Skip to content
KeySlice

Privacy Policy

Last updated: September 14, 2026

KeySlice ("we", "us", the "site") is a free touch-typing trainer at keyslice.app. Short version: the site never sees what you type, playing needs no account, and if you choose to create one we store your email address and your progress so it follows you between devices.

Who is responsible

KeySlice is run by an independent developer, not a company. For anything in this policy, including a request to see or delete your data, email hello@keyslice.app.

What you type

Everything the trainer does happens in JavaScript in your browser. The characters you type, the mistakes you make and the time between your keystrokes are read by the page to score the drill in front of you. Your keystrokes are never transmitted. No server receives them, and this does not change when you sign in — an account syncs your results, never a live record of your typing.

Your progress, without an account

Your per-key scores, your position on the lesson path and your settings (theme, sound, reduced motion) are written to your browser's localStorage under keys beginning keyslice.. Signed out, that storage is local to your browser and is never uploaded. Two consequences worth knowing: while you are signed out we hold nothing about you at all, so there is nothing on our side to hand over or delete, and clearing this site's data (or using a private window) erases your progress with no way for us to recover it.

Moving that progress to another computer means signing in, which is described below. Earlier versions of this site could also turn your progress into a transfer link, and that is no longer offered — but a link you already hold still works. Opening one on the settings page still reads it the same way: the whole payload sits in the URL fragment — the part after the # — which browsers by specification never send to any server, so it is not in our logs, not in Cloudflare's, and not in the logs of anything the link passes through. Nothing is written on the receiving browser until you have been shown what would change and have agreed to it. Such a link contains your typing history, so anyone you give it to can import it: treat it as private and do not post it in public.

The report at the end of a run also offers a result card: a picture of that run's speed, accuracy, level and drill seed, which you can save and post. It is drawn in your browser and saved by your browser, so the image never reaches us or anyone else unless you send it somewhere yourself. It carries those four things and nothing more — no name, no email, no account identifier, and not even the time you played — and this is true whether or not you are signed in. Unlike a transfer link, a result card contains none of your history, so it is safe to post.

If you create an account

An account is optional and exists for one reason: to sync your progress between devices. Everything in the trainer works without one, permanently, and we do not intend to change that. You sign in with Google, and we ask Google for the narrowest thing that identifies you: your email address and nothing else — no name, no profile picture, no contacts, no other Google data.

What an account stores:

  • your email address, and the account identifier Google uses for you;
  • when the account was created, and when you last signed in;
  • whether you confirmed you are 13 or older (see Children below) — the answer, never a date of birth;
  • your saved progress, in the same compressed form the transfer link uses. It is stored as an opaque block: our server writes it and reads it back to you, and never looks inside it.

Lawful basis. We store the above to provide the syncing you asked for when you chose to sign in. You can withdraw at any time by deleting your account, below.

Where it is stored. Cloudflare D1, in Cloudflare's Asia-Pacific region. Encrypted backups are taken nightly and kept for 30 days, then deleted.

Seeing, exporting and deleting your data

While signed in you can download everything we hold about you, and you can delete your account. Deleting removes your email address, your account record and your synced progress from our database immediately. It does not touch the copy in your own browser, which stays where it is so you can keep playing.

A deleted account can still appear in an encrypted backup until that backup ages out, which takes at most 30 days. After that, nothing of it remains.

If you cannot sign in, email hello@keyslice.app from the address on the account and we will do it for you.

If you stop using KeySlice. An account with no sign-in and no sync for 12 months is treated as abandoned: we delete it, along with its progress. We would rather hold nothing than hold an email address nobody is using.

Analytics

KeySlice can load Google Analytics 4, but only when the site is built with an analytics ID configured. When it is loaded, GA4 records aggregate visit data: which pages were viewed, approximate location derived from IP address, device and browser type, and referring site. It sets its own cookies to tell repeat visits apart. It does not receive what you type or your per-key scores, because those never leave the page. When no analytics ID is configured, no analytics script is requested at all.

See Google's Privacy Policy and the Google Analytics Opt-out Add-on if you would rather not be counted.

Advertising

KeySlice is supported by advertising served by Google AdSense. Google and its advertising partners may set cookies or read device identifiers in your browser to select ads, limit how often you see the same one, and measure whether an ad worked. What you type, your drill results and your progress are never sent to Google — not your keystrokes, which never leave the page, and not your synced progress, which we do not share with anyone.

You can review or switch off personalized advertising at Google My Ad Center, and read how Google uses data from sites that use its services in Google's partner-sites notice. Switching personalization off does not remove ads, it makes them less relevant.

Cookies

Signed out and with analytics disabled, KeySlice sets no cookies at all. Your progress and settings use localStorage, which is not a cookie and is not sent with any request. Signing in sets these, and nothing else:

  • __Host-session — keeps you signed in. Expires after 30 days. It cannot be read by scripts on the page, and what we store in our database is only a one-way hash of it, so a copy of our database does not let anyone sign in as you.
  • oauth_state, oauth_next, oauth_adult — carry you safely through the Google sign-in and guard against a forged sign-in request. They last 30 minutes and are deleted the moment sign-in finishes.
  • ks_signed_in and ks_fresh — tell the page you are signed in without it having to ask our server. They contain no personal data and no credential.

The other cookies that can appear are Google's: Google Analytics' own on a build where analytics is enabled, and Google AdSense's advertising cookies. If you are in the EEA, the UK or Switzerland, personalized advertising cookies are set only with your consent, which you are asked for before any such cookie is set and can change at any time. You can block or clear cookies in your browser whenever you like; signing out is the only thing that stops working.

Children

Playing KeySlice needs no account and collects nothing about you, so anyone can use the trainer. Creating an account asks your age first. If you are under 13 we do not create one — you keep the full trainer, with your progress in your own browser, and we hold nothing about you. We do not knowingly store personal information from anyone under 13. If you believe a child has created an account, email hello@keyslice.app and we will delete it.

Changes

When we update this policy, we will revise the "Last updated" date above.

Contact

Questions? Email hello@keyslice.app.