Key must appoint a representative in each. We are in the process of appointing them, and this section will name them, with their contact details, as soon as the appointments complete. Until then, contact Key directly at hello@key.new on any data protection matter and a human will handle it.
Children
You must be 18 or over to hold a Key account. A child may join a call alongside the adult who booked it, with that adult present; we don’t knowingly collect data from anyone under 18 beyond what’s in that call’s recording.
Changes
We’ll update this page as the product changes and note the date at the top. Material changes get an email.