Privacy Policy
PasswordBee — Offline Password Manager
Effective date: 21 August 2026 · Last updated: 20 September 2026
Short version: PasswordBee does not collect, transmit, or store any of your personal data. There is no account to create, no server to sign in to, and no analytics or advertising. Everything you save stays encrypted on your own device. The developer has no ability to see your vault, your master password, or anything inside it.
1. Data we collect
None. The app collects no personal or sensitive user data, and transmits no user data off the device. Specifically, the app does not:
We have no servers, no database, and no logs relating to you. Because nothing leaves your device, there is no data for us to inspect, share, sell, breach, or hand over.
2. Backup and export files you create
The app can export your vault as an already-encrypted file, at your request. When you use Export, the app hands that file to Android’s system share sheet so that you choose where it goes (for example your Downloads folder, an SD card, or a cloud drive). We do not receive the file and are not involved in where it is sent.
- An exported backup is protected by the same master password and the same AES-256 encryption as the live vault. Assume the file may be visible to other apps or people who have access to the location you chose; it is safe to store there only because it is fully encrypted.
- Once the file leaves the app, it is under your control and subject to the privacy policy and security of whatever service or storage you send it to. Please keep it somewhere you trust.
- Deleting your exported backups is your responsibility; the app cannot reach them.
- For technical reasons the app must write the file before it can hand it over, so one encrypted copy is left in the app’s own private cache after an export. It stays inside the app’s sandbox, it is encrypted exactly like the vault, and the next export replaces it — at most one such copy ever exists, and clearing the app’s cache or uninstalling removes it.
Restoring a backup
When you restore, Android’s file picker lets you select one file. The app reads only that file — it has no ability to browse, scan, or index anything else in your storage or cloud accounts. The backup is opened with the master password that backup was made with, and its entries are merged into your current vault rather than replacing it.
3. Purchases and subscriptions
The app offers optional Premium subscriptions, sold and processed entirely by Google Play Billing
4. Third parties
The app contains no advertising networks, analytics providers, attribution SDKs, or social logins. The only third-party service the app communicates with is the Google Play Store, for the billing purpose described above. We do not share, sell, rent, or disclose any user information to anyone, because we do not hold any.
5. Data retention and deletion
We retain nothing, so there is nothing for us to delete on your behalf. You are in full control:
- Delete individual entries inside the app.
- Use your recovery code, if you set one up, to unlock the vault and choose a new master password — the way back in from a forgotten password.
- Use “Forgot key” → fresh start on the login screen to erase the entire vault and return the app to its first-launch state. If you did not set up a recovery code, a lost master password makes a vault mathematically unopenable, so discarding it is the only way forward. It is permanent and unrecoverable, and the app asks you to confirm first.
- Uninstall the app to remove its vault, its cached export copy, and all app data from the device.
- Delete any backup files you exported, from wherever you saved them.
Subscription records held by Google can be managed through your Google Play account.
6. Security
We use AES-256 encryption at rest, Argon2id key derivation, hardware-backed Android Keystore for the optional biometric path, and an offline-only design that removes network exposure of your vault entirely. No system is perfect: the security of your data also depends on your device being free of malware, having a screen lock, and on you choosing a strong master password and keeping it private.
Optional recovery code. If you turn it on, the app keeps a copy of your master password on your device, encrypted so that only the 128-bit recovery code you saved can unwrap it (using the same Argon2id + AES-256 as the vault). It is held only in the app’s private storage, is never transmitted, and neither the code nor your password is ever seen by us. It exists so a forgotten master password isn’t a dead end. An exported backup carries this wrapper too — it stays fully encrypted — and a restored backup keeps its own recovery code unless you choose to create a new one. If you never turn the feature on, nothing extra is stored and a forgotten password cannot be recovered.