This Privacy Policy explains how the CabinetPass apps for iPhone and Mac (“CabinetPass”, “the app”), provided by Govardhan Chitrada, an independent developer (“we”, “us”), handles information. CabinetPass is designed so that we never receive your passwords, notes, files or master password.
1. Information we collect
We do not collect any personal information. CabinetPass has no user accounts, no analytics or crash-reporting SDKs, no advertising, and no tracking. We do not operate servers that receive or store your data.
2. Data stored on your device
- Your vault (items, fields, notes, 2FA secrets, password history and file attachments) is encrypted on your device with AES-256-GCM using a key derived from your master password with Argon2id. It is stored in the app’s private storage on your iPhone.
- Your master password is never stored or transmitted. If you forget it, neither you nor we can recover your vault.
- Quick-unlock keys. If you turn on Face ID or an app passcode, a key that unlocks your vault is stored in the iOS Keychain on this device only. Face ID is handled entirely by iOS; the app never receives biometric data.
- App settings (theme, auto-lock, sync preferences and the email address of a connected Google account) are stored locally on your device.
3. Google user data (Google Drive sync)
Sync is optional and off by default. If you choose to connect a Google account, CabinetPass uses Google Sign-In and the Google Drive API as follows.
Data accessed
- Basic account information (your email address and name, via Google Sign-In) to show which Google account is connected.
- Google Drive application data folder (scope
https://www.googleapis.com/auth/drive.appdata). This is a hidden folder that only CabinetPass can access. The app cannot see, read or modify any other files in your Google Drive.
How the data is used
- To upload, download, update and delete encrypted copies of your vault and attached files in the application data folder, so you can back up your vault and use it on multiple devices.
- To display the connected account’s email address in the app.
Everything written to Google Drive is encrypted on your device before upload. Google stores only ciphertext and never has your master password or encryption keys.
Sharing and transfer
We do not receive your Google user data. The data flows only between your device and Google. We do not sell, rent or share Google user data with anyone, do not use it for advertising, do not allow humans to read it, and do not use it to develop, improve or train generalized artificial-intelligence or machine-learning models.
Storage and protection
Google Sign-In authorization tokens are managed by Google’s Sign-In SDK and stored in the iOS Keychain on your device. The connected account’s email address is stored locally in app settings. Vault data in Google Drive is protected by AES-256-GCM encryption performed on your device.
Retention and deletion
- Delete the Drive copy: Settings → Google Drive → Delete Data from Google Drive removes all files CabinetPass created in your Drive.
- Disconnect: Settings → Google Drive → Sign Out disconnects the account and revokes the app’s access.
- Revoke from Google: you can remove access at any time at myaccount.google.com/permissions. Hidden app data can be deleted from Google Drive → Settings → Manage apps.
- Local data: Settings → Erase Vault, or deleting the app, removes the vault and keys from your device.
4. Other services the app contacts
- Have I Been Pwned (optional breach check). Only when you tap Check Compromised Passwords, the app
sends the first 5 characters of each password’s SHA-1 hash to
api.pwnedpasswords.com(k-anonymity). Your passwords and full hashes never leave your device. - In-app purchases. CabinetPass Pro is sold through Apple’s App Store. Apple processes the payment; we never receive your payment details, name or Apple ID. The app only learns from StoreKit whether you own Pro.
- Apple. The App Store and iOS may process data under Apple’s Privacy Policy, such as download and crash data if you have opted in to share it with developers.
Widgets
CabinetPass widgets and Control Center controls are shortcuts only. They display no vault data and open the app, which requires unlocking before anything is shown.
5. Device permissions
- Face ID to unlock your vault, if you enable it.
- Camera to scan 2FA QR codes and photograph documents you choose to attach.
- Photos to attach images you select.
Images and documents you attach are encrypted before they are saved. You can change permissions at any time in the iOS Settings app.
6. Security
CabinetPass uses Argon2id key derivation and AES-256-GCM authenticated encryption, stores quick-unlock keys in the iOS Keychain, clears copied secrets from the clipboard, and can hide its contents in the app switcher. No method of storage is 100% secure; please choose a strong, unique master password and keep your device updated.
7. Children
CabinetPass is not directed to children under 13, and we do not knowingly collect information from anyone, including children.
8. Your rights
Because we do not collect or hold your personal data, there is nothing for us to access, correct or delete on our side. You control all of your data using the in-app options described above. Depending on where you live (for example under the GDPR or CCPA) you may have additional rights; contact us with any questions.
9. Changes to this policy
We may update this policy. We will change the effective date above and, for material changes, notify you in the app or on this page before they take effect.
10. Contact
Govardhan Chitrada — independent developer
Email: govardhanchitrada@gmail.com