Privacy Policy

Effective September 11, 2026

PassBox is developed by Rintaro Masaoka. This policy covers the PassBox app on iPhone and Mac, this website, and support inquiries.

Information you enter

PassBox stores the box names, passwords or PINs, opening methods, durations, and change history that you create. This information is needed to provide the app’s core features.

Local storage

Your boxes are stored in the app’s private storage on your device. The local archive is encrypted using encryption provided by Apple’s operating system. PassBox stores the corresponding encryption key with the archive, so this protects against casual plaintext viewing but is not designed to resist a device owner who can inspect app storage.

iCloud synchronization

When iCloud is available to PassBox, the app automatically synchronizes encrypted box data and its corresponding keys with your private iCloud database. This enables synchronization between your devices and recovery after reinstalling, provided the data was successfully synchronized and remains in iCloud. PassBox also stores an app-specific iCloud account identifier to prevent synchronization with a different account. Apple processes iCloud information under its privacy policy. The developer does not operate a separate server for your boxes and does not receive or have routine access to their contents.

You can manage PassBox’s access to iCloud in your device’s iCloud settings; see Apple’s instructions. PassBox has no separate in-app synchronization switch. Turning off access stops synchronization on that device but does not itself delete previously stored data. Local boxes remain accessible. Repeat the setting on each device where you want to stop synchronization.

Clipboard

Copying a password or PIN places it on the system clipboard. When you use the Copy button in an opened box, PassBox asks iPhone to keep the copy local to the device and expire it after 60 seconds. On Mac, that button clears an unchanged copy after 60 seconds while the app remains running.

Copies made in the password generator, or through the system’s text-selection commands, do not receive these automatic clearing protections from PassBox. The system may share clipboard contents between devices depending on your settings. Other software with clipboard access may read or retain a copy; clearing the clipboard does not remove copies already saved elsewhere.

Deletion and retention

Boxes and their change history remain stored until you delete them. To delete a box, choose Delete box and confirm its name. Deleted boxes can be restored from the Deleted boxes section of iCloud & recovery for 90 days. The app does not currently offer immediate permanent deletion during that recovery period.

After the recovery period, PassBox removes the expired box’s name, password or PIN, opening configuration, and associated history from local storage when the app next runs successfully. Removal from iCloud requires a successful synchronization. Other devices remove their copies when they next run and synchronize. If a device stays offline or synchronization fails or is disabled, its copy or the iCloud copy may remain longer than 90 days.

To prevent deleted content from returning during synchronization, PassBox retains deletion records containing box and event identifiers and, where available, recovery deadlines and deletion-event identifiers. These records contain no box names, passwords, PINs, or opening configurations and have no automatic expiry. The app-specific iCloud account binding also remains while the vault is retained.

Uninstalling PassBox does not delete its iCloud data, and removing the Mac app may leave its local data. Disabling synchronization is separate from deletion. For the app’s deletion process to finish, it must run and successfully synchronize after the recovery period. Contact support if you need help managing stored data; the developer cannot directly access or erase your private iCloud boxes. Apple’s handling of service records and backups is governed by its own policies.

Data not collected by the developer

PassBox has no developer-operated account, advertising, analytics, tracking, or third-party analytics SDK. The developer does not collect your credentials, usage history, contacts, location, purchases, or device identifiers through the app.

Support inquiries

If you email support, the developer receives your email address, message, and any attachments you choose to send. This information is used to respond to your inquiry and resolve related issues. Correspondence is retained for as long as needed for that purpose or applicable legal obligations. You may request deletion by emailing the contact address below. Please do not send passwords, PINs, recovery codes, or screenshots containing credentials.

Support email is handled through Gmail and is also subject to Google’s privacy policy.

Website visits

This website is hosted by Cloudflare Pages. Cloudflare processes connection and request information, such as IP addresses and requested URLs, to deliver and protect the website under its privacy policy. The website does not ask you to enter your box contents and does not include advertising or analytics scripts. Website hosting is separate from the app’s iCloud synchronization.

Children

PassBox is not directed to children and does not knowingly collect personal information from children.

Changes to this policy

This policy may be updated when PassBox changes. The effective date above will be revised when material changes are published.

Contact

Questions about this policy may be sent to rmasaoka.dev@gmail.com.