PassVault is a password manager developed by LifeLayer Apps. This policy explains what the app stores, where it is stored, which outside services are involved, and how to remove everything.
1.Data we collect
PassVault stores your vault locally on your device, in encrypted form. We do not operate servers that collect or store your personal information, and there is no account to create.
- Vault entries. The titles, passwords, categories and timestamps you enter are encrypted with AES-256-GCM and written to a single file on your device.
- Master password. Your master password is never stored. A key is derived from it with Argon2id and used to encrypt and decrypt the vault. We never have access to it — and neither does anyone else, which is why it cannot be recovered if you forget it.
- iCloud backup (optional). If you use the backup and restore feature, an encrypted copy of your vault is written to your own iCloud Drive storage. It stays encrypted the entire time, and we have no access to your iCloud account.
- App settings. Preferences such as language, theme and whether Face ID is required are stored locally on your device.
2.Encryption
All sensitive data is encrypted with AES-256-GCM, using keys derived from your master password with Argon2id. Encryption and decryption happen entirely on your device. We never have access to your master password or to your decrypted vault contents.
3.Biometric data
When you enable Face ID or Touch ID, PassVault uses Apple’s LocalAuthentication framework. Your biometric data is processed entirely by the Secure Enclave on your device. PassVault never accesses, stores or transmits it — the app only receives a yes or no answer from iOS.
4.Third-party services
The app includes the following third-party services:
- Google AdMob. Serves advertisements in the app. AdMob may collect device identifiers and usage data for ad personalisation. See Google’s privacy policy.
- RevenueCat. Manages in-app purchases and keeps track of purchase status. RevenueCat receives an anonymous app user identifier along with purchase and receipt data. See RevenueCat’s privacy policy.
- Apple StoreKit. Processes in-app purchases through Apple’s payment system. We never see your payment details.
These services run alongside the app and have no access to your vault. None of them receives your master password, your vault file, or anything stored inside it.
5.Data we do not collect
- We do not collect your name, email address or any account information — there is no account.
- We do not track your location.
- We do not sell, share or transfer your personal data to third parties.
- We do not use analytics or crash-reporting SDKs beyond the services listed above.
- We do not have access to your passwords or vault contents at any time.
6.Deleting your data
Deleting the app from your device removes the vault file and its encryption keys with it. If you used iCloud backup, remove the stored copy from your iCloud storage settings on your device: Settings › your name › iCloud › Manage Account Storage.
7.Children’s privacy
PassVault is not directed at children under the age of 13, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
8.Changes to this policy
We may update this policy from time to time. The current version always lives at this address, with the date at the top revised. Material changes will also be noted in the app’s release notes.
9.Contact us
Questions about this policy, or a request to delete data we hold — write to us and a person will answer.
lifelayer.apps@gmail.com
LifeLayer Apps