Zero-Knowledge • 100% Offline Password Manager

Legal & Transparency

Official Privacy Policy and Terms of Service governing the Password Vault mobile application on the Google Play Store.

📅 Effective Date: August 8, 2026
🛡️ Architecture: Air-Gapped & Encrypted at Rest
⚖️ Compliance: Google Play 2026 User Data Policy
🚫

Zero Internet

No network permissions

🔒

AES-256-GCM

Argon2id Key Derivation

⚡

Entropy Engine

Strong password generator

👆

Biometric Keystore

Hardware-backed unlock

01 Commitment to Zero-Knowledge Privacy

Your privacy is our fundamental core principle. Password Vault ("we", "our", or "the application") was engineered with an uncompromising zero-knowledge, 100% offline security architecture.

Unlike cloud-based password managers that transmit your confidential credentials to remote databases vulnerable to breaches, Password Vault operates exclusively on your physical Android device. We do not operate remote servers, we do not require account registration, and we have zero access to your master password or credentials.

✓ Air-Gapped Network Isolation

Password Vault strictly omits the android.permission.INTERNET permission from its Android Manifest. The application physically lacks the OS-level capability to transmit data over Wi-Fi, cellular, or Bluetooth networks.

02 Google Play Data Safety & Collection Disclosure

In accordance with the Google Play Developer User Data Policy, below is the comprehensive declaration of data handling:

Data Category Collected? Shared? Processing & Storage Mechanism
Credentials & Passwords NO NO Local AES-256-GCM Encrypted at rest. Key derived via Argon2id / PBKDF2.
Secure Notes & Metadata NO NO Zero Plaintext All titles, notes, and category labels are encrypted payloads.
Biometric Data (Fingerprint / Face) NO NO Android Keystore Managed strictly by Android OS Hardware Security Module.
Personal Info (Name, Email, Phone) NO NO Password Vault requires zero user accounts or registration.
Location & GPS Coordinates NO NO Zero location permissions declared.
App Telemetry & Crash Analytics NO NO Zero analytics trackers, telemetry, or advertising SDKs.

03 Cryptography & Key Derivation

Password Vault secures all stored secrets using state-of-the-art cryptographic primitives:

  • Authenticated Encryption: All database records are encrypted with 256-bit AES in Galois/Counter Mode (AES-256-GCM) with unique per-record 96-bit initialization vectors (IVs).
  • Memory-Hard Key Derivation: Master keys are derived using Argon2id (64 MB memory cost, 3 iterations) or PBKDF2-HMAC-SHA-256 (600,000 iterations), protecting against specialized GPU/ASIC brute-force attacks.
  • Zero Plaintext Storage: SQLite database tables contain only structural UUID identifiers and encrypted ciphertext envelopes. Record types (Credentials, Notes, Categories) are bound into AEAD Additional Authenticated Data (AAD) to prevent ciphertext substitution.

04 Biometric Authentication & Android Keystore

Password Vault integrates with native Android BiometricPrompt and AndroidKeyStore to wrap the Vault Data Encryption Key (VDEK):

  • No Raw Biometrics Access: The application never receives or stores your biometric templates. Verification is performed directly by the hardware-backed secure element.
  • Biometric Invalidation: In compliance with Android security standards, enrolling any new fingerprint or biometric credential on your device automatically invalidates the Keystore key binding, requiring master password re-authentication.

05 Privacy Hardening & System Defenses

To protect your credentials from background interception, screen readers, and malicious applications:

  • Screen Capture Protection (FLAG_SECURE): The application window blocks screenshots, screen recording, and recent apps task switcher previews.
  • Sensitive Clipboard Masking (Android 13+): When copying passwords or usernames, the payload is tagged with EXTRA_IS_SENSITIVE to suppress visual clipboard previews.
  • 30-Second Clipboard Auto-Clear: Copied credentials are automatically erased from the system clipboard after 30 seconds.
  • Disabled Auto-Backup: The Android Manifest specifies android:allowBackup="false", preventing unencrypted cloud syncing via Google Drive or ADB backup extraction.

06 Encrypted Backups (.pvault) & Storage Access Framework

Password Vault allows users to create portable, encrypted .pvault backup containers:

  • Framed Binary Container: Backups are protected by a user-defined backup password derived using Argon2id with a 16-byte salt and AES-256-GCM encryption bound to a PVAULT01 magic framing header.
  • Storage Access Framework (SAF): Backup export and import utilize Android’s native document picker (ACTION_CREATE_DOCUMENT and ACTION_OPEN_DOCUMENT), eliminating the need for broad storage permissions (READ_EXTERNAL_STORAGE / WRITE_EXTERNAL_STORAGE).
  • Portable Re-Encryption: Restoring a backup on a new device generates a fresh, local VDEK and re-encrypts all imported records securely.

07 Data Retention & Permanent Deletion

You maintain complete sovereignty over your data:

  • Individual Deletion: Deleting a login credential, category, or note instantly erases its encrypted record from the SQLite database.
  • Emergency Reset: Performing an emergency vault reset in Settings or clearing app data via Android Settings permanently destroys all database tables, preferences, and Android Keystore biometric keys.

⚠️ Irrecoverable Data Notice

Because Password Vault employs zero-knowledge cryptography without backdoor recovery mechanisms, if you lose your master password, biometric access, and have not created an encrypted .pvault backup, your vault cannot be recovered by the developers.

08 Children's Privacy (COPPA Compliance)

Password Vault is intended for use by adults managing personal credentials (ages 18 and older). We do not knowingly collect, store, or solicit information from children under the age of 13.

09 Contact & Policy Updates

We may update this Privacy Policy periodically to reflect emerging security standards or Google Play requirements. All modifications will be published directly to this page with an updated effective date.

If you have questions regarding this Privacy Policy or the security architecture of Password Vault, please contact at intellignt.phool@protonmail.com.

01 Agreement to Terms

By downloading, installing, accessing, or using the Password Vault application ("the App"), you agree to be bound by these Terms & Conditions ("Terms"). If you do not agree to these Terms, do not install or use the App.

02 License & Permitted Use

Subject to your compliance with these Terms, you are granted a limited, personal, non-exclusive, non-transferable, revocable license to use the App solely for personal, non-commercial security, credential management, and encrypted notes organization on your Android device.

You agree NOT to:

  • Modify, reverse-engineer, decompile, or disassemble any binary code of the App, except to the extent permitted by applicable open-source licenses.
  • Attempt to bypass security barriers, cryptographic controls, or memory isolation mechanisms.
  • Use the App for any unlawful purpose, fraud, or infringement of third-party intellectual property.

03 Zero-Knowledge Architecture & User Responsibility

You acknowledge and understand that Password Vault is a self-sovereign, zero-knowledge offline application:

🔑 Master Password Custody Responsibility

You maintain exclusive custody of your master password, biometric credentials, and .pvault backup passwords. The developer maintains zero master recovery keys, backdoors, or escrow mechanisms. Loss of your master password will result in permanent loss of access to your vault data.

04 Security Disclaimer

Password Vault is an encrypted local password manager and digital safe.

  • The App does not monitor the security of external websites or services where your credentials are used.
  • You are responsible for generating strong passwords, creating regular encrypted .pvault backups, and safeguarding your device PIN.

05 Disclaimer of Warranties ("AS IS")

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, PASSWORD VAULT IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.

While Password Vault uses industry-standard AES-256-GCM encryption, Argon2id key derivation, and Android Keystore protection, we do not warrant that the application will be 100% bug-free, uninterrupted, or immune to hardware-level side-channel attacks on compromised or rooted devices.

06 Limitation of Liability

UNDER NO CIRCUMSTANCES SHALL THE DEVELOPERS, AUTHORS, OR CONTRIBUTORS OF PASSWORD VAULT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, PUNITIVE, OR EXEMPLARY DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF DATA, LOSS OF PASSWORDS, UNAUTHORIZED ACCOUNT ACCESS ON THIRD-PARTY SERVICES, HARDWARE CORRUPTION, OR FINANCIAL LOSS RESULTING FROM THE USE OR INABILITY TO USE THE APPLICATION OR ENCRYPTED BACKUP CONTAINERS.

07 Intellectual Property Rights

All rights, title, and interest in and to the Password Vault application—including user interfaces, graphic assets, brand elements, and codebase—are the intellectual property of the developer and are protected by international copyright and trademark laws.

08 Modifications to Terms

We reserve the right to modify these Terms at any time. Any changes will become effective immediately upon publishing the updated Terms to this page. Your continued use of Password Vault following any modifications constitutes acceptance of the updated Terms.

09 Governing Law & Severability

These Terms shall be governed by and construed in accordance with the laws of your jurisdiction without regard to conflict of law principles. If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.