Security
This page restates what Privacy, Help, and the encryption guide already say. We do not list SOC 2, ISO 27001, pentest badges, or insurance — those are not published here.
Billing goes through Stripe. We do not store full card numbers. That is in the Privacy Policy.
Disposable inboxes store messages sent to addresses we issue. Burner numbers are purchased through 5sim; we keep order identifiers to show SMS and enforce quota.
Not a guarantee against phishing, malware, or a stolen unlocked session. Lock the vault. Do not paste cookies or share logins you do not own.
Independent audit reports are not published on this site. If that changes, this page should link the real report — not a placeholder badge.
Step 1
Logins, notes, MFA secrets, and other vault items are encrypted before they are stored. We cannot read a PIN-protected vault.
Step 2
For username and PIN vaults, the PIN never leaves the browser. There is no PIN-reset email.
Step 3
When Premium sync is on, the encrypted blob can be stored for that account. Unlocked contents are not uploaded as a readable list.
Step 4
We store a random vault key and release it only to your authenticated Google session on this site. Use a PIN vault if you need the stricter model.
The blog post on local encryption is the longer explanation of PIN-derived keys and backups. Privacy is the legal version. Terms covers Premium and third-party providers.
Create a free vault, then add temp mail and burner numbers when the library grows.