Who is responsible
PassVault is published by Abdelrahman fahmy fahmy awad in Egypt. Privacy questions may be sent to abdelrahmanfahmy.dev@gmail.com; security reports should go to abdelrahmanfahmy.dev@gmail.com.
Application data
PassVault has no application account, cloud synchronization, advertising, analytics, telemetry, crash-report upload, or publisher-operated application server. The app does not send the publisher your vault contents, searches, settings, generated passwords, TOTP setup keys, verification codes, master password, or backup password.
Sensitive credential fields, folder and tag content, password history, and TOTP setup data are encrypted locally. The local database also contains structural metadata needed to operate the vault, including identifiers, timestamps, credential types, favorite state, relationships, and row counts; that structural metadata is not application-encrypted.
Biometrics and device security
If you enable biometric unlock, PassVault asks the operating system to authenticate you. It does not receive or store a face, fingerprint, or biometric template. A device-only operating-system-protected key or Keychain item protects access to the vault encryption key. Enrollment is optional, and the master password remains the fallback.
TOTP and camera access
When you add two-factor authentication to a login, its setup key is stored inside the encrypted credential. Codes are calculated on the device from that key and device time and are not persisted. Camera access is requested only when you choose to scan a compatible QR code; the QR payload is processed locally and is not uploaded.
Backups and clipboard
PassVault creates a backup only when you request one. Backups use the .pvault format, are encrypted with a separate password, and are written to a location you choose. Once exported, the operating system and any service you select to store or share the file control its retention.
When you copy a password or TOTP code, it enters the system clipboard and may be accessible to the operating system or other software. PassVault can attempt to clear its own unchanged clipboard value after the configured timeout, but cannot undo access that has already occurred.
Retention, deletion, and recovery
Application data remains on the device until you delete records, reset the vault, or remove the app, subject to operating-system backup and cache behavior. The publisher has no remote vault copy to delete and cannot recover a forgotten master password. Keep an encrypted backup if you need a recovery path.
Permissions and third parties
PassVault uses platform services such as local storage, biometric authentication, the camera when requested, the clipboard, and file pickers. The application does not include advertising or analytics SDKs. Store operators and your device platform may independently process purchase, diagnostic, or account data under their own policies.
This public website is hosted by GitHub Pages. GitHub may process visitor information such as IP addresses for security and service operation under GitHub’s own privacy terms. The website uses no PassVault analytics, advertising, account system, contact form, or cookies set by PassVault.
Children and changes
PassVault is a general-purpose security utility and is not directed to children. If this policy changes materially, the effective date above will be updated and the revised policy will be published at this stable URL.
Contact
For privacy or support: abdelrahmanfahmy.dev@gmail.com
For security reports: abdelrahmanfahmy.dev@gmail.com