Privacy policy
What we collect, why we collect it, and how little of it there actually is.
Your vault is local first
Activated passes are written to your browser, on your device, in local storage. Until you press Sync they are not uploaded, not mirrored, and not readable by us. Clearing your browser data deletes the unsynced ones permanently.
That is why the vault list renders instantly — and why we cannot recover a pass for you if it was cleared before it was synced.
What an account stores
We store your email address, your name, and a bcrypt hash of your password — never the password itself. There is no social login, so no third-party identity provider is told that you use this service.
Pressing Sync in the vault uploads your pass records so they survive a cleared cache. Nothing is uploaded until you press it.
What leaves your device otherwise
When you activate or check a code, the code itself is validated against the issuer. That request carries the code and nothing else — no name, no email, no address.
Analytics
We count page views and activation outcomes in aggregate to spot outages. There are no third-party advertising trackers, no cross-site identifiers, and no profile built about you.
Deleting your data
Clearing the vault removes local records immediately. Deleting your account removes the stored email, password hash and every synced pass along with it.