Privacy Policy

Last updated: 24 September 2026

Passvault (“Passvault”, “we”, “us”) is a digital brand of Khush Technologies, India
(GSTIN 24AHTPC5258Q1ZN). This policy explains what we collect when you use the passvault.me website, the
Passvault client area (my.passvault.me), your Passvault vault, and the Passvault apps and browser extension.

Questions or requests: [email protected].

1. The short version

  • Your vault is end-to-end encrypted on your own device. We store it, but we cannot read it: not your
    passwords, notes, cards, passkeys or attachments, and not your master password.
  • We collect the minimum we need to run your vault and bill you. We do not sell data, show ads, or use
    analytics or tracking in the vault, apps or browser extension.

2. What we cannot see: your vault

  • Your master password never leaves your device. Your device derives your encryption key from it
    (PBKDF2-SHA256, 600,000 iterations by default) and encrypts every item before it is sent to your vault.
  • We store only the encrypted data, plus a hash derived from your master password that lets you log in. If you
    forget your master password we cannot recover your vault (unless your organisation has set up account
    recovery).
  • The names of the websites in your saved logins are encrypted like everything else.

3. What we collect and why

Data Why Where it comes from
Name, email address, billing address, company (optional) Your client account, invoices, service emails You, when you order
Payment details Taking payment. PayPal, Stripe or PhonePe processes the payment; we never see or store full card numbers You, at checkout
Vault account email and name Logging in to your vault, sharing and invitations inside your organisation You or your organisation’s admin
Encrypted vault data Storing and syncing your vault Your devices (we cannot decrypt it)
Device information: device type, name and an identifier created by the app Showing you your logged-in devices, new-device login alerts, keeping you logged in Your apps and extension
IP address, time and type of request Security (rate-limiting, spotting attacks, new-device alerts) and troubleshooting Server logs, kept 14 days for the vault proxy and 30 days for the vault application
Support messages Answering you You

4. The browser extension and apps

  • The extension connects only to your own vault address (for example yourname.passvault.me), which you
    enter the first time you use it. It does not contact us or anyone else, apart from opening passvault.me in a
    tab once when it is first installed.
  • To fill forms it reads the login, card and identity fields on the page you are on, inside your browser.
    Page contents and the addresses of the sites you visit are not recorded or sent anywhere.
  • Your vault is kept in your browser’s extension storage in encrypted form so it works offline.
  • No analytics, telemetry or advertising code is included.
  • The extension asks for access to all websites because a password manager must work wherever you log in; see
    the permission list on the Chrome Web Store page.

5. Website icons

If you have website icons turned on, your vault server fetches the small icon (favicon) of each website in
your vault and caches it, so the website sees a request from our server, not from you. You can turn icons off
in the app settings.

6. The website (passvault.me)

passvault.me uses no analytics, advertising or tracking cookies. Its fonts are loaded from Google Fonts, which
receives your IP address. The client area (my.passvault.me) uses a session cookie to keep you logged in and Google
reCAPTCHA on the sign-up form to stop automated spam sign-ups; reCAPTCHA is subject to
Google’s Privacy Policy.

7. Who processes data for us

Some providers are outside your country. Where the law requires it, we rely on the providers’ standard contractual
clauses or equivalent safeguards for these transfers.

Provider What for Location
OVHcloud Hosting your vault server Frankfurt, Germany
pCloud and Google Drive Nightly encrypted backups of vault servers (your vault data inside them is also end-to-end encrypted) United States
Cloudflare DNS and protecting the website from attacks Global
Google Fonts on the website, reCAPTCHA on client-area sign-up Global
OVHcloud (our own mail server) Sending service emails (verification, invitations, two-step codes) Canada
PayPal, Stripe, PhonePe Payments Their own locations; see their privacy policies
Contabo Hosting the website and client area United States

We do not sell, rent or share your data with anyone else, except where the law requires it.

8. How long we keep it

  • Vault data: while your subscription is active. When you cancel, your vault is deleted at the end of your paid
    period. If a renewal is not paid, your vault is suspended after 5 days and later deleted by our staff; ask us at
    any time to delete it sooner. Encrypted backups roll off within 12 months after deletion.
  • Billing records: as long as tax law requires (in India, currently at least six years).
  • Server logs: 14 days (vault proxy), 30 days (vault application).

9. Your rights

You can see, export (from the vault: Tools → Export) and delete your data at any time. Email [email protected] and
we will answer within 30 days. If you are in the EU/UK you also have the rights given by the GDPR, including the
right to complain to your local data-protection authority.

10. Security

Encryption on your device (section 2), HTTPS everywhere, one isolated vault per customer, daily encrypted
backups, and restricted administrator access. No system is perfectly secure; if a breach affects your data we
will tell you without undue delay.

11. Children

Passvault is not for children under 16.

12. Changes

We will post changes here and, for significant changes, email account holders.

13. Law

This policy is governed by the laws of India; courts in Mumbai have jurisdiction (matching our Terms of Service),
without taking away any rights you have under the law where you live.

Scroll to Top