Security overview

Your vault starts on your device.

Password Manager is designed around a local encrypted vault. You can use the core vault offline, and network sync remains an option you turn on when you need it.

01

Local by default

Account names, passwords, and TOTP seeds are stored in an on-device SQLCipher-encrypted database.

02

Sync by choice

Without sync, vault records remain local. When enabled, account contents are encrypted on device before upload.

03

A secret we never receive

Your master password is used on device to protect the sync key and is never sent to the server.

Encryption happens before data leaves the device.

  1. 1

    Your device

    The app encrypts account contents and wraps the sync key on device.

  2. 2

    Encrypted sync storage

    The server stores ciphertext, the wrapped sync key, and required sync and cryptographic metadata.

  3. 3

    Your other device

    Your sign-in identifies the ciphertext owner; the same master password is required to unlock synced data.

Encrypted local vault

SQLCipher protects saved account data at rest inside the app database.

PIN and biometrics

Optional app lock adds a device-level check when opening the vault.

Clipboard clearing

Copied passwords are removed from the clipboard after a short delay.

Encrypted transport

Optional sync data travels over HTTPS in addition to application-level encryption of account contents.

Security also depends on the choices around the vault.

  • We cannot recover or reset your master password. If it is lost, encrypted sync data may become unrecoverable.
  • App lock is an additional access control, not a replacement for your master password or device security.
  • Autofill and copied credentials are ultimately delivered to the app or website you choose. Use them only with destinations you trust.
  • No product can promise absolute security. Keep your device and operating system updated and protect access to your device.