Added the English version; corrected permission descriptions; quantified the clipboard-clear interval; added the TOTP section, the App Store privacy-label mapping, and this revision history
1.0
2026-09-04
Initial release
1.Introduction
PassKeeper (Chinese name: 密记本, referred to as "the App") is a local-first digital vault for logins, bank cards, ID documents, keys and backup codes, private notes and other highly sensitive information.
Because of the extreme sensitivity of this data, the App is built on the principles of data minimization, local-first storage, and zero collection or analytics. This policy explains what data the App handles, how and where it is handled, and the control you have.
By installing and using the App, you agree to this Privacy Policy.
2.What We Collect
The App does not collect, upload, or analyze any user data.
No identity information (name, email, phone number, etc.) is collected.
No third-party analytics, advertising, or tracking SDKs are embedded.
Your vault entries are never uploaded to any server operated by us.
No copy of your data exists on our side — we do not even operate a server.
Everything you create in the App (entries, fields, image attachments, 2FA secrets) belongs solely to you.
App Store privacy label: based on the above, the App is declared as "Data Not Collected" on its App Store privacy section.
3.Storage and Encryption
3.1Local encrypted storage
All entries are stored on your device using authenticated encryption — AES-256-GCM or ChaCha20-Poly1305. The encryption key is derived from your master password on the device using a key derivation function (PBKDF2).
Your master password is never stored anywhere (not on disk, not uploaded). The App keeps only a local verifier to check password correctness; the password itself cannot be restored from it, and we cannot help you recover it.
The encrypted vault file lives inside the app sandbox (Application Support) and is deleted when you uninstall the App.
If you switch the encryption algorithm in Settings, all records are immediately re-encrypted with the new one. Both available algorithms are industry-standard authenticated ciphers with tamper protection.
3.2Keychain
Derived keys and unlock credentials are stored in the iOS Keychain, protected by your device passcode and the Secure Enclave.
These items are marked "ThisDeviceOnly" and never migrate to other devices through backups.
3.3One-time codes (TOTP two-factor)
Two-factor secrets you store are saved as entry fields, encrypted together with the vault.
Verification codes are computed locally on the device in real time according to RFC 6238. No network request is involved.
4.iCloud Sync (optional, off by default)
Only after you actively enable iCloud sync does the encrypted vault travel through the Apple-provided iCloud Drive container (iCloud.com.skyerkj.password) between devices signed in with your Apple ID.
Only encrypted data is synced. We cannot read it, and Apple does not grant app developers access to your iCloud content. Data resides in your personal iCloud space under your agreement with Apple.
Turning sync off or signing out keeps data on the device; nothing further is uploaded.
Please note: the security of iCloud data also depends on the security of your Apple ID (two-factor authentication is recommended). Apple's own privacy policy governs the iCloud service.
5.System Permissions
The App requests the following iOS permissions only when needed and only for the stated purposes:
Permission
Purpose
Required
Face ID / Touch ID NSFaceIDUsageDescription
Fast unlocking without retyping the master password
Optional
Camera NSCameraUsageDescription
Taking photos to attach to entries
Optional
Photo Library NSPhotoLibraryUsageDescription
Choosing photos from your library as attachments
Optional
The App requests no other permissions — no location, contacts, microphone, or local network.
You may revoke any permission at any time in Settings; only the matching feature is affected, never the encrypted storage of existing data.
Image attachments are encrypted together with their entries; they never enter the system photo library and are never uploaded.
6.Security Features
To help you protect your data, the App includes:
Auto-lock: locks automatically after the delay you choose (Immediately / 1 / 5 / 15 minutes) when backgrounded.
Privacy screen: hides content previews in the app switcher to prevent shoulder surfing.
Clipboard protection: copied sensitive values are cleared from the clipboard after about 45 seconds.
Security checkup: on-device hints for weak and reused passwords (this analysis happens entirely on the device).
Biometrics: biometric data is held exclusively by the operating system; the App never touches biometric features and only receives a pass/fail result.
7.Sharing and Third Parties
We share your data with no one — because it never leaves your device (or your personal iCloud container).
The App embeds no third-party SDKs, analytics frameworks, or ad networks.
The only cloud channel is the iCloud sync you explicitly enable (provided by Apple). Apart from that, the App establishes no network connections.
The App uses industry-standard encryption (AES-256-GCM / ChaCha20-Poly1305), which qualifies as standard encryption exempt from export-compliance registration.
8.Export and Deletion
You are in full control of your data:
Export: export your vault at any time. Encrypted exports (.ppv) are protected by a separate password of your choosing; plain JSON exports contain everything in clear text — store them safely and delete them promptly.
Delete local data: uninstalling the App removes all local data, including the encrypted vault file and the device-only Keychain items. Deletion is irreversible — export a backup first if needed.
Delete iCloud data: turn off sync and remove the container files from iCloud Drive following Apple's guidance to clear the cloud copy.
9.Children
The App is not directed at children and does not collect any information from any user, including minors. If you are a parent or guardian and believe a child has used the App, uninstalling it permanently erases all data.
10.Changes to This Policy
If this policy changes materially (for example, if a future version introduces a new optional service), we will announce it prominently in the App or in the store release notes and update the effective date and revision history at the top of this document. Continued use of the new version constitutes acceptance of the updated policy.
11.Contact Us
For any questions, suggestions, or complaints about this policy or how data is handled, contact us through the channels published on the App Store page.
TL;DR: Your data stays in your hands. The App encrypts locally, never uploads, never tracks, and has no accounts or ads. iCloud sync is off by default — and even when enabled, only encrypted data is synced.