Last Updated: August 3, 2026
SecurePass stores everything on your device and nowhere else. There is no account to create, no server to sync with, and no analytics or advertising code in the app. Your passwords are encrypted with a key derived from your master password, which is never stored and never leaves your phone. The developer cannot see your data and cannot recover it for you.
None. SecurePass does not collect names, email addresses, phone numbers, device identifiers, advertising IDs, usage analytics, or crash reports. There is no backend service to send them to.
No access to your data. All encryption and decryption happen locally on your device. Your master password is never transmitted anywhere, and the developer never obtains your vault decryption keys.
Encryption. Vault contents are encrypted with AES-256-GCM. Your master password is stretched into an encryption key using Argon2id with a random per-vault salt, then discarded. Provided you choose a strong master password, your data remains unreadable even if the device storage is copied.
This data is excluded from Android's automatic cloud backup. Uninstalling the app, or using "Wipe Vault", deletes it permanently. There is no copy anywhere else, so it cannot be restored by the developer.
You can export an encrypted backup file (.pvault) protected by a separate password of your
choosing. The file is encrypted on your device before it is written. It is only shared or uploaded if
you choose to send it somewhere — the app never transmits it. Keep exported backups safe: they
contain your vault.
Importing a backup replaces the current contents of your vault.
If you enable fingerprint or face unlock, authentication is performed entirely by your device's operating system. The app never receives, stores, or has any access to your fingerprint or facial data — it only receives a yes/no result from the operating system. That result releases an encryption key held in your device's hardware-backed keystore, behind a user-authentication requirement. Nothing biometric is ever transmitted.
When you copy a password, SecurePass clears the clipboard automatically after a delay you control. This happens locally through the operating system. If you select "Never", the copied value stays on the system clipboard until something else replaces it, where other apps may be able to read it — the app warns you before applying that setting.
SecurePass offers an optional one-time "Premium" upgrade through Google Play billing. Payment is handled entirely by Google Play. The developer does not operate any payment infrastructure and never receives or stores your card details — only a confirmation from Google that a purchase completed, recorded locally on your device. Google's handling of payment information is governed by Google's Privacy Policy.
Network permission. The app declares the Android INTERNET permission because the
Google Play Billing library requires it. SecurePass performs no network communication of its own: your vault,
your master password, and everything derived from them are never sent off your device.
SecurePass does not request access to storage, contacts, location, camera, or the microphone.
The app contains no tracking, analytics, or advertising software. The only third-party service involved is Google Play billing, used solely for the optional purchase described in section 7.
No method of storage is completely secure. Because SecurePass transmits nothing, the practical attack surface is limited to your own device.
Because SecurePass collects no personal data, there is nothing held about you to access, correct, or erase. Your vault is under your sole control at all times: you can view, edit, export, or permanently delete it from within the app at any moment, without needing to contact anyone.
SecurePass is not directed at children under 13. No information is knowingly collected from children — consistent with the fact that no information is collected from anyone.
Revisions are published on this page with an updated date above. Material changes will also be noted in the app's release notes.
Questions about this policy or the app can be sent to contact@asadigital.co.in.