Privacy Policy
Last updated 31 August 2026
Secure Pass is built on a zero-knowledge architecture: your master password and the contents of your vault are encrypted and decrypted entirely on your device. We do not have the technical ability to read your saved passwords, cards, notes, or any other credential data — not because of a policy, but because we never receive it in a form we could read.
This policy explains what we do collect, why, and who it's shared with.
What we can't see
- Your master password — it never leaves your device, in any form.
- The contents of your vault — every credential is encrypted with AES-256-GCM using a key derived from your master password before it is sent to our servers. We store only ciphertext.
- Item labels/names — encrypted individually, the same as credential data.
What we do collect
- Account details — email address, username, first and last name, and a salted hash of your derived authentication key (never your password itself).
- Encrypted vault data — ciphertext, initialisation vectors, and authentication tags for each item. This is meaningless without your master password.
- Item metadata — credential type (e.g. "password", "payment card"), a favicon URL derived from a website hint you provide, favourite/sort state, and timestamps. This is not encrypted, as it's needed to render your vault list.
- Security & audit events — login and account-change events are logged with IP address, user agent, and timestamp, to help detect suspicious activity and support account recovery.
- Device information — on mobile, a per-install device identifier is used to enforce trusted-device approval for vault access.
- Passkey public keys — if you register a passkey (Face ID, Touch ID, Windows Hello), we store the public key and metadata your device provides. Biometric data itself never leaves your device; we never receive it.
- Subscription status — your plan tier and Stripe customer/subscription identifiers. Payment card details are handled entirely by Stripe and never reach our servers.
Who we share data with
We use a small number of service providers to operate Secure Pass. Each only receives what it needs to do its job:
- Stripe — payment processing and subscription billing.
- Resend (or your configured SMTP provider) — transactional email, such as verification and recovery emails.
- Twilio — SMS delivery, only if you opt in to phone-based account recovery.
- Anthropic — only if card/document scanning is enabled on your account and you choose to use it. A photo you capture is sent for one-time field extraction and is not stored by us or, per Anthropic's API terms, retained by them beyond processing the request.
We do not sell your data, and we do not use advertising or analytics trackers.
Data retention & deletion
Your account and vault data are retained for as long as your account is active. You can delete individual vault items at any time, and delete your account and all associated data yourself from Settings → Security → Danger Zone — see how to delete your account.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data (for example, under GDPR in the EU/UK or CCPA in California). Because vault contents are encrypted end-to-end, we can export or delete the ciphertext on your behalf, but cannot decrypt it for you.
Contact
Questions about this policy or your data can be sent to support@securepassvault.app.
This document describes Secure Pass's actual data handling as implemented in the product. It is provided as a plain-language reference and has not been reviewed by a lawyer — before relying on it as a binding legal policy (including for GDPR/CCPA compliance claims), have it reviewed by qualified counsel for your jurisdiction.
