Last updated: 29 July 2026
The short version. The Secret Box applications and browser extension collect no personal data and contain no analytics or tracking. Your vault never leaves your device by way of us: there is no Secret Box account, no Secret Box server, and no copy of it anywhere we can reach. Only two optional connections exist — an update check you can switch off, and a breach check that is off until you start it — and neither carries vault data. Details in section 4.
This policy covers the Secret Box desktop applications (macOS, Windows, Linux), the mobile applications (Android, iOS/iPadOS), the browser extensions (Chrome, Edge, Firefox, Safari), and this website.
Nothing. Everything you put into Secret Box — passwords, usernames, notes, 2FA secrets, custom fields, attachments, folders and tags — is encrypted on your device with AES-256-GCM using a key derived from your master password, and stored only in that device's local application storage. It is never uploaded to us, synchronised to us, backed up to us, or transmitted to us in any form — there is nowhere for it to go, because we run no server. For your own operating system's backup, which is a separate matter, see below.
We do not collect: names, email addresses, IP addresses, device identifiers, usage statistics, crash reports, feature analytics, or advertising identifiers. There is no telemetry of any kind, opt-in or otherwise.
Your operating system's own backup. Phones back apps up automatically, and we would rather tell you exactly where that stands than let “never leaves your device” do quiet work. Android: Secret Box opts out. The app disables Android’s automatic backup and excludes its data from both cloud backup and phone-to-phone transfer, so your vault is not copied into your Google account or onto a new handset. The trade-off is yours to manage: switching phones means exporting an encrypted backup and restoring it, which is free and always will be. (Android’s documentation notes that a few manufacturers’ migration tools ignore this setting; that part is outside any app’s control.) iOS: also opted out. There was never any iCloud sync — the app has no iCloud container and no CloudKit access — but Apple’s device backup is a separate mechanism that ignores that and copies an app’s storage anyway. The app now marks the folder holding your vault as excluded from backup, so iCloud Backup skips it. Same trade-off as Android: a new iPhone will not inherit your vault, so export an encrypted backup before you switch.
Your master password is never stored, never written to disk, and never sent anywhere. It exists in memory only while you are unlocking, and is used solely to derive the encryption key. This means nobody — including us — can recover your vault if you lose both your master password and your recovery code. That is a deliberate design decision, not an oversight.
| Connection | When | What is sent |
|---|---|---|
| Update check | Desktop apps, periodically or on launch. Can be disabled in settings. | The current version number. No identifiers, no vault data, no account. |
| Breach check (optional, off by default) | Only if you explicitly start one | The first five characters of a SHA-1 hash of a password, using the k-anonymity protocol. The password itself and its full hash never leave the device. |
| Everything else | Never | — |
App-store versions may additionally use the platform's own update and purchase mechanisms (Apple App Store, Google Play, Microsoft Store), which are governed by those platforms' privacy policies.
If you turn on sync, Secret Box writes one encrypted file into a folder you choose — typically one your own cloud service already syncs. We do not operate that service, receive that file, or hold any key to it: your provider stores ciphertext it cannot read, exactly like the backup file you could email to yourself. Their handling of that file is governed by their own privacy policy. Sync is off unless you set it up, and there is no Secret Box account or server involved at any point.
The extension requests the minimum permissions its features require, and uses them only for those features:
The extension does not request access to cookies, browsing history, or network requests. Captured credentials are shown to you for confirmation and are never queued, logged, or stored outside your encrypted vault. If your vault is locked or closed, a captured credential is discarded immediately.
This site is static and serves no personalised content. It sets no cookies and runs no third-party scripts, advertising, or social widgets. Our hosting provider processes standard server request data (such as IP address and user agent) transiently for security and delivery, as any web host must.
Purchases are handled by our payment provider, who acts as merchant of record and collects the billing information needed to complete the transaction and meet tax obligations. That data is processed under their privacy policy; we receive only what is necessary to issue and support your licence, such as your email address.
A licence key is a signed file containing your email address and the edition purchased. It is verified mathematically on your device against a public key built into the app. Activation contacts no server, and we receive no notification when or where you install.
Because the applications collect no personal data, there is generally nothing for us to access, correct, export or delete. For purchase records held by us or our payment provider, you may request access or deletion at the contact address below, subject to legal retention requirements for financial records. This applies regardless of your jurisdiction, including under the GDPR and CCPA.
Secret Box is not directed at children under 13 and collects no data from anyone, including children.
We hold no user vault data, so a compromise of our systems cannot expose your passwords. Should any incident affect purchase records, affected customers will be notified by email.
If this policy changes, the date at the top is updated and the change is noted in the application's release notes. Material changes will never retroactively apply to data already on your device — there is none to apply them to.
Questions about this policy or about security: support@adsit.work.