Skip to content
Timastra
HomeProductsAboutContact
Get in touch ↗
All app privacy & support

Password Vault

Password Vault — Privacy policy

An encrypted local vault with optional breach checks and connected sharing.

Privacy policySupportAccount & data deletion

Effective and last updated: 11 September 2026.

Who provides this app

Password Vault is provided under the Timastra brand. Timastra LLC is the planned legal entity; its formation and the transfer of app operations to it are pending. This policy will be updated when that transition is complete. Privacy questions can be sent to support@timastra.com.

This policy covers the app and the features described below. Platform-specific features apply only where supported.

Vault data

Passwords, logins, keys, cards, secure notes and attachments are stored in your encrypted vault. Vault contents use AES-256-GCM, with a master-password key derived using Argon2id. The list of vault names and file paths is unencrypted so you can choose a vault before unlocking it. Quick-unlock key material uses the operating system's secure storage. Android excludes vault data from automatic cloud backup and device transfer. No account is needed for ordinary vault use, and there is no telemetry or advertising.

Optional online checks and sharing

Each online breach check requires confirmation and sends only the first five hexadecimal characters of a password's SHA-1 hash to Have I Been Pwned, with matching performed locally. It does not send plaintext passwords, usernames or full hashes; the provider sees your IP address and prefixes. Optional connected sharing sends encrypted snapshots and scoped access tokens to a server you choose. Snapshots can include selected-entry history and attachments. An inheritance server handles access timing and configured notifications. None of these requests runs automatically on launch.

Files, recipients and recovery

File-folder sync and encrypted share files are copied through locations or recipients you choose. Server operators can process connection metadata and encrypted resources. Revoking access cannot erase a copy a recipient already downloaded. Backups and recovery sheets are independent copies. Support cannot recover a forgotten master password without your own valid recovery material; do not send that material to support.

Retention and deletion

Delete unwanted vault entries or vault files and their local backup versions, then remove exported shares, sync-folder copies and recovery sheets separately. Clear app storage to remove installed app data. For connected sharing, revoke members and delete hosted resources through the configured server before removing access credentials. Ask its operator about backups and notification records. Already downloaded recipient copies cannot be remotely erased.

View deletion instructions and request help.

Support messages and your privacy choices

If you contact us, we receive your email address, message and any attachments you choose to send. We use them to respond, troubleshoot and handle privacy requests. Email and hosting providers process these communications and ordinary connection information. We retain correspondence as needed to resolve the request and meet applicable recordkeeping obligations; you may request deletion of correspondence.

You may request access, correction, export or deletion of personal information we hold, or raise an objection or withdraw consent where applicable. Local-only records must be managed on your device because we do not hold a remote copy. Optional device permissions can be revoked in system settings. Service providers may process data outside your country under their own policies; security also depends on your device and any destinations you choose for exports.

Contact and policy changes

Email support@timastra.com for Password Vault privacy questions. Include the app name and enough non-sensitive information to identify your request. Never send passwords, authentication codes, recovery keys or private health, financial or photo backups. We may need to verify ownership before releasing or deleting hosted records.

Material changes to the app's data practices will be reflected in this policy with an updated date and in the app where appropriate. Visiting this page is also covered by our website privacy policy.

Timastra

Focused software for business and education.

ProductsPricing & deliveryAboutContactProduct supportApp privacy & supportAccount & data deletionPayments & refundsData & securityPrivacyTerms

© 2026 Timastra
Independent by design.

↑
Password Vault — Privacy policy | Timastra