Privacy Policy

Last updated: April 2026

1. Who We Are

UnveilPass is a zero-knowledge password manager operated by UnveilTech.

2. Zero-Knowledge Architecture

Your data is yours. All vault data (passwords, secure items, identities, notes, files) is encrypted in your browser using AES-256-GCM before being sent to our server. We cannot read, access or decrypt your vault content. Your master password is never stored or transmitted — only an irreversible Argon2id hash is used for authentication.

3. What Data We Collect

3.1 Data you provide

DataPurposeStorage
Email addressAccount identification, login, notificationsEncrypted at rest (AES-256-GCM)
Master passwordAuthenticationNever stored — only irreversible Argon2id hash

3.2 Data encrypted client-side (zero-knowledge)

The following data is encrypted in your browser BEFORE being sent to our server. We cannot read it:

3.3 Data collected automatically

DataPurposeRetention
IP addressSecurity (rate limiting, audit log)90 days
Browser / User AgentDevice identification, audit log90 days
Approximate location (city/country)Audit log, automatic dark mode90 days
Activity timestampsAudit log (login, changes, sharing)90 days

3.4 Data we do NOT collect

4. How We Use Your Data

DataPurposeLegal Basis (GDPR)
EmailAuthentication, notifications, breach alertsContract (account creation)
Password hashAuthenticationContract
Encrypted vault dataService deliveryContract
IP addressSecurity, rate limiting, abuse preventionLegitimate interest
Audit logAccount security, complianceLegitimate interest
Approximate locationAutomatic dark mode, securityLegitimate interest

5. Third-Party Services

We use the following third-party services. No vault data (passwords, entries, notes) is ever shared with third parties.

ServiceLocationData SharedPurpose
StripeUSAEmail, payment informationBilling and subscription management
Have I Been Pwned (HIBP)USAFirst 5 characters of password SHA-1 hash only (k-anonymity)Breach scanning — your actual password is never exposed
AI service providerUSAChat messages (only when you use the support assistant)Optional in-app support assistant
MaxMind GeoIPLocal databaseIP address (processed locally on our server, no external call)Geolocation for audit log and dark mode
sunrise-sunset.orgExternal APIApproximate latitude/longitude derived from your IPCalculate sunrise/sunset times for automatic dark mode
About breach scanning: We use a technique called k-anonymity. Only the first 5 characters of a SHA-1 hash of your password are sent to HIBP. Your actual password never leaves your browser. This is the same method used by all major password managers.

6. Data Retention

DataRetention Period
Account data (email, vault)Until you delete your account
Audit log (activity history)90 days
Deleted vault entries (trash)30 days, then permanently purged
SecureSend filesUntil TTL expires (max 7 days), metadata kept 30 days
Web sessions60 minutes
Device trust tokens7 days
Email verification codes10 minutes

7. Your Rights

7.1 For all users

7.2 For EU/EEA residents (GDPR)

Under the General Data Protection Regulation, you have the right to:

7.3 For California residents (CCPA/CPRA)

7.4 For other US states

Residents of Virginia, Colorado, Connecticut, Utah, Montana and other states with privacy laws have similar rights. Contact us at support@unveiltech.com for any request.

8. Data Security

9. Data Hosting

Our servers are hosted by OVH in France (European Union). Your encrypted data is stored within the EU.

When we use third-party services based in the USA (Stripe, HIBP), only minimal non-vault data is shared (email hash for HIBP, email for Stripe billing). No vault data ever leaves our EU servers.

10. Children's Privacy

UnveilPass is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us at support@unveiltech.com for immediate deletion.

11. Account Deletion

When you delete your account, ALL data is permanently and immediately removed:

This action is irreversible. No data can be recovered after deletion.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice in the console. The "Last updated" date at the top indicates the latest revision.

13. Contact Us

For any questions about this Privacy Policy or your data: