Privacy Policy

PasswordBee — Offline Password Manager
Effective date: 21 August 2026 · Last updated: 20 September 2026

Short version: PasswordBee does not collect, transmit, or store any of your personal data. There is no account to create, no server to sign in to, and no analytics or advertising. Everything you save stays encrypted on your own device. The developer has no ability to see your vault, your master password, or anything inside it.

1. Data we collect

None. The app collects no personal or sensitive user data, and transmits no user data off the device. Specifically, the app does not:

We have no servers, no database, and no logs relating to you. Because nothing leaves your device, there is no data for us to inspect, share, sell, breach, or hand over.

2. Backup and export files you create

The app can export your vault as an already-encrypted file, at your request. When you use Export, the app hands that file to Android’s system share sheet so that you choose where it goes (for example your Downloads folder, an SD card, or a cloud drive). We do not receive the file and are not involved in where it is sent.

Restoring a backup

When you restore, Android’s file picker lets you select one file. The app reads only that file — it has no ability to browse, scan, or index anything else in your storage or cloud accounts. The backup is opened with the master password that backup was made with, and its entries are merged into your current vault rather than replacing it.

3. Purchases and subscriptions

The app offers optional Premium subscriptions, sold and processed entirely by Google Play Billing

4. Third parties

The app contains no advertising networks, analytics providers, attribution SDKs, or social logins. The only third-party service the app communicates with is the Google Play Store, for the billing purpose described above. We do not share, sell, rent, or disclose any user information to anyone, because we do not hold any.

5. Data retention and deletion

We retain nothing, so there is nothing for us to delete on your behalf. You are in full control:

Subscription records held by Google can be managed through your Google Play account.

6. Security

We use AES-256 encryption at rest, Argon2id key derivation, hardware-backed Android Keystore for the optional biometric path, and an offline-only design that removes network exposure of your vault entirely. No system is perfect: the security of your data also depends on your device being free of malware, having a screen lock, and on you choosing a strong master password and keeping it private.

Optional recovery code. If you turn it on, the app keeps a copy of your master password on your device, encrypted so that only the 128-bit recovery code you saved can unwrap it (using the same Argon2id + AES-256 as the vault). It is held only in the app’s private storage, is never transmitted, and neither the code nor your password is ever seen by us. It exists so a forgotten master password isn’t a dead end. An exported backup carries this wrapper too — it stays fully encrypted — and a restored backup keeps its own recovery code unless you choose to create a new one. If you never turn the feature on, nothing extra is stored and a forgotten password cannot be recovered.