Privacy
The desktop app does not have a cloud vault. Your passwords stay in the encrypted file on your disk.
The desktop may contact this website for a crash report, an update check, or a journey ping. Crash reports can be turned off. Turning them off means we cannot see the crash, so we cannot ship a fix for it. None of those calls include vault data. That is a hard rule.
What those calls may contain
- Crash: app version, operating system, version, architecture, crash time, reason, and stack
- Updates: app version, operating system, optional supporter key
- Journey: install id, app version, operating system, request IP, stored-item count, and counts for generator, security, settings, import, copies, unlocks, and donate overlay clicks. Never titles, URLs, usernames, or passwords
What they never contain
- Vault entries, titles, URLs, or passwords
- Master password
- Recovery kit file. That file stays on the USB stick or extra disk you chose. It is never uploaded
- A field named password, secret, token, vault, or entry (those requests are rejected)
The website download page asks for an email. That is the newsletter list. A confirm link is consent to product notes and to manual update mail. You can opt out of system stats on that form. Donate goes through Pay by Jag. This site does not store card numbers. A supporter key is shown only on your thank-you page after payment succeeds.
The browser plugin source is public at /extension so you can read the files that run in your browser. The desktop app is a signed installer. This site does not publish a way to unpack or read that app binary.
Support tickets are opened at /contact. We mail a private 64-bit link so you can read and reply. That page does not publish a staff mailbox. Ticket pictures stay on this site.