Legal
Privacy Policy
PassKub ("we", "our", "the App") is a password and PIN manager for Windows, macOS, Android, iOS, and Chrome/Edge/Safari/Firefox, developed by Trust me secure. This policy explains what data PassKub collects and how it is used.
Summary
- Your vault (passwords, PINs, notes, payment cards, identity documents, and related metadata) is encrypted on your device with a key derived from your keypass (master password) using Argon2id, and encrypted with AES-256-GCM. We cannot read the contents of your vault, including any card or identity-document details you choose to store.
- If you use your device's camera to scan a payment card or identity document, or tap an NFC chip (e.g., an EMV payment card, Thai National ID, or e-passport), that scan is processed entirely on your device. The photo, chip data, or any intermediate image is never uploaded or transmitted to us.
- By default, PassKub works fully offline — nothing leaves your device.
- If you sign in to enable optional Premium cloud sync, we store only the encrypted (ciphertext) blob of your vault plus your email address (for account/sign-in) and subscription status. We cannot decrypt the vault ciphertext we store.
Data we collect
| Data | When | Purpose | Shared with |
|---|---|---|---|
| Vault contents (encrypted) — including passwords, PINs, notes, payment card details, and identity-document details | Only if you enable Premium sync | Sync your vault across your devices | Stored on our server (Supabase) as ciphertext only |
| Email address | Only if you sign in for Premium | Account sign-in (one-time email code), receipt/subscription management | Supabase (auth); Stripe (Windows desktop/browser extension billing) or Apple App Store / Google Play (mobile billing) |
| Subscription status | Only if you subscribe to Premium | Determine Premium entitlement | Supabase; payment processed by Stripe (Windows desktop/browser extension), Apple App Store, or Google Play Billing |
| Crash/diagnostic data | Never | — | PassKub does not use any crash-reporting or analytics SDK |
Windows desktop billing and data. If you choose Premium on Windows desktop, Stripe processes the subscription payment. We receive subscription status, never card details; the same encrypted-sync and deletion practices described in this policy apply.
We do not collect: browsing history, the sites you use PassKub's autofill on, your device's contacts, location, camera images or NFC chip data captured while scanning a card or identity document, or any plaintext vault contents.
Data we do not have access to
Because vault encryption/decryption happens entirely on your device using a key derived from your keypass, we never see, store, or transmit your plaintext passwords, PINs, notes, payment card details (card number, cardholder name, expiry date, CVV/CSC), or identity-document details (name, date of birth, nationality, document number, address, or machine-readable-zone/chip data) — not even when Premium sync is enabled. Camera- and NFC-based scanning used to help fill in card or identity-document fields also runs entirely on-device; the resulting image or chip data is never uploaded to us. Losing your keypass means we also cannot recover your data; there is no "forgot password" for the vault itself.
Third-party services
- Supabase — hosts our authentication and encrypted-vault-sync database. See Supabase's privacy policy.
- Cloudflare — hosts the API (Worker) that mediates sync/billing requests. See Cloudflare's privacy policy.
- Stripe (Windows desktop and browser extension Premium) — processes subscription payments. We never see your card details. See Stripe's privacy policy.
- Apple App Store / Google Play Billing (mobile Premium, once enabled) — process subscription payments; we receive only your subscription status, not payment details.
Data retention & deletion
- Local vault data stays on your device until you delete the app or clear its storage.
- If you used Premium sync, you can request deletion of your account and synced ciphertext by contacting service@passkub.com. We will delete it within 30 days.
Children's privacy
PassKub is not directed at children under 13 (or the relevant age of consent in your region), and we do not knowingly collect data from them.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with an updated "Last updated" date.
Contact
Questions about this policy: service@passkub.com