PockyPass Logo
PockyPassv1.0.0
← Back to Home
🛡️Zero-Knowledge Privacy • GDPR & CCPA Compliant

Privacy Policy

Effective Date: September 11, 2026 • Last Updated: September 2026

1.Introduction & Zero-Knowledge Commitment

PockyPass ("we", "us", or "our") provides decentralized, client-side password and credential management solutions across web browsers, mobile applications, and desktop platforms. We are founded on an uncompromising principle: your private data belongs entirely and exclusively to you.

PockyPass is engineered using a strict Zero-Knowledge Cryptographic Architecture. All cryptographic operations—including key derivation via PBKDF2 (100,000 rounds) and encryption via AES-256-GCM—occur solely in the local volatile memory of your client device. We do not operate centralized authentication databases, we do not store your passwords, and we cannot access your vault under any circumstances.

2.Information We Do Not Collect

Unlike conventional cloud-based password managers, PockyPass never receives, logs, or transmits:

  • Your Master Password, Master Key, or Emergency Recovery Key.
  • Plaintext usernames, passwords, notes, secure tokens, or URLs stored inside your vault.
  • Encrypted vault files or copies thereof on proprietary PockyPass servers.
  • Browsing histories, autofill logs, form interactions, or clipboard contents.
  • Biometric data (e.g. Face ID / Touch ID), which is processed strictly by your device's Secure Enclave.

3.Decentralized Cloud Storage (BYOC Model)

PockyPass employs a "Bring Your Own Cloud" (BYOC) infrastructure. Your encrypted vault file (pockypass_sync.enc) is stored exclusively in your own personal cloud storage:

  • Google Drive: Saved inside the isolated, user-specific appDataFolder.
  • Microsoft OneDrive: Saved inside the isolated, user-specific special/approot container.

Client authorization occurs directly with Google Identity and Microsoft Graph using industry-standard OAuth 2.0 PKCE protocols. Authentication tokens reside strictly on your local device and are never transmitted to PockyPass developers.

4.In-App Purchases, Subscriptions & RevenueCat

PockyPass integrates with RevenueCat to facilitate mobile in-app purchases, manage subscription states, and validate premium feature entitlements across platforms.

Payment Processing by Apple & Google: All financial transactions, billing, credit/debit card processing, and invoice generation are handled exclusively by Apple Inc. (via the Apple App Store) or Google LLC (via the Google Play Store).

Zero Financial Data Retention: PockyPass developers and PockyPass systems never collect, process, see, or store your credit card numbers, bank account information, or billing physical addresses.

RevenueCat Data Usage: To authenticate your entitlement to premium features, RevenueCat receives an anonymous, randomly generated pseudonymous user identifier and transactional receipt tokens generated by Apple or Google. For further details, please review RevenueCat's Privacy Policy at revenuecat.com/privacy.

5.No Telemetry, Analytics, or Advertising

PockyPass does not contain advertising SDKs, tracking pixels, behavioral analytics engines (e.g. Google Analytics, Facebook Pixel), or data brokers. We do not track which websites you visit, which credentials you copy, or how frequently you unlock your vault.

6.Compliance with General Data Protection Regulation (GDPR)

For users situated in the European Economic Area (EEA) and the United Kingdom, PockyPass adheres strictly to Regulation (EU) 2016/679 (GDPR):

Data Controller & Processor: Because PockyPass does not store or process personal data on centralized servers, you remain the sole controller of your vault data.

Your Legal Rights: Under Articles 15 through 22 of the GDPR, you have the right to access, rectify, restrict, port, or erase your data ("Right to be Forgotten"). Because all data is stored exclusively in your own Google Drive, OneDrive, or local client device, you may exercise complete erasure at any time by simply deleting your backup files and uninstalling the software.

Lawful Basis: Any pseudonymous entitlement verification is processed pursuant to Article 6(1)(b) of the GDPR (performance of a contract to deliver requested services).

7.California Consumer Privacy Act (CCPA / CPRA)

Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents are afforded specific rights concerning their personal information:

We Do Not Sell or Share Your Data: PockyPass has never sold, leased, or monetized personal information to third parties, and will never do so (as defined by Cal. Civ. Code § 1798.140).

Non-Discrimination: We do not discriminate against any user for exercising their privacy rights under California law.

8.Children's Online Privacy (COPPA)

PockyPass is not directed to children under the age of 13 (or under 16 in the EEA). We do not knowingly solicit, collect, or process personal data from minors. If you believe a child has provided personal information, please contact us immediately.

9.Security Architecture & Cryptographic Safeguards

All client cryptographic procedures utilize the native W3C Web Cryptography API and platform Secure Keychains. Master passwords undergo 100,000 rounds of PBKDF2 with SHA-256 and unique salts. Vault payloads are secured using authenticated AES-256-GCM encryption with unique initialization vectors (IVs).

10.Modifications to This Privacy Policy

We reserve the right to revise this Privacy Policy to reflect technical enhancements, architectural updates, or regulatory obligations. Any material modifications will be posted directly to this page with an updated revision date.

11.Contact & Data Protection Inquiries

If you have questions, concerns, or requests regarding this Privacy Policy or our cryptographic privacy architecture, please contact our legal and security team directly at: