Auth Box Privacy Policy

Effective Date: March 25, 2026

TL;DR: Auth Box is a zero-knowledge password manager. We cannot see, access, or decrypt your passwords. Your vault is encrypted on your device before it ever leaves — if it leaves at all.

1. Zero-Knowledge Architecture

Auth Box uses end-to-end encryption (AES-256-GCM) with keys derived from your seed phrase. All encryption and decryption happens exclusively on your device. Our servers — if you choose to use them — store only encrypted blobs that are mathematically impossible for us to decrypt.

2. Data We Do NOT Collect

3. Data We May Collect (Optional Sync Only)

If you choose to enable server sync, we store:

If you use Auth Box in offline mode (no sync), we collect nothing.

4. Biometric Data (Face ID / Touch ID)

Auth Box uses Apple's LocalAuthentication framework for biometric unlock. Biometric data is processed entirely by the iOS Secure Enclave — it never leaves your device and is never accessible to Auth Box or any third party.

5. Third-Party Services

We do not use analytics SDKs, advertising networks, or third-party trackers.

6. Data Retention

Local data is stored on your device and deleted when you delete the app or reset your vault. Server-synced data is retained until you delete your account. Arweave backups are permanent by design (blockchain immutability) but are encrypted and useless without your seed phrase.

7. Children's Privacy

Auth Box is not directed at children under 13. We do not knowingly collect personal information from children.

8. Changes to This Policy

We will notify users of material changes via the app. The latest version is always available at this URL.

9. Contact

For privacy questions: maurice_wen@proton.me