Privacy Policy · Secure It

Nothing to hand over, even if we wanted to.

Last updated 9 October 2026 Android · com.talha.secure_it

Secure It is a local-first, zero-knowledge password manager. Your vault is encrypted on your device with a key derived from your master password. We operate no servers, and we never receive, store, or have any ability to read your passwords, your master password, or your recovery phrase.

0 servers we operate
AES‑256 vault encryption
Argon2id key derivation
0 trackers or analytics SDKs
01

Summary

Secure It is a local-first, zero-knowledge password manager. Your vault is encrypted on your device with a key derived from your master password. We operate no servers, and we never receive, store, or have any ability to read your passwords, your master password, or your recovery phrase.

02

The data Secure It stores on your device

All of the following stays on your device unless you explicitly turn on Google Drive sync or export a file yourself.

What Kept where Detail
Vault entries vault.enc Service names, usernames, passwords, categories and notes, inside an encrypted vault file in the app's private storage.
Master password Never stored Only an Argon2id‑derived value is used to unwrap your vault's encryption key. That derivation cannot be reversed.
Recovery phrase Never stored Shown to you once; only its effect — a second wrapped copy of your vault key — is saved.
App preferences On‑device Non‑secret settings, such as your light/dark theme choice.
Biometric unlock (optional) Android Keystore Your master password is placed in the OS's own secure storage so a fingerprint check can retrieve it. It never leaves the device.

Secure It does not collect analytics, advertising identifiers, crash telemetry, location, contacts, or any device identifier.

03

Google Drive sync optional · off by default

If you choose to link a Google account, Secure It requests only the drive.file and userinfo.email scopes. drive.file restricts the app to files it creates itself — it cannot see, read, or browse any other file in your Drive. userinfo.email is used solely to display which account is linked.

Your device Google Drive vault.enc AES‑256 encrypted, on your device, before upload

Google stores the encrypted file. Google cannot decrypt it — and neither can we.

Your master password and recovery phrase are never uploaded. Data handled here is governed by Google's Privacy Policy while it is at rest in your Drive account.

Unlink at any time from within the app. Deleting vault.enc from your Google Drive removes the synced copy.

Secure It's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide the Drive sync and sharing features described here; it is never sold, never used for advertising, and never read by any person.

04

Exports you create

"Backup Vault" and the "Emergency Kit" PDF produce files at your request and hand them to your device's share sheet or file picker. Where those files go from there is entirely your choice — we never see them.

Handle with care

The Emergency Kit contains your recovery phrase in plain text. Treat it as you would a key to a safe.

05

Clipboard

Passwords you copy are placed on the system clipboard, flagged sensitive so Android does not display them in its clipboard preview, and automatically cleared after 45 seconds if you have not copied something else since.

06

Sharing a credential optional · off by default

If you use "Share Entry," the credential is encrypted on your device with a one-time random key before it ever leaves it. The encrypted copy is stored in your own Google Drive, under a randomly‑generated file name — not ours, and not any third party's.

The key that unlocks it travels only inside the share link itself, in the part after the # symbol. Browsers and web servers never transmit that part anywhere — which means Google cannot decrypt the file, and neither can we. We never see the credential, the link, or who it was shared with.

If you set a passphrase, both the link and the passphrase are required to open the share. Send them through two different apps — sending both the same way protects against nothing.

A share is a copy, not a loan

Because no server enforces anything here, nothing can stop a link from being opened more than once while its file still exists. Treat a share link as a temporary copy of the password, and change the password afterward if it matters. You can revoke any share instantly from "Shares" on the dashboard, which deletes the file and kills the link for everyone, immediately.

07

Data sharing

Secure It contains no advertising SDKs, no analytics SDKs, and no third-party trackers. No data is sold or shared with anyone.

Never present

  • Advertising SDKs
  • Analytics SDKs
  • Third‑party trackers
  • Data sales of any kind

Only network destination

  • Google's own APIs
  • Only when you've linked Drive sync
08

Data deletion

Uninstalling Secure It removes the vault and all app data from your device. To remove synced data, delete vault.enc from your Google Drive and revoke the app's access at myaccount.google.com/permissions.

Because we hold no data about you, there is no account to delete and no server-side deletion request to make.

09

Children

Secure It is not directed at children under 13 and collects no data from anyone.

10

What zero‑knowledge means for you

Because we never hold your master password or recovery phrase, we cannot recover your vault if you lose both. This is the deliberate trade-off that makes the design safe.

No recovery without your key

If you lose your master password and your recovery phrase, your vault is unrecoverable — by you or by us. Keep your Emergency Kit somewhere secure.

11

Changes

Material changes to this policy will be published at this URL and reflected in the "Last updated" date above.

12

Contact

Questions about this policy: talhaaslamdev@gmail.com

App home page: talha-aslam-portfolio.me/secure_it