Legal
Privacy Policy
This policy explains what information the Tripass app and tripass.com.au collect, why, and what control you have over it. Tripass is operated by a sole trader based in Australia (“Tripass”, “we”, “us”). We handle personal information in line with the Australian Privacy Principles.
The short version
- Your vault (passwords, notes, cards and two-factor secrets) is encrypted on your iPhone with AES-256-GCM before it is backed up. We cannot read it.
- We never receive your master password or your encryption key.
- We do not sell your data, show ads, or track you across other apps and websites.
Information we collect
- Account details. If you create an account for cloud backup, we store your email address and an account identifier through Firebase Authentication (a Google service).
- Encrypted vault backup. If you turn on backup, an encrypted copy of your vault is stored in Google Cloud Firestore in the Sydney region (australia-southeast1). It is ciphertext only.
- Support messages. If you email us, we keep your message and email address to answer you.
If you use Tripass without an account, your vault stays on your iPhone and we collect nothing.
Information we do not collect
- Your master password, encryption keys, or the unencrypted contents of your vault.
- Face ID data. Biometric checks are handled entirely by iOS.
- Advertising identifiers, location, or contacts.
Breach checks
The Health tab checks passwords against the Have I Been Pwned “Pwned Passwords” service using k-anonymity. Tripass computes a SHA-1 hash of the password on your device and sends only the first 5 characters of that hash. The comparison happens on your iPhone. Neither we nor Have I Been Pwned learn the password.
Clipboard
When you copy a password or code, Tripass clears it from the clipboard after a short delay. Tripass does not read your clipboard for any other purpose.
Service providers
We use Google Firebase (Authentication and Cloud Firestore) to provide accounts and encrypted backup. Google processes this data on our behalf under its own terms and security controls. Have I Been Pwned receives the 5-character hash prefixes described above.
Retention and deletion
We keep your account and encrypted backup until you delete them. You can delete your account in the app's Settings; this removes your account and your encrypted backup from our servers. You can also email us to request deletion. Data on your iPhone is removed when you delete the app.
Your rights
You can ask to access or correct the personal information we hold about you, or complain about how we handled it. Contact us first; if you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Children
Tripass is not directed at children under 13, and we do not knowingly collect their information.
Changes
If we change this policy, we will update the effective date above and, for significant changes, tell you in the app.