01 Commitment to Zero-Knowledge Privacy
Your privacy is our fundamental core principle. Password Vault ("we", "our", or "the application") was engineered with an uncompromising zero-knowledge, 100% offline security architecture.
Unlike cloud-based password managers that transmit your confidential credentials to remote databases vulnerable to breaches, Password Vault operates exclusively on your physical Android device. We do not operate remote servers, we do not require account registration, and we have zero access to your master password or credentials.
✓ Air-Gapped Network Isolation
Password Vault strictly omits the android.permission.INTERNET permission from
its Android Manifest. The application physically lacks the OS-level capability to transmit
data over Wi-Fi, cellular, or Bluetooth networks.
02 Google Play Data Safety & Collection Disclosure
In accordance with the Google Play Developer User Data Policy, below is the comprehensive declaration of data handling:
| Data Category | Collected? | Shared? | Processing & Storage Mechanism |
|---|---|---|---|
| Credentials & Passwords | NO | NO | Local AES-256-GCM Encrypted at rest. Key derived via Argon2id / PBKDF2. |
| Secure Notes & Metadata | NO | NO | Zero Plaintext All titles, notes, and category labels are encrypted payloads. |
| Biometric Data (Fingerprint / Face) | NO | NO | Android Keystore Managed strictly by Android OS Hardware Security Module. |
| Personal Info (Name, Email, Phone) | NO | NO | Password Vault requires zero user accounts or registration. |
| Location & GPS Coordinates | NO | NO | Zero location permissions declared. |
| App Telemetry & Crash Analytics | NO | NO | Zero analytics trackers, telemetry, or advertising SDKs. |
03 Cryptography & Key Derivation
Password Vault secures all stored secrets using state-of-the-art cryptographic primitives:
- Authenticated Encryption: All database records are encrypted with 256-bit AES in Galois/Counter Mode (AES-256-GCM) with unique per-record 96-bit initialization vectors (IVs).
- Memory-Hard Key Derivation: Master keys are derived using Argon2id (64 MB memory cost, 3 iterations) or PBKDF2-HMAC-SHA-256 (600,000 iterations), protecting against specialized GPU/ASIC brute-force attacks.
- Zero Plaintext Storage: SQLite database tables contain only structural UUID identifiers and encrypted ciphertext envelopes. Record types (Credentials, Notes, Categories) are bound into AEAD Additional Authenticated Data (AAD) to prevent ciphertext substitution.
04 Biometric Authentication & Android Keystore
Password Vault integrates with native Android BiometricPrompt and
AndroidKeyStore to wrap the Vault Data Encryption Key (VDEK):
- No Raw Biometrics Access: The application never receives or stores your biometric templates. Verification is performed directly by the hardware-backed secure element.
- Biometric Invalidation: In compliance with Android security standards, enrolling any new fingerprint or biometric credential on your device automatically invalidates the Keystore key binding, requiring master password re-authentication.
05 Privacy Hardening & System Defenses
To protect your credentials from background interception, screen readers, and malicious applications:
- Screen Capture Protection (
FLAG_SECURE): The application window blocks screenshots, screen recording, and recent apps task switcher previews. - Sensitive Clipboard Masking (Android 13+): When copying passwords or
usernames, the payload is tagged with
EXTRA_IS_SENSITIVEto suppress visual clipboard previews. - 30-Second Clipboard Auto-Clear: Copied credentials are automatically erased from the system clipboard after 30 seconds.
- Disabled Auto-Backup: The Android Manifest specifies
android:allowBackup="false", preventing unencrypted cloud syncing via Google Drive or ADB backup extraction.
06 Encrypted Backups (.pvault) & Storage Access Framework
Password Vault allows users to create portable, encrypted .pvault backup
containers:
- Framed Binary Container: Backups are protected by a user-defined backup
password derived using Argon2id with a 16-byte salt and AES-256-GCM encryption bound to a
PVAULT01magic framing header. - Storage Access Framework (SAF): Backup export and import utilize Android’s
native document picker (
ACTION_CREATE_DOCUMENTandACTION_OPEN_DOCUMENT), eliminating the need for broad storage permissions (READ_EXTERNAL_STORAGE/WRITE_EXTERNAL_STORAGE). - Portable Re-Encryption: Restoring a backup on a new device generates a fresh, local VDEK and re-encrypts all imported records securely.
07 Data Retention & Permanent Deletion
You maintain complete sovereignty over your data:
- Individual Deletion: Deleting a login credential, category, or note instantly erases its encrypted record from the SQLite database.
- Emergency Reset: Performing an emergency vault reset in Settings or clearing app data via Android Settings permanently destroys all database tables, preferences, and Android Keystore biometric keys.
⚠️ Irrecoverable Data Notice
Because Password Vault employs zero-knowledge cryptography without backdoor recovery
mechanisms, if you lose your master password, biometric access, and have not created an
encrypted .pvault backup, your vault cannot be recovered by the developers.
08 Children's Privacy (COPPA Compliance)
Password Vault is intended for use by adults managing personal credentials (ages 18 and older). We do not knowingly collect, store, or solicit information from children under the age of 13.
09 Contact & Policy Updates
We may update this Privacy Policy periodically to reflect emerging security standards or Google Play requirements. All modifications will be published directly to this page with an updated effective date.
If you have questions regarding this Privacy Policy or the security architecture of Password Vault, please contact at intellignt.phool@protonmail.com.