Privacy Policy
Last updated: 7 August 2026 · v1.0
PassWard does not collect, transmit, or share any personal data. The app has no INTERNET permission and cannot communicate with any external server.
Data Controller
Pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR), the data controller is:
Im.Ka.Vu.
- Email: info@passward.eu
- Website: https://www.passward.eu
Personal Data Collected
None. PassWard does not collect any personal data whatsoever. The Android application manifest does not declare the INTERNET permission. This is a verifiable technical constraint: the app is physically unable to open network connections of any kind.
Specifically, PassWard does not use:
- Analytics or crash-reporting services
- Advertising identifiers or tracking pixels
- Sensors, GPS, camera, or microphone
- Device identifiers (IMEI, Android ID, etc.)
- Telemetry or usage statistics of any kind
Data Stored Locally on the Device
PassWard stores the following data exclusively on the user's device, within the app's private sandbox:
- Vault file — an AES-256-GCM encrypted file containing the user's passwords and notes. The decryption key is never stored in plaintext.
- App preferences — non-sensitive settings such as theme selection, sort order, and lockout timing.
- Hardware-backed key — a cryptographic key stored in the Android Keystore hardware module (TEE/SE). It never leaves the secure element.
None of this data is transmitted, synchronized, or backed up to any remote server controlled by the data controller.
Legal Basis for Processing
Pursuant to Article 6 of the GDPR, a legal basis is required when personal data is processed. Since PassWard does not process any personal data, no legal basis is necessary. This article is included solely for completeness and transparency.
Permissions
PassWard requests a single Android permission:
USE_BIOMETRIC— used to authenticate the user via fingerprint or face recognition for vault unlock. The biometric data itself is processed entirely by the operating system and is never accessible to the app.
No other permissions (network, storage, location, contacts, camera, etc.) are requested or used.
Third-Party Sharing
None. No personal data is shared with third parties, because no personal data is collected.
PassWard uses the following open-source libraries, all of which operate entirely on-device without any network communication:
- Bouncy Castle — Argon2id key derivation (local computation only)
- Google Tink — AES-256-GCM encryption (local computation only)
- AndroidX Biometric — biometric authentication (local system API only)
International Data Transfers
None. Since all data resides exclusively on the user's device and the app has no INTERNET permission, no data transfer takes place — neither within the EU/EEA nor to any third country.
Backup and Export
PassWard provides a user-controlled encrypted backup and export feature. The exported file is encrypted with AES-256-GCM and can only be decrypted with the user's master password.
The data controller has no access to backup files, does not store them, and cannot recover or decrypt them under any circumstances. The user is solely responsible for the storage and protection of their backup files.
Data Retention and Deletion
All app data is stored exclusively on the user's device. Uninstalling PassWard permanently and irrevocably removes all data, including the encrypted vault, preferences, and hardware-backed keys.
No remote copies, backups, or residual data are retained by the data controller, as no data is ever transmitted from the device.
Data Subject Rights
Articles 15 through 22 of the GDPR grant data subjects rights including access, rectification, erasure, restriction of processing, data portability, and objection.
Since PassWard does not collect, store, or process any personal data on the controller's systems, these rights are not applicable in practice. The controller holds no data to access, correct, delete, or port.
Should you have any questions or concerns, you may still contact the data controller at info@passward.eu.
Right to Lodge a Complaint
Pursuant to Article 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes the Regulation.
The competent authority for the data controller is:
Garante per la Protezione dei Dati Personali
www.garanteprivacy.it
Security Measures
Pursuant to Article 32 of the GDPR, PassWard implements the following technical security measures to protect user data on-device:
- AES-256-GCM — authenticated encryption for the vault file, ensuring both confidentiality and integrity
- Argon2id — memory-hard key derivation function resistant to GPU and ASIC brute-force attacks
- Automatic key wipe — cryptographic keys are securely erased from memory after use
- Progressive lockout — exponentially increasing delays after failed authentication attempts
- Anti-screenshot — FLAG_SECURE prevents screen capture and recording of sensitive screens
- Hardware-backed key — a non-exportable key in the Android Keystore (TEE/SE) protects the vault encryption key
Cookies
None. The PassWard website (passward.eu) does not use cookies of any kind — neither technical, profiling, nor third-party cookies. No cookie consent banner is required.
Minors
PassWard is not intended for use by individuals under the age of 16. The data controller does not knowingly collect any data from minors (or from any user, as described above).
Changes to This Policy
Any changes to this Privacy Policy will be published on this page with an updated revision date. Since PassWard does not collect email addresses or contact information, notification of changes can only be provided through the app or this website.
Continued use of the app after changes are published constitutes acceptance of the revised policy.