Skip to content
LifeLayer Apps
PassVault NeverMiss OneSweep AudioTale Support
Apps Support
PassVault

Privacy Policy

PassVault · Secure Password Hub

Last updated 11 September 2026

On this page

  1. 1 Data we collect
  2. 2 Encryption
  3. 3 Biometric data
  4. 4 Third-party services
  5. 5 Data we do not collect
  6. 6 Deleting your data
  7. 7 Children's privacy
  8. 8 Changes to this policy
  9. 9 Contact us

PassVault is a password manager developed by LifeLayer Apps, available for iOS and Android. This policy explains what the app stores, where it is stored, which outside services are involved, and how to remove everything. Where the two platforms differ, both are described.

1.Data we collect

PassVault stores your vault locally on your device, in encrypted form. We run no servers of our own that collect or store your personal information, and there is no account to create. The outside services the app does talk to — for advertising and for purchases — are listed in section 4; none of them ever sees your vault.

  • Vault entries. The titles, passwords, categories and timestamps you enter are encrypted with AES-256-GCM and written to a single file on your device.
  • Master password. Your master password is never stored. A key is derived from it with Argon2id and used to encrypt and decrypt the vault. We never have access to it — and neither does anyone else, which is why it cannot be recovered if you forget it.
  • Backup. This differs by platform.
    • On iOS, the optional iCloud backup writes an encrypted copy of your vault to your own iCloud Drive storage. It stays encrypted the entire time, and we have no access to your iCloud account.
    • On Android, there is no cloud backup at all. The app excludes itself from Android’s automatic backup and from device-to-device transfer. This is a correctness requirement rather than a preference: the key that unwraps your vault is held by the Android Keystore, which is bound to the device and never travels with a backup or a transfer, so a restored vault could never be opened. Exporting from within the app is the supported way to move your vault.
  • Export files. On both platforms, Settings can write your vault out to a file you choose. That file is not encrypted — it is plain JSON, so anyone who opens it can read your passwords. The app asks for your master password first and warns you before writing it. The file goes only where you save it; it is never sent to us or to anyone else.
  • App settings. Preferences such as language, theme and whether biometric unlock is required are stored locally on your device.

2.Encryption

All sensitive data is encrypted with AES-256-GCM, using keys derived from your master password with Argon2id. Encryption and decryption happen entirely on your device. We never have access to your master password or to your decrypted vault contents.

3.Biometric data

When you enable biometric unlock, PassVault asks the operating system to verify you: Face ID or Touch ID through Apple’s LocalAuthentication framework on iOS, and fingerprint or face unlock through Android’s BiometricPrompt on Android. Your biometric data is processed entirely by dedicated hardware on the device — the Secure Enclave on Apple devices, the Trusted Execution Environment or equivalent on Android. PassVault never accesses, stores or transmits it; the app only receives a yes or no answer from the system.

4.Third-party services

The app includes the following third-party services:

  • Google AdMob. Serves advertisements on the free tier only: a banner on the vault screen and a full-screen ad when you unlock the app. AdMob may collect device identifiers and usage data for ad personalisation. Before the first ad request the app runs Google’s consent flow, and on iOS it also asks for App Tracking Transparency permission; declining either means you see non-personalised ads instead. With PassVault Pro no ads are requested and AdMob is never called. See Google’s privacy policy.
  • Our own app promotions. When AdMob has no ad to serve, the free tier fills the same banner and full-screen slots with promotions for our other apps. These are images bundled inside PassVault, so nothing is requested from the network to show them and nothing about you is collected; tapping one opens our website in your browser. With PassVault Pro these slots are not shown at all.
  • RevenueCat. Manages in-app purchases and keeps track of purchase status. RevenueCat receives an anonymous app user identifier along with purchase and receipt data. See RevenueCat’s privacy policy.
  • Your app store. Purchases are processed by Apple StoreKit on iOS and by Google Play Billing on Android. We never see your payment details.

These services run alongside the app and have no access to your vault. None of them receives your master password, your vault file, or anything stored inside it.

5.Data we do not collect

  • We do not collect your name, email address or any account information — there is no account.
  • The app never asks for location permission and does not track your location.
  • We do not sell your personal data. We do not transfer anything to third parties beyond the advertising and billing identifiers the services in section 4 receive in order to work.
  • We use no analytics or crash-reporting SDK of any kind.
  • We do not have access to your passwords or vault contents at any time.

6.Deleting your data

Deleting the app from your device removes the encrypted vault file with it, so your entries are gone. Your master password is never stored anywhere, and without it the vault file cannot be decrypted.

One iOS detail worth knowing. PassVault keeps the vault’s salt and its wrapped encryption key in the iOS Keychain, and iOS deliberately keeps Keychain items when an app is deleted, so that reinstalling an app does not lock you out. Those two items therefore outlive an uninstall. They are useless on their own — without the vault file and your master password they decrypt nothing — but if you want them gone as well, use Forgot master password? on the lock screen before deleting PassVault: it erases the vault file, both Keychain items and the iCloud backup if you made one. On Android the key material is held by the Android Keystore and is removed with the app.

On iOS, if you used iCloud backup, remove the stored copy from your iCloud storage settings on your device: Settings › your name › iCloud › Manage Account Storage.

On Android, there is no cloud copy to remove.

On both platforms, an export file you created is an ordinary unencrypted file wherever you saved it. Deleting it is up to you, and worth doing once you no longer need it.

7.Children’s privacy

PassVault is not directed at children under the age of 13, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

8.Changes to this policy

We may update this policy from time to time. The current version always lives at this address, with the date at the top revised. Material changes will also be noted in the app’s release notes.

9.Contact us

Questions about this policy, or a request to delete data we hold — write to us and a person will answer.

lifelayer.apps@gmail.com
LifeLayer Apps

This policy supersedes the previous version published at barisbatuhan.github.io.

Back to PassVault
LifeLayer Apps

Small apps for the parts of the day that keep slipping.

lifelayer.apps@gmail.com

Apps

  • PassVault
  • NeverMiss
  • OneSweep
  • AudioTale

Help

  • Support
  • Email us

Privacy

  • PassVault
  • NeverMiss
  • OneSweep
  • AudioTale

© 2026 LifeLayer Apps. All rights reserved.