Privacy Policy
Last updated: August 24, 2026 • Application: MyPass
This Privacy Policy explains how SLaboratory ("we", "us", or "our") collects, uses, and protects information when you use the MyPass mobile application (the "App").
🔒 Zero-Knowledge Architecture: Your passwords, credentials, notes, and sensitive data are encrypted locally on your device. We never have access to your master password, encryption keys, or unencrypted data.
1. Information We Do NOT Collect
We believe your personal credentials belong solely to you. Because MyPass utilizes client-side end-to-end encryption:
- We do not collect or store your master password or PIN.
- We do not collect or store your saved passwords, usernames, card numbers, or notes.
- We cannot decrypt or restore your data if you lose your master password.
2. Local Data Storage & Encryption
All credentials entered into MyPass are encrypted locally on your device using industry-standard cryptographic algorithms: Argon2id for key derivation and XChaCha20-Poly1305 for authenticated data encryption. The encrypted database resides exclusively in your device's secure private application storage.
3. Cloud Backup via Google Drive (Optional)
If you choose to enable cloud backups:
- The App connects directly to your personal Google Drive account via the Google Sign-In and Google Drive API.
- Backup archives are encrypted on your device before upload.
- Backup files are stored exclusively in your personal Google Drive's hidden
appDataFolder, which is isolated from other apps and inaccessible to anyone except your authorized Google account.
- We (SLaboratory) do not host or operate servers that store or process your backup files.
4. Third-Party Services & Diagnostics
To ensure application stability, performance, and handle voluntary contributions, the App utilizes the following third-party services:
- Firebase Crashlytics & Analytics (Google LLC): Collects anonymous crash logs, device technical specifications (e.g., OS version, device model), and general usage statistics to diagnose bugs and improve app reliability. No personal credentials or passwords are ever transmitted.
- RevenueCat (RevenueCat, Inc.): Facilitates voluntary in-app donations and purchases via Google Play In-App Billing. RevenueCat processes anonymous purchase tokens and transaction metadata. Financial transactions are handled securely by Google Play.
5. Device Permissions
The App may request the following permissions solely for core functionality:
- Biometric Authentication (Fingerprint / Face Unlock): Used strictly for convenient, secure local unlocking of the vault. Biometric data is processed by the hardware security module of your operating system and is never accessed or stored by MyPass.
- Internet Access: Used exclusively for Google Drive backup synchronization, anonymous crash reporting (Firebase), and processing Google Play donations (RevenueCat).
6. Data Retention & Deletion
You have full control over your data:
- Local Data: You can delete individual vault entries, reset your database, or uninstall the App to permanently remove all stored local data.
- Google Drive Backup: You can delete your cloud backup directly from the Backup screen within the App or via your Google Drive Account settings.
7. Children's Privacy
MyPass is not directed to individuals under the age of 13. We do not knowingly collect personal information from children.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.
9. Contact Us
If you have any questions or suggestions regarding this Privacy Policy, please contact us at:
📧 Email: slaboratory.support@gmail.com
Developer: SLaboratory