Last updated: 24 September 2026
Passvault (“Passvault”, “we”, “us”) is a digital brand of Khush Technologies, India
(GSTIN 24AHTPC5258Q1ZN). This policy explains what we collect when you use the passvault.me website, the
Passvault client area (my.passvault.me), your Passvault vault, and the Passvault apps and browser extension.
Questions or requests: [email protected].
1. The short version
- Your vault is end-to-end encrypted on your own device. We store it, but we cannot read it: not your
passwords, notes, cards, passkeys or attachments, and not your master password. - We collect the minimum we need to run your vault and bill you. We do not sell data, show ads, or use
analytics or tracking in the vault, apps or browser extension.
2. What we cannot see: your vault
- Your master password never leaves your device. Your device derives your encryption key from it
(PBKDF2-SHA256, 600,000 iterations by default) and encrypts every item before it is sent to your vault. - We store only the encrypted data, plus a hash derived from your master password that lets you log in. If you
forget your master password we cannot recover your vault (unless your organisation has set up account
recovery). - The names of the websites in your saved logins are encrypted like everything else.
3. What we collect and why
| Data | Why | Where it comes from |
|---|---|---|
| Name, email address, billing address, company (optional) | Your client account, invoices, service emails | You, when you order |
| Payment details | Taking payment. PayPal, Stripe or PhonePe processes the payment; we never see or store full card numbers | You, at checkout |
| Vault account email and name | Logging in to your vault, sharing and invitations inside your organisation | You or your organisation’s admin |
| Encrypted vault data | Storing and syncing your vault | Your devices (we cannot decrypt it) |
| Device information: device type, name and an identifier created by the app | Showing you your logged-in devices, new-device login alerts, keeping you logged in | Your apps and extension |
| IP address, time and type of request | Security (rate-limiting, spotting attacks, new-device alerts) and troubleshooting | Server logs, kept 14 days for the vault proxy and 30 days for the vault application |
| Support messages | Answering you | You |
4. The browser extension and apps
- The extension connects only to your own vault address (for example
yourname.passvault.me), which you
enter the first time you use it. It does not contact us or anyone else, apart from opening passvault.me in a
tab once when it is first installed. - To fill forms it reads the login, card and identity fields on the page you are on, inside your browser.
Page contents and the addresses of the sites you visit are not recorded or sent anywhere. - Your vault is kept in your browser’s extension storage in encrypted form so it works offline.
- No analytics, telemetry or advertising code is included.
- The extension asks for access to all websites because a password manager must work wherever you log in; see
the permission list on the Chrome Web Store page.
5. Website icons
If you have website icons turned on, your vault server fetches the small icon (favicon) of each website in
your vault and caches it, so the website sees a request from our server, not from you. You can turn icons off
in the app settings.
6. The website (passvault.me)
passvault.me uses no analytics, advertising or tracking cookies. Its fonts are loaded from Google Fonts, which
receives your IP address. The client area (my.passvault.me) uses a session cookie to keep you logged in and Google
reCAPTCHA on the sign-up form to stop automated spam sign-ups; reCAPTCHA is subject to
Google’s Privacy Policy.
7. Who processes data for us
Some providers are outside your country. Where the law requires it, we rely on the providers’ standard contractual
clauses or equivalent safeguards for these transfers.
| Provider | What for | Location |
|---|---|---|
| OVHcloud | Hosting your vault server | Frankfurt, Germany |
| pCloud and Google Drive | Nightly encrypted backups of vault servers (your vault data inside them is also end-to-end encrypted) | United States |
| Cloudflare | DNS and protecting the website from attacks | Global |
| Fonts on the website, reCAPTCHA on client-area sign-up | Global | |
| OVHcloud (our own mail server) | Sending service emails (verification, invitations, two-step codes) | Canada |
| PayPal, Stripe, PhonePe | Payments | Their own locations; see their privacy policies |
| Contabo | Hosting the website and client area | United States |
We do not sell, rent or share your data with anyone else, except where the law requires it.
8. How long we keep it
- Vault data: while your subscription is active. When you cancel, your vault is deleted at the end of your paid
period. If a renewal is not paid, your vault is suspended after 5 days and later deleted by our staff; ask us at
any time to delete it sooner. Encrypted backups roll off within 12 months after deletion. - Billing records: as long as tax law requires (in India, currently at least six years).
- Server logs: 14 days (vault proxy), 30 days (vault application).
9. Your rights
You can see, export (from the vault: Tools → Export) and delete your data at any time. Email [email protected] and
we will answer within 30 days. If you are in the EU/UK you also have the rights given by the GDPR, including the
right to complain to your local data-protection authority.
10. Security
Encryption on your device (section 2), HTTPS everywhere, one isolated vault per customer, daily encrypted
backups, and restricted administrator access. No system is perfectly secure; if a breach affects your data we
will tell you without undue delay.
11. Children
Passvault is not for children under 16.
12. Changes
We will post changes here and, for significant changes, email account holders.
13. Law
This policy is governed by the laws of India; courts in Mumbai have jurisdiction (matching our Terms of Service),
without taking away any rights you have under the law where you live.