Your vault
This policy describes how Pwdx handles your information. Your vault is stored in your private Apple CloudKit database. Account names are not encrypted by Pwdx. Passwords, titles, websites and notes are encrypted on your device using AES-GCM and RSA-OAEP before upload. The RSA private key is stored encrypted; its wrapping key syncs through iCloud Keychain. Your recovery code is not uploaded. We do not receive your vault contents through the notification service and do not have the keys needed to decrypt them.
Local authentication, AutoFill and keyboard
Face ID, Touch ID or device passcode verification is handled by Apple. Pwdx does not receive biometric templates. AutoFill decrypts the credential you select on the device. The keyboard provides basic typing without Full Access; optional vault insertion needs access to the app’s shared storage and a one-use field authorization lasting up to 60 seconds. It does not record or upload your keystrokes, surrounding text or filled credentials.
Optional notifications and Feedback
After you read the disclosure and agree to connect the optional notification service, it stores your installation identifier, device name, platform, APNs environment and push token, authentication token hashes, and the message titles, bodies, replies, timestamps and delivery status used to provide the service. Feedback is not end-to-end encrypted. Authorized third-party integrations can send you requests and receive the replies you submit. System notification previews may display the supplied title and part of the message body. You control previews and notification permissions in system settings.
Support, service providers and retention
We share information only as needed to provide the features you choose, meet legal obligations or protect the service. Service providers must protect information consistently with this policy and applicable requirements; authorized integrations must protect received messages and replies and use them only for their stated purpose. Apple and Cloudflare also describe their processing in their own privacy policies: Apple and Cloudflare. If you connect a different notification server, its operator is responsible for that server’s data practices; review its policy before connecting.
Our support form stores the message and optional email you submit so we can help you. Apple provides iCloud, Keychain, purchases, TestFlight and APNs; Cloudflare provides notification hosting, storage and operational logs. Infrastructure may process IP addresses and request metadata for delivery and abuse prevention. We do not sell personal information, use advertising SDKs or track you across apps or websites. Device registration is retained until deletion or service closure. Messages and replies are retained in your Feedback history until you delete the device’s notification data or request deletion; the ten-minute reply deadline does not erase message history. Support requests are retained until resolved and no longer needed, or until you request deletion. Short-lived rate-limit records are removed automatically after their enforcement window. Some operational backups and logs may persist according to provider retention settings.
Your choices
You can withdraw notification-service consent in Settings using “Disconnect and delete notification data”. This removes the installation’s server messages, replies and push identifiers and stops future notifications. Disabling system notifications alone stops alerts, but does not delete your inbox. Third parties may already have received your reply; contact them to exercise deletion rights for their copy. You can delete vault entries in the app; deletion markers sync across devices. Local encrypted caches can remain until devices sync or the app is removed. Deleting the app does not automatically delete iCloud data or notification records. Manage iCloud storage through Apple settings; contact us through Support to request notification or support data deletion. For access, correction, deletion or other privacy requests, use the Pwdx support form. Provide your client ID or support-request reference if available, and an email if you want a response. We may ask for limited information to verify control of the affected installation; we never need your vault secrets. Never send us your passwords, private keys or recovery code. We may update this policy when service behavior changes and will update the effective date here.