Privacy Policy
Last updated: August 8, 2026
1. Introduction
At PassVault, your privacy and security are our foundational principles. We built PassVault with a strict zero-knowledge architecture. This Privacy Policy explains how we handle your data when you use our extension and mobile app.
2. Data We Do NOT Collect
PassVault operates entirely on your device. We do not collect, transmit, or have access to any of the following:
- Your Master Password
- Your encryption keys
- Your saved passwords, usernames, notes, or any other vault items
- Your browsing history
- Your analytics or tracking data
3. Google Drive Integration
PassVault uses Google Drive to securely sync your encrypted vault across your devices. To do this, PassVault requests the following Google OAuth scopes:
https://www.googleapis.com/auth/drive.appdata- To store your encrypted vault in a hidden application data folder that is only accessible by PassVault.https://www.googleapis.com/auth/drive.file- To allow you to manually export or backup your vault file to your visible Drive, if you choose to do so.
Crucially: All data is encrypted locally using AES-GCM-256 before it is sent to Google Drive. Neither Google nor the PassVault developers can read your vault data.
4. Security
Your vault is secured using PBKDF2 for key derivation and AES-GCM for symmetric encryption. The encryption and decryption happen exclusively in your browser's memory or on your mobile device. Because we do not have your Master Password, we cannot recover your data if you forget it.
5. Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.
6. Contact Us
If you have any questions about this Privacy Policy, please contact us at privacy@prithibi.net.