Security overview
Your vault starts on your device.
Password Manager is designed around a local encrypted vault. You can use the core vault offline, and network sync remains an option you turn on when you need it.
Local by default
Account names, passwords, and TOTP seeds are stored in an on-device SQLCipher-encrypted database.
Sync by choice
Without sync, vault records remain local. When enabled, account contents are encrypted on device before upload.
A secret we never receive
Your master password is used on device to protect the sync key and is never sent to the server.
When sync is enabled
Encryption happens before data leaves the device.
- 1
Your device
The app encrypts account contents and wraps the sync key on device.
- 2
Encrypted sync storage
The server stores ciphertext, the wrapped sync key, and required sync and cryptographic metadata.
- 3
Your other device
Your sign-in identifies the ciphertext owner; the same master password is required to unlock synced data.
Protection in everyday use
Encrypted local vault
SQLCipher protects saved account data at rest inside the app database.
PIN and biometrics
Optional app lock adds a device-level check when opening the vault.
Clipboard clearing
Copied passwords are removed from the clipboard after a short delay.
Encrypted transport
Optional sync data travels over HTTPS in addition to application-level encryption of account contents.
Important limits
Security also depends on the choices around the vault.
- We cannot recover or reset your master password. If it is lost, encrypted sync data may become unrecoverable.
- App lock is an additional access control, not a replacement for your master password or device security.
- Autofill and copied credentials are ultimately delivered to the app or website you choose. Use them only with destinations you trust.
- No product can promise absolute security. Keep your device and operating system updated and protect access to your device.