Privacy Policy
Request account and data deletion
Android 26.8.5 disables usage collection by Firebase Analytics and does not offer in-app ads or purchases. Crash diagnostics, app configuration, integrity checks, and optional sign-in and sync still process data. The analytics and purchase entries below apply to earlier versions where those features were enabled.
Crashlytics and its supporting Firebase Installations and Sessions libraries process installation identifiers, device/app information, and session timing for crash and stability metrics. There is no in-app switch to disable this collection in Android 26.8.5. Remote Config processes an installation identifier, country/language codes, time zone, and app/OS versions to retrieve feature configuration. Optional sign-in can also provide a profile name; Firebase Authentication processes IP addresses to prevent abuse.
Password Manager (the “App”) stores your accounts, passwords, and TOTP seeds encrypted on your device by default. Only when you turn on sync, Google/Apple sign-in identifies the owner of ciphertext, and Firebase Firestore stores account data encrypted on device, a sync key wrapped as nonce/ciphertext/MAC, the record IDs, update times, revisions, deletion states, the sync-key-envelope revision and random change ID, and cryptographic metadata—including KDF salt—needed for sync. Account names, passwords, and TOTP seeds remain only inside ciphertext. A limited set of data may be processed through third-party SDKs for crash reporting, usage analytics, payments, and optional sync.
1. Never collected or transmitted in plaintext
- Account names, passwords, and TOTP seeds: stored in an on-device encrypted database (SQLCipher). If sync is on, their contents are encrypted first and transmitted only inside ciphertext; the sync metadata listed below is sent in separate fields.
- Autofill identifiers: web domains, Android package names, and iOS service identifiers are stored as account metadata to match login screens. If sync is on, they are included only inside encrypted account records and are not sent in plaintext to analytics, crash reporting, ads, or payment SDKs.
- Your master password, database encryption key, and local backup files: not sent to Firebase Auth, Firestore, Analytics, Crashlytics, or payment SDKs.
- If app lock is enabled, PIN / biometric state is kept in the device’s secure storage.
- If you do not use sync, account data remains local-only.
Local handling by the Chrome extension
The Passwordmanager Chrome Extension works with the separately installed macOS desktop app to fill a selected account into the current HTTPS login page or, after explicit approval, save or update credentials entered on a supported signup or account-change page.
- Only after the user requests a search from the extension popup, the extension sends the exact HTTPS origin of the current top-level page to the fixed local Native Messaging host. The origin is used only to find an exact account match and is not stored by the extension or sent to a developer server.
- During fill, the page detector reports only whether supported username and password fields exist and does not read typed values. For save or update, it reads only the supported username and password fields after you open the extension-owned save UI and confirm the detected action. It never collects selectors, DOM text, HTML, unrelated fields, or general form contents.
- Save or update values pass only to the fixed local app. The app displays the proposed create, password-update, or username-update action and requires its own confirmation and operating-system authentication. The extension then verifies the same top-level HTTPS document and fields still contain the approved values before one commit. Navigation, changed values, cancellation, expiry, replay, iframe use, app lock, or transport failure prevents the mutation.
- After the user selects an account, its username and password pass transiently from the running local app through the extension into the captured fields on the current user-selected page. The destination website can process the filled values, so use the feature only on sites you trust.
- The extension does not retain a vault, master password, key, account, password, origin, or browsing history in browser storage. It sends none of this data to Firebase, developer servers, analytics, advertising, crash reporting, or human review, and does not log related payloads.
- Fill candidate state remains in service-worker memory for at most 30 seconds, and a pending save approval for at most 60 seconds. App lock, navigation, origin or document mismatch, iframe use, expiry, replay, or transport failure prevents credential delivery or storage.
Information handled by the extension is used only to provide its disclosed single purpose and complies with the Limited Use requirements of the Chrome Web Store User Data Policy. It is not used or transferred for advertising, personalization, sale, credit assessment, or unrelated purposes. Removing the extension removes its browser components; separate local app data remains subject to the App retention and deletion policy below.
2. Data collected and transmitted
The App processes the data below through the listed third-party SDKs. However, generation/lifecycle-based remote deletion and reactivation and the related Firebase Functions are not yet active in production. The key epoch, generation ID, lifecycle state, temporary operation metadata, and lifecycle-specific limited-use App Check token/replay-protection processing described below apply only after that feature is activated in production and a user invokes the relevant flow. Separately, in app versions that include App Check, Firebase App Check—backed by Google Play Integrity on Android or Apple App Attest/DeviceCheck on iOS—may process app/device integrity signals that do not contain saved-account contents during initialization or token issuance.
| Data type | Elements | Purpose | Processor |
|---|---|---|---|
| App activity / identifiers | App instance ID, usage events | Analytics & improvement | Firebase Analytics |
| Diagnostics / crashes | Crash logs, device & OS info | Stability | Firebase Crashlytics |
| App/device integrity | App attestation token and app/device integrity signals (never saved-account contents) | App Check initialization/token issuance and prevention of forged or replayed remote sync deletion/reactivation requests | Firebase App Check, Google Play Integrity, Apple App Attest/DeviceCheck |
| Sign-in identifiers | Firebase uid, sign-in provider information, and sign-in account data such as email when provided by the provider | Identify the owner of optional sync ciphertext | Firebase Auth, Google/Apple Sign-In |
| Sync data | Account-record ID, updated time, revision, deletion state, content/encryption/KDF identifiers, and nonce/ciphertext/MAC. Sync-key-envelope revision, random change ID, key epoch/random generation ID, lifecycle status/time, content/encryption/KDF identifiers, Argon2id KDF salt, and wrappedKey encoded as nonce/ciphertext/MAC. During deletion/reactivation, an opaque request ID, target generation, status, and page cursor are stored temporarily. Random IDs are not derived from user data or key material. Account ciphertext may include account names, passwords, TOTP seeds, and autofill identifiers. | User-enabled cross-device sync and safe deletion/reactivation | Firebase Firestore/Functions |
| Purchase history | In-app purchase transactions | Sponsorship | Apple App Store / Google Play |
3. Third-party sharing
The data above is shared with the following providers solely to deliver the related features. The App does not sell data.
- Google (Firebase): analytics, diagnostics, sign-in identifier processing, sync-data storage (ciphertext and metadata), and App Check/Play Integrity verification.
- Apple: Apple-platform app integrity verification through App Attest or DeviceCheck.
- Apple / Google: Apple/Google sign-in and in-app purchase processing.
See the Google Privacy Policy and Apple Privacy Policy.
4. Data security
- Accounts, passwords, and TOTP seeds are encrypted with SQLCipher and stored on the device by default.
- If sync is on, Firestore stores account data encrypted on device, a sync key wrapped as nonce/ciphertext/MAC, and required unencrypted sync/cryptographic metadata including the envelope revision, random change ID, and KDF salt. Account names, passwords, and TOTP seeds are not stored in plaintext.
- The master password is used only on device to wrap or unwrap the sync key and is never sent to the server. Encrypted sync data cannot be recovered if the master password is lost.
- When enabled by the user, app lock (PIN / biometrics) prevents unauthorized access at app entry.
- Copied passwords are automatically cleared from the clipboard after a short delay.
- Data sent over the network is encrypted in transit (HTTPS).
5. Retention and deletion
- Local data (accounts, passwords, and TOTP seeds) is deleted when you delete items in the App or uninstall the App.
- If sync is on, whether an item is deleted is synchronized in Firestore as unencrypted deletion-state metadata.
- The currently deployed remote-sync deletion flow is a point-in-time operation that deletes encrypted account records and wrapped-key ciphertext. If sync remains enabled on another device, that device may upload encrypted records again, so sync must also be turned off on those devices when deleting remote data. After the generation/lifecycle feature is activated in production, deletion will require recent reauthentication and App Check and will retain a non-payload lifecycle tombstone containing only the retired epoch, random generation ID, deletion status, and server time to block uploads from the retired generation.
- For Firebase Auth/Firestore account data or analytics/diagnostics deletion requests, contact us below.
6. Children’s privacy
The App is not directed to children and does not knowingly collect children’s personal data.
7. Changes
This policy may be updated to reflect legal or service changes. Updates are posted on this page with a revised effective date.
8. Contact
Privacy inquiries: me@nine20.net