FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. Keybase

Keybase

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Keybase do?

Keybase is an end to end encrypted messaging, file sharing and identity verification platform acquired by Zoom in 2020. It offers chat (1:1 and group), encrypted file storage (KBFS), encrypted git repositories and a cryptographic identity proof system that links accounts to social media handles. Although message content is end to end encrypted, Keybase processes metadata (sender, recipient, timestamps, IPs, device identifiers) on US infrastructure, making it relevant for GDPR data transfer assessments.

What Keybase is and how it works

Keybase started in 2014 as a public directory that linked PGP keys to verified social identities (Twitter, GitHub, websites). It grew into a full end to end encrypted communications platform with chat, group teams, encrypted file storage (KBFS), encrypted git repositories and Stellar wallet integration. In 2020, Keybase was acquired by Zoom Video Communications to bolster Zoom''s end to end encryption capabilities. Active product development has slowed since, but the service is still operational and the open source clients are still maintained.

What data Keybase processes

Even with end to end encryption, Keybase processes substantial metadata: username, optional email, public PGP keys, identity proofs on social platforms, friend network and team memberships, device identifiers (one per install), IP address per session, message timestamps, file sizes and chat counts. The encrypted payloads of messages and files are stored on Keybase servers but cannot be decrypted by Zoom. The web client at keybase.io sets session and CSRF cookies during login.

GDPR implications

Keybase processes personal data of EU residents (username, email, IP, social graph) and is therefore subject to GDPR. Since Zoom is established in the US, transfers to Zoom servers in the US must be addressed via Standard Contractual Clauses and the EU, US Data Privacy Framework. The metadata processed can be considered low risk on its own but reveals communication patterns and identity links that may be sensitive in certain contexts (journalists, activists, regulated professions).

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and lawful basis

For an individual signing up to Keybase, the lawful basis is contract performance (Art. 6(1)(b) GDPR), since the service is requested by the data subject. For organisations deploying Keybase to employees, contract performance and legitimate interest in secure communications are typical bases, with employee information requirements. For the web client cookies, the ePrivacy Directive applies and consent is required for non strictly necessary cookies.

Data transfers and Zoom ownership

Since 2020, Keybase has been operated by Zoom (US), with infrastructure on AWS in the US. This puts Keybase squarely in the US transfer category. Standard Contractual Clauses apply, Zoom is certified under the EU, US Data Privacy Framework, and the strong end to end encryption of message content offers a substantive supplementary measure. Run a Transfer Impact Assessment if you deploy Keybase for sensitive use cases.

Practical compliance steps

For organisational use, sign the Zoom DPA (which covers Keybase), document Keybase in your record of processing activities, run a Transfer Impact Assessment for US transfers, inform users (employees or members), prefer device names that do not identify the bearer, avoid using Keybase identity proofs to link personal accounts to professional identities, and consider migrating to actively developed alternatives if you need long term roadmap certainty.

GDPR consent category

Essential

Websites using Keybase must obtain user consent under GDPR regulations.

Legal basisContract performance (Art. 6(1)(b) GDPR) for the messaging service; consent (Art. 6(1)(a)) for any marketing communications
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive (Cookie Law) for web client, CCPA

DPIA considerations

Keybase processes username, email address, public PGP keys, social media verification proofs, friend network (who you chat with), team memberships, IP address per session, device identifiers (one per Keybase install) and metadata about chat (timestamps, message counts, file sizes), although the content itself is end to end encrypted. Key DPIA considerations: (1) since 2020 Keybase belongs to Zoom (US), inheriting Zoom's US transfer posture; (2) metadata can reveal social graphs and communication patterns even without message content access; (3) public verification proofs link accounts to social handles, making them searchable and aggregatable; (4) account deletion does not always remove all server side metadata immediately; (5) Keybase is no longer actively developed and the long term roadmap is uncertain.

Sample consent text

We use Keybase for end to end encrypted communications. While message content is encrypted client side, Keybase (owned by Zoom Video Communications, USA) processes metadata such as your username, IP address and contact graph in the United States under Standard Contractual Clauses and the EU, US Data Privacy Framework. You can revoke this access at any time by deleting your Keybase account.

Technical details

Tracking methodEnd to end encrypted desktop and mobile client; web client at keybase.io
Server locationUnited States (Zoom Video Communications since 2020)
Cookieless tracking availableYes
Data transferred outside the EUKeybase is owned by Zoom Video Communications Inc. (United States) since 2020. Servers are hosted on AWS in the US. End to end encryption protects message content from server side access but metadata (sender, recipient, timestamps, IP addresses, device identifiers) is processed in the US under Standard Contractual Clauses and the EU, US Data Privacy Framework.

Third-party domains contacted

keybase.ioapi.keybase.iokeybaseusercontent.com

Cookies placed

NameTypeDurationPurpose
sessionStrictly NecessarySessionWeb client session cookie used to maintain authenticated state on keybase.io.
csrfStrictly NecessarySessionCross site request forgery protection token for the keybase.io web interface.

Keybase is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does Keybase set cookies on visitors?

Keybase is primarily a desktop and mobile client. The web version at keybase.io sets session and CSRF cookies on the keybase.io domain only for authenticated users, not for anonymous visitors browsing public profiles. There is no third party tracking widget for customer websites.

Is consent required to use Keybase?

For individuals signing up, consent is not the basis; the lawful basis is contract performance. For organisations deploying Keybase to employees, contract or legitimate interest applies and employees must be informed. Cookie consent applies to the web client at keybase.io.

What is the legal basis for processing data through Keybase?

Contract performance (Art. 6(1)(b) GDPR) for the messaging service itself, and legitimate interest (Art. 6(1)(f)) for security telemetry. Marketing communications from Zoom about Keybase products would require consent (Art. 6(1)(a)).

Does Keybase transfer data to the United States?

Yes. Since Zoom acquired Keybase in 2020, all infrastructure is operated by Zoom on AWS in the United States. Transfers rely on Standard Contractual Clauses and the EU, US Data Privacy Framework, where Zoom is certified.

Do I need a DPIA for Keybase?

A DPIA is recommended whenever Keybase is deployed by an organisation, especially for sensitive use cases (journalism, healthcare, legal, regulated industries). End to end encryption is a strong supplementary measure but metadata transfer to the US still merits documented assessment under Art. 35 GDPR.

How do I implement Keybase in a GDPR compliant way?

For organisational use, sign the Zoom DPA, document Keybase in your record of processing activities, run a Transfer Impact Assessment, inform users in the workforce or member privacy notice, prefer non identifying device names, and consider end to end encrypted EU alternatives if you need full EU residency.

What are alternatives to Keybase?

Element (Matrix protocol, can be self hosted in EU), Threema (Switzerland), Signal (US non profit), Wire (Switzerland and Germany), Olvid (France) and Tutanota (Germany) are end to end encrypted alternatives. For full EU residency and roadmap certainty, Element with EU hosting or Wire are the closest comparables.

How should my privacy notice describe Keybase?

State that Keybase (Zoom Video Communications Inc., USA) is the processor of communications and identity data, list the categories of metadata processed (username, email, IP, contact graph, device identifiers, message metadata) and note that message content is end to end encrypted, the legal basis, the retention, the US hosting and the transfer mechanism (SCCs, Data Privacy Framework).