Zero-knowledge password manager
Last updated: November 25, 2025
Effective date: November 25, 2025
At Passary, we believe that your data belongs to you and privacy is a fundamental right. This Privacy Policy explains in detail how Passary ("we", "us", or "our") handles information when you use our local-first password manager application (the "Service").
The Short Version: We don't collect, process, or store your personal data. Your vault is stored locally on your device, encrypted with keys only you possess. We have zero access to your passwords or vault contents.
This Privacy Policy applies to the Passary web application available at passary.com and any related services we provide. It describes our data handling practices in compliance with:
Passary operates on a zero-knowledge, local-first architecture. We do NOT collect, process, transmit, or store:
The following data is stored exclusively on your local device using your browser's storage mechanisms (LocalStorage, IndexedDB):
Important: This data never leaves your device unless you explicitly export your vault file. We have no access to this data.
When you access our website, standard web server logs may temporarily record:
Purpose: Security monitoring, preventing abuse, and technical error diagnosis only.
Legal Basis: Legitimate interest (Article 6(1)(f) GDPR) in maintaining the security and functionality of our infrastructure.
Retention: Server logs are automatically deleted within 7 days.
Passary is designed as a local-first application. All encryption, decryption, and data processing occurs entirely within your web browser or on your local device. Your vault data is:
We do not share, sell, rent, or trade any user data with third parties. Period.
We do not use:
Where we do process any data (minimal server logs), our legal basis is:
As a data subject under GDPR, you have the following rights. However, due to our zero-knowledge architecture, most traditional data rights are not applicable because we don't possess your personal data:
You can request confirmation of what data we process. Since we don't collect personal data, we can confirm we hold no personal information about you.
Not applicable - we don't store your data. You have full control to edit your vault locally.
Your data is already stored only on your device. You can delete it at any time by clearing your browser data or deleting your vault file.
You can export your encrypted vault file at any time through the application.
You can object to processing based on legitimate interest. Given we perform minimal processing, you can stop using the service at any time.
You can clear your cookie consent at any time via the Cookie Policy page.
You have the right to lodge a complaint with a supervisory authority. In Hungary, the competent authority is:
NAIH (National Authority for Data Protection and Freedom of Information)
Website: naih.hu
To exercise any of these rights, please contact us at privacy@passary.com
Since your data never leaves your device and we don't collect personal data, there are no international data transfers. The web application files are served from servers located in the European Union (Hungary).
We implement industry-standard security measures:
Important: If you lose your master password or vault file, we CANNOT recover it. This is by design - it ensures we have zero access to your data.
Passary does not knowingly collect data from children under 16 years of age. Given our zero-knowledge architecture, we have no way to determine user age. If you are a parent or guardian and believe your child has used Passary, please contact us. However, since we don't collect data, no action would typically be necessary.
We do not engage in any automated decision-making or profiling as defined under GDPR Article 22. We do not use algorithms to analyze or predict your personal preferences, behavior, or characteristics.
Our Service may contain links to external websites. We are not responsible for the privacy practices of these third-party sites. We encourage you to read their privacy policies when you leave our site.
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. Changes will be posted on this page with an updated "Last updated" date.
Material changes will be communicated through a notice on our homepage. Your continued use of Passary after changes constitutes acceptance of the updated policy.
While our zero-knowledge architecture makes traditional data breaches of user credentials impossible, if we experience any security incident affecting our infrastructure, we will:
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: privacy@passary.com
Response Time: We aim to respond to all privacy inquiries within 30 days, as required by GDPR.
By using Passary, you acknowledge that you have read, understood, and agree to this Privacy Policy and our Terms of Service. Given the local-first nature of our service, your primary consent is to the use of browser local storage for essential functionality.
Necessary for the vault to function (encryption, local storage access).
Passary does not use any analytics or marketing cookies. We respect your privacy by design.