PassMate

Privacy Policy

Effective 17 July 2026 · PassMate is operated by Togrul Agayev, an independent developer (“we”, “us”).

The short version

PassMate is built so that we cannot read your data. Your vault is end-to-end encrypted on your device; our servers store only ciphertext. We collect the minimum needed to run an account service, we use no analytics or advertising, and we never sell data.

What we collect

  • Account email address — used to create and sign in to your account, for email verification, and for password reset. On mobile you may instead sign in with Google, in which case we receive the email address of that Google account.
  • Encrypted vault data — the items you store, encrypted on your device with keys we never have. We store and sync this ciphertext but cannot decrypt or read it.
  • Authentication metadata — standard records kept by the authentication service (such as account creation time and last sign-in time).

What we never collect

  • Your master password, recovery key, or any encryption key.
  • The readable content of your vault — item names, usernames, passwords, notes, or anything else inside it.
  • Analytics, advertising identifiers, or behavioural tracking of any kind — in the app or on this website.

Where data is processed

Accounts and encrypted data are hosted on Google Firebase (Google Cloud). Google acts as our infrastructure provider and processes this data on our behalf; it receives only the same ciphertext we do. This website is served by Firebase Hosting, which keeps standard, short-lived server access logs (such as IP address and requested URL) for operational purposes. The website itself sets no cookies and runs no trackers.

Breach checking

If you use the password health report, PassMate checks passwords against the Have I Been Pwned service using k-anonymity: only the first five characters of a one-way hash are transmitted. Your passwords never leave your device in any readable or reversible form.

Data on your device

Your device keeps your signed-in session in the operating system's credential storage and, if you enable biometric unlock, an encrypted copy of your vault key protected by your device's secure hardware. Both are removed when you sign out or disable the feature.

Retention and deletion

Your data is kept for as long as your account exists. Deleting your account inside the app permanently removes your account and all server-side data, including all encrypted items. Because we cannot read your data, we also cannot recover it after deletion — or after you lose both your master password and recovery key.

Children

PassMate is not directed at children under 16, and we do not knowingly collect their data.

Changes

If this policy changes, the new version will be published on this page with an updated effective date.

Contact

Privacy questions and requests: support@passmate.tech.