01 / YOUR INFORMATION
Privacy Policy
This policy describes how the current PassCrate application handles information on the device and through optional cloud synchronization.
01Local-first operation
PassCrate has no application backend, advertising, analytics, or activity tracking. Vault data is stored on the device. Secret values and private notes are encrypted; local group names, secret names, and field labels remain searchable metadata inside the protected application database.
02Optional cloud synchronization
When you enable cloud synchronization or restore, PassCrate sends encrypted snapshot files directly to the Google Drive or Dropbox account you authorize. The selected provider processes account authorization, network identifiers, and stored files under its own privacy policy. PassCrate does not upload the vault passphrase.
03Device security features
Operating-system services handle device-owner and biometric authentication. PassCrate receives only the success, cancellation, or availability result—not your fingerprint, face template, phone PIN, or phone password. Provider credentials and device-key material are kept in platform-protected storage.
04Clipboard
Copying a secret or note places plaintext on the operating-system clipboard, where other permitted applications may read it. PassCrate attempts to clear only the value it placed there after the configured interval and whenever the vault locks.
05Retention and deletion
Reset PassCrate deletes the local vault, local settings, device keys, and connected-provider credentials, but it does not delete existing encrypted cloud files. The Cloud Sync page provides separately confirmed controls for deleting the current cloud vault or all PassCrate files from the connected provider, subject to provider retention behavior.
06Policy availability
This offline copy is available before vault creation or restoration. A public privacy-policy URL and accurate app-store data disclosures must also be maintained for distributed builds.