CryptKeep Privacy Policy

Last updated: July 16, 2026

CryptKeep ("the app") is a zero-knowledge password manager. Your passwords are encrypted on your device before they ever leave it - only you can read them.

What we collect

How encryption works

All sensitive data - titles, usernames, passwords, URLs, notes, category names, and any two-factor (authenticator) codes you save in an entry - is encrypted on your device using AES-256-GCM with authenticated encryption. The encryption key is derived from your master password via PBKDF2-SHA256 (up to 600,000 iterations) with a cryptographically random salt. Your master password never leaves your device and is never stored anywhere.

What the server sees

Encrypted vault data is synced to Supabase, a third-party backend service. Because encryption and decryption happen entirely on your device, the server only ever receives and stores encrypted data. Neither the developer nor Supabase can read your passwords or vault contents.

Two-factor authentication

If you enable two-factor authentication (2FA) on your CryptKeep account, a TOTP secret is generated and stored in your account metadata on Supabase. This secret is used to verify your identity during sign-in. No 2FA data is shared with third parties.

Separately, CryptKeep includes a built-in authenticator that can store the two-factor codes for your other accounts (for example, the code a website asks for after your password). These codes are stored inside your encrypted vault, exactly like your passwords, and are generated on your device. They are never sent anywhere.

Camera

On devices with a camera, CryptKeep can scan a QR code to set up a two-factor code for an account. The camera is used only at that moment, to read the code you point it at. No photos, video, or camera data are stored or sent anywhere; only the setup key inside the QR code is saved, encrypted, in your vault.

Unlocking with biometrics

If your device supports it, you can unlock your vault with biometrics or your device sign-in (for example, fingerprint, face, or Windows Hello). When you turn this on, an unlock key is stored in your device's secure storage (such as the Android Keystore, the iOS Keychain, or Windows Hello). This stays on your device and is never sent anywhere.

Payments and subscriptions

CryptKeep Pro subscriptions are processed by Stripe, a third-party payment processor. When you subscribe, Stripe collects your name, email, and payment details under their own privacy policy. CryptKeep does not store your payment card information. Your email address is used to link your Stripe subscription to your CryptKeep account. For details on how Stripe handles your data, see Stripe's Privacy Policy.

Pro feature data sharing

CryptKeep Pro includes features that communicate with third-party services:

These features are only active for Pro subscribers. Breach monitoring runs when you open the Password Health dashboard; website icons run only if you have turned the setting on.

What we don't collect

The app does not collect analytics, telemetry, usage data, or device information. It does not use advertising SDKs.

Account deletion

You can permanently delete your account and all associated data directly from the app in Settings. This action is irreversible. If you have an active Pro subscription, you should cancel it in Stripe before deleting your account.

Master password recovery

If you lose your master password, your vault cannot be recovered. By design, no one - including the developer - can decrypt your data.

Third-party distribution

If the app is obtained through the Microsoft Store, Apple App Store, or Google Play, the respective platform may process data related to download, purchase, and licensing under their own policies. This policy describes only processing performed by the CryptKeep app itself.

Contact

eeriegoesd@gmail.com