π‘οΈ How your data is protected
Briefly and honestly: what is encrypted, with what, and where the protection ends.
What is encrypted
- Passwords, logins, site addresses and notes; card numbers, CVV, PIN, card logins and notes; serial numbers with history; attachment files.
- Service names, card types and dates stay readable: they are needed for lists and search.
- Your email and account password protect sign-in, not the data: the data has its own master password.
How it works
- A key is derived from the master password (Argon2id, 128 MB memory). It is stored nowhere, not on the server and not in backups.
- Records and files are encrypted with AES-256-GCM using a vault key, which is itself wrapped by the master password key and by the recovery code key.
- Face or fingerprint unlock: the passkey produces a secret that wraps another copy of the vault key. Without the device it is useless.
- While the vault is open, the key is kept split: one half in the server session, the other in a browser cookie. Neither half alone reveals anything.
Where it ends
- The master password and the passkey secret pass through the server at unlock time: decryption happens on the server, not in the browser. A copy of the database or disk is unreadable without them, but a compromised running server during your session would not be stopped by this.
- A weak master password can be guessed. Malware on your device sees what you see.
- We cannot restore data on request: not by email, not by phone.
If you forget the master password
Only the recovery code issued at setup can open the data. Without it, the records can only be deleted and set up again.