Skip to content
timastra
ProductsPricingDemosMobile appsSupportAbout
Menu
ProductsPricingDemosMobile appsSupportAbout
Get in touchContact→
App help and policies

Password Vault

Password Vault — Privacy policy

Keep passwords and sensitive information in an encrypted local vault, with optional breach checks and sharing.

Privacy policySupportAccount & data deletionTerms of use

Effective and last updated: 28 September 2026.

Who provides this app

Password Vault is provided by Timastra LLC, 5830 E 2nd St, Ste 7000 #38687, Casper, WY 82609, US. Privacy questions can be sent to support@timastra.com.

This policy explains the app’s data use, including optional features and differences between supported platforms.

Vault data

Passwords, logins, keys, cards, secure notes and attachments are stored in your encrypted vault. Vault contents use AES-256-GCM, with a master-password key derived using Argon2id. The list of vault names and file paths is unencrypted so you can choose a vault before unlocking it. Quick-unlock key material uses the operating system's secure storage. Android excludes vault data from automatic cloud backup and device transfer. No account is needed for ordinary vault use, and there is no telemetry or advertising.

Optional online checks and sharing

Each online breach check requires confirmation and sends only the first five hexadecimal characters of a password's SHA-1 hash to Have I Been Pwned, with matching performed locally. It does not send plaintext passwords, usernames or full hashes; the provider sees your IP address and prefixes. Optional connected sharing sends encrypted snapshots and scoped access tokens to a server you choose. Snapshots can include selected-entry history and attachments. An inheritance server handles access timing and configured notifications. None of these requests runs automatically on launch.

Files, recipients and recovery

File-folder sync and encrypted share files are copied through locations or recipients you choose. Server operators can process connection metadata and encrypted resources. Revoking access cannot erase a copy a recipient already downloaded. Backups and recovery sheets are independent copies. Support cannot recover a forgotten master password without your own valid recovery material; do not send that material to support.

Trial and purchases

Subscriptions and the lifetime unlock are sold through Google Play or the App Store, which process payment under their own privacy policies; the app never sees card details. RevenueCat validates store purchases and tells the app which products your store account owns, using an anonymous app user ID, the store's transaction records and basic device information; it never receives vault contents. The app keeps the answer, the date your free trial started and when a subscription was last confirmed in a small unencrypted file on your device. Timastra can see purchase records in RevenueCat, not your vault.

Retention and deletion

Delete unwanted vault entries or vault files and their local backup versions, then remove exported shares, sync-folder copies and recovery sheets separately. Clear app storage to remove installed app data. For connected sharing, revoke members and delete hosted resources through the configured server before removing access credentials. Ask its operator about backups and notification records. Already downloaded recipient copies cannot be remotely erased.

View deletion instructions and request help.

Support messages and your privacy choices

If you contact us, we receive your email address, message and any attachments you choose to send. We use them to respond, troubleshoot and handle privacy requests. Email and hosting providers process these communications and ordinary connection information. We retain correspondence as needed to resolve the request and meet applicable recordkeeping obligations; you may request deletion of correspondence.

You may request access, correction, export or deletion of personal information we hold, or raise an objection or withdraw consent where applicable. Local-only records must be managed on your device because we do not hold a remote copy. Optional device permissions can be revoked in system settings. Service providers may process data outside your country under their own policies; security also depends on your device and any destinations you choose for exports.

Contact and policy changes

Email support@timastra.com for Password Vault privacy questions. Include the app name and enough non-sensitive information to identify your request. Never send passwords, authentication codes, recovery keys or private health, financial or photo backups. We may need to verify ownership before releasing or deleting hosted records.

Material changes to the app's data practices will be reflected in this policy with an updated date and in the app where appropriate. Visiting this page is also covered by our website privacy policy.

timastra

Focused software for business, schools and everyday life.

Explore

ProductsBusiness software plansPricingExplore demosMobile appsAboutContact

Get help

Product supportPayment recoveryApp privacy & supportAccount & data deletionService status

Policies

Customer agreementsPayments & refundsData & securityPrivacyTermsCustomer service agreement

© 2026 Timastra LLC
Independent software studio.

↑
Password Vault — Privacy policy | Timastra