Legal
Privacy Policy
PassKub ("we", "our", "the App") is a password and PIN manager for Android, iOS, and Chrome/Edge/Safari/Firefox, developed by Trust me secure. This policy explains what data PassKub collects and how it is used.
Summary
- Your vault (passwords, PINs, notes, and related metadata) is encrypted on your device with a key derived from your keypass (master password) using Argon2id, and encrypted with AES-256-GCM. We cannot read the contents of your vault.
- By default, PassKub works fully offline — nothing leaves your device.
- If you sign in to enable optional Premium cloud sync, we store only the encrypted (ciphertext) blob of your vault plus your email address (for account/sign-in) and subscription status. We cannot decrypt the vault ciphertext we store.
Data we collect
| Data | When | Purpose | Shared with |
|---|---|---|---|
| Vault contents (encrypted) | Only if you enable Premium sync | Sync your vault across your devices | Stored on our server (Supabase) as ciphertext only |
| Email address | Only if you sign in for Premium | Account sign-in (one-time email code), receipt/subscription management | Supabase (auth); Stripe (browser extension billing) or Apple App Store / Google Play (mobile billing) |
| Subscription status | Only if you subscribe to Premium | Determine Premium entitlement | Supabase; payment processed by Stripe, Apple App Store, or Google Play Billing |
| Crash/diagnostic data | Never | — | PassKub does not use any crash-reporting or analytics SDK |
We do not collect: browsing history, the sites you use PassKub's autofill on, your device's contacts, location, or any plaintext vault contents.
Data we do not have access to
Because vault encryption/decryption happens entirely on your device using a key derived from your keypass, we never see, store, or transmit your plaintext passwords, PINs, or notes — not even when Premium sync is enabled. Losing your keypass means we also cannot recover your data; there is no "forgot password" for the vault itself.
Third-party services
- Supabase — hosts our authentication and encrypted-vault-sync database. See Supabase's privacy policy.
- Cloudflare — hosts the API (Worker) that mediates sync/billing requests. See Cloudflare's privacy policy.
- Stripe (browser extension Premium only) — processes subscription payments. We never see your card details. See Stripe's privacy policy.
- Apple App Store / Google Play Billing (mobile Premium, once enabled) — process subscription payments; we receive only your subscription status, not payment details.
Data retention & deletion
- Local vault data stays on your device until you delete the app or clear its storage.
- If you used Premium sync, you can request deletion of your account and synced ciphertext by contacting service@passkub.com. We will delete it within 30 days.
Children's privacy
PassKub is not directed at children under 13 (or the relevant age of consent in your region), and we do not knowingly collect data from them.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with an updated "Last updated" date.
Contact
Questions about this policy: service@passkub.com