Privacy Policy
Data we do not collect
We want to be explicit: PrivPass does not operate any servers that receive your personal data. We do not collect:
- Names, email addresses, or contact information
- Usage analytics or crash reports
- Browsing habits or behavioural data
- Location data
- Advertising identifiers
- Any data for the purposes of tracking or profiling
Data stored by the app
All data created within PrivPass is stored exclusively within your own iCloud account via Apple's CloudKit framework. This data never touches our servers.Password Store Data
The following data is stored in your iCloud account and is never stored in plain text:
- Passwords
- AES-GCM* encrypted; per-item random salt, nonce, and authentication tag
- One Time Code (TOTP) secrets
- AES-GCM* encrypted; per-item random salt, nonce, and authentication tag
- Payment card details
- AES-GCM* encrypted; per-item random salt, nonce, and authentication tag
- Folder names and colours
- Stored unencrypted in your iCloud account
- Password entry metadata (name, username, URL, notes, favourite flag)
- Stored unencrypted in your iCloud account
- Payment card metadata (title, created date)
- Stored unencrypted in your iCloud account
- One Time Code metadata (service name, username)
- Stored unencrypted in your iCloud account
Master Password
Your master password is stored solely within Apple's Keychain on your device. It is never stored in plain text, never transmitted to any server, and never written to iCloud. It is used locally to derive encryption keys for your password store.
App Preferences
UserDefaults with an App Group container, shared only between the main app and its AutoFill extension on the same device.iCloud & CloudKit
PrivPass uses Apple's CloudKit to sync your encrypted data across your own Apple devices signed into the same iCloud account. Your data is governed by Apple's iCloud Terms and Conditions and Apple's Privacy Policy. We have no access to, and cannot retrieve, any data stored in your iCloud account.
If iCloud is unavailable (e.g. you are signed out), data is stored locally on your device only and will not sync until iCloud becomes available again.
AutoFill Credential Provider
PrivPass includes an AutoFill Credential Provider extension that integrates with iOS's native AutoFill system (Settings > General > AutoFill & Passwords). This extension reads your saved passwords and One Time Codes locally on your device to offer autofill suggestions in apps and browsers. No data is transmitted externally by this extension.Camera Access
PrivPass requests access to your device camera solely to scan QR codes when adding a new One Time Code (TOTP). Camera access is triggered only when you explicitly tap "Scan QR Code". No images or video are stored or transmitted.Push Notifications
PrivPass may request permission to send push notifications. Notifications, if enabled, are handled locally by the app and are not used to transmit any personal data to external servers.In-App Purchases
PrivPass offers an optional in-app purchase ("Buy a Coffee") as a way to support development. This purchase is processed entirely by Apple via the App Store. We do not receive, handle, or store any payment information. Apple's App Store Terms & Conditions apply to all purchases.
App Review Requests
PrivPass uses Apple's StoreKit framework to occasionally prompt you to rate or review the app in the App Store. This is triggered locally after a threshold number of app launches. No personal data is collected or transmitted as part of this process.Biometric Authentication & Device Authentication
PrivPass uses Apple's Local Authentication framework to support Face ID, Touch ID, or device passcode as an App Lock mechanism. Biometric data is processed entirely by Apple's Secure Enclave on your device. PrivPass never has access to biometric data and does not store authentication results anywhere outside the device.
Third-Party SDKs & Services
PrivPass integrates the following third-party libraries:
- CodeScanner
- Purpose: QR code scanning for TOTP setup
- Data shared: None - operates entirely on-device
- SwiftOTP
- Purpose: TOTP token generation
- Data shared: None - operates entirely on-device
Neither library transmits data to any external server.
Children's Privacy
PrivPass is not directed at children under the age of 13. We do not knowingly collect any personal information from children. As we do not collect personal data from any user, there is no specific risk to minors beyond general App Store age rating considerations.
Data Security
We take the security of your data seriously. Key measures include:
- All sensitive data is encrypted using AES-GCM before being written to iCloud
- Each item uses a unique, randomly generated salt and nonce to prevent identical passwords from producing identical ciphertext
- Your master password is stored in Apple's Keychain, not in iCloud or any database
- Decryption is performed entirely on-device — the App never sends unencrypted data anywhere
- The App supports App Lock via biometrics or device passcode, with mandatory master password verification at least once every five days when App Lock is enabled
Destroy & Reset
PrivPass provides a "Destroy and Reset" feature that permanently and irreversibly deletes all data stored in your iCloud account, all app preferences, and your master password from the Keychain. This action requires master password verification and biometric/device authentication before proceeding.
Data Retention
Because we do not collect or store any of your data on our systems, we have no data retention obligations with respect to your personal information. All data remains in your iCloud account and on your device under your control. You may delete all data at any time using the "Destroy and Reset" feature within the App, or by deleting the App from your device.
Your Rights
You are always in control of your data in PrivPass. Because we don't hold your data on our own systems, you can exercise the following rights directly, at any time, without needing to contact us:
- Access — Your data is accessible to you at any time within the App.
- Deletion — You can permanently delete all data using the "Destroy and Reset" feature, or simply by deleting the App from your device.
- Portability — You can export your passwords at any time using the built-in Export Passwords feature.
Because PrivPass stores all data within your own iCloud account rather than on our servers, the traditional data subject request process under UK GDPR, EU GDPR, and CCPA works a little differently here — you hold the keys, quite literally. That said, if you have any questions about your rights or how your data is handled, we're always happy to help.
Email: help@tophhie.cloud
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the App's functionality or applicable legislation. The most current version will always be accessible within the App and on our website. Continued use of the App after any changes constitutes acceptance of the updated policy.Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:
Email: help@tophhie.cloud
You can also complain to the ICO:
Information Commissioner's OfficeWycliffe House, Water Lane
Wilmslow, Cheshire
SK9 5AF
0303 123 1113
ico.org.uk
Have a question about this policy?
Reach out to Tophhie Cloud if you have any questions, concerns, or requests relating to this policy. We'll get back to you as soon as we can.