한국어 · English
Password Manager (the “App”) stores your accounts, passwords, and TOTP seeds encrypted on your device by default. Only when you turn on sync, Google/Apple sign-in identifies the owner of ciphertext, and Firebase Firestore stores account data encrypted on device, a sync key wrapped as nonce/ciphertext/MAC, the record IDs, update times, revisions, deletion states, the sync-key-envelope revision and random change ID, and cryptographic metadata—including KDF salt—needed for sync. Account names, passwords, and TOTP seeds remain only inside ciphertext. A limited set of data may be processed through third-party SDKs for crash reporting, usage analytics, payments, and optional sync.
The Passwordmanager Chrome Extension works with the separately installed macOS desktop app for one purpose: filling a selected account into the current HTTPS login page at the user's request.
Information handled by the extension is used only to provide its disclosed single purpose and complies with the Limited Use requirements of the Chrome Web Store User Data Policy. It is not used or transferred for advertising, personalization, sale, credit assessment, or unrelated purposes. Removing the extension removes its browser components; separate local app data remains subject to the App retention and deletion policy below.
The App processes the data below through the listed third-party SDKs. However, generation/lifecycle-based remote deletion and reactivation and the related Firebase Functions are not yet active in production. The key epoch, generation ID, lifecycle state, temporary operation metadata, and lifecycle-specific limited-use App Check token/replay-protection processing described below apply only after that feature is activated in production and a user invokes the relevant flow. Separately, in app versions that include App Check, Firebase App Check—backed by Google Play Integrity on Android or Apple App Attest/DeviceCheck on iOS—may process app/device integrity signals that do not contain saved-account contents during initialization or token issuance.
| Data type | Elements | Purpose | Processor |
|---|---|---|---|
| App activity / identifiers | App instance ID, usage events | Analytics & improvement | Firebase Analytics |
| Diagnostics / crashes | Crash logs, device & OS info | Stability | Firebase Crashlytics |
| App/device integrity | App attestation token and app/device integrity signals (never saved-account contents) | App Check initialization/token issuance and prevention of forged or replayed remote sync deletion/reactivation requests | Firebase App Check, Google Play Integrity, Apple App Attest/DeviceCheck |
| Sign-in identifiers | Firebase uid, sign-in provider information, and sign-in account data such as email when provided by the provider | Identify the owner of optional sync ciphertext | Firebase Auth, Google/Apple Sign-In |
| Sync data | Account-record ID, updated time, revision, deletion state, content/encryption/KDF identifiers, and nonce/ciphertext/MAC. Sync-key-envelope revision, random change ID, key epoch/random generation ID, lifecycle status/time, content/encryption/KDF identifiers, Argon2id KDF salt, and wrappedKey encoded as nonce/ciphertext/MAC. During deletion/reactivation, an opaque request ID, target generation, status, and page cursor are stored temporarily. Random IDs are not derived from user data or key material. Account ciphertext may include account names, passwords, TOTP seeds, and autofill identifiers. | User-enabled cross-device sync and safe deletion/reactivation | Firebase Firestore/Functions |
| Purchase history | In-app purchase transactions | Sponsorship | Apple App Store / Google Play |
The data above is shared with the following providers solely to deliver the related features. The App does not sell data.
See the Google Privacy Policy and Apple Privacy Policy.
The App is not directed to children and does not knowingly collect children’s personal data.
This policy may be updated to reflect legal or service changes. Updates are posted on this page with a revised effective date.
Privacy inquiries: me@nine20.net