PassaLock — Privacy Policy Effective date: September 21, 2025 This Privacy Policy covers the PassaLock app and the PassaLock Chain ecosystem: PassaVault, CloudVault/PixelGem, and PixelDreamer/PixelNik. Who We Are PassaLock is created by Gary Makinson, a 29-year-old developer from Oliver, BC, who built these tools after his mom’s bank account was compromised in a café incident. The mission is simple: give people privacy-first tools that are easy to use and help keep their digital lives safe. Data Controller: PassaLock (Gary Makinson) Our Privacy Principles Privacy-first by design. We minimize data collection and keep processing on-device wherever possible. No tracking, no ads, no profiling. End-to-end encryption. Secrets are encrypted with modern cryptography. On Apple platforms, we integrate with Apple Keychain where applicable. You’re in control. You can export or delete your data at any time from within the app(s). What We Collect On-Device Only (Default) Vault data & credentials (PassaLock / PassaVault): stored locally and encrypted. Keys are derived on-device (e.g., using system Keychain APIs) and are not transmitted to us. App settings: preferences like Face ID/PIN unlock, Auto-Lock timers, and UI options. Logs (local): basic error logs stored on-device for troubleshooting; you choose if/what to share with us. Optional Services Cloud sync (CloudVault/PixelGem): If you enable sync, your encrypted data may be stored with your chosen cloud provider. We do not have the keys. Crash diagnostics: If you opt in via Apple’s settings, anonymized crash reports may be shared with us by Apple. These reports do not contain your vault contents. Support emails: If you contact us, we receive your email and any information you choose to share. We do not collect analytics, advertising identifiers, or precise location data. How We Use Information Provide core features: local encryption, Face ID/biometric unlock, Auto-Lock, password generation, and secure storage. Sync (if enabled): to store and synchronize encrypted data across your devices. Diagnostics (if opted in): to fix crashes and improve reliability. Support: to respond to your requests. Sharing & Third Parties No selling of data. No ads or trackers. No third-party analytics SDKs. Processors (if any): cloud storage you choose for encrypted sync; Apple (for optional crash reports). These parties receive only the data necessary to perform their services, and encrypted vault contents remain inaccessible to them. Security Encryption: We use industry-standard cryptography (e.g., AES-GCM) and platform security (e.g., Apple Keychain, Secure Enclave where available). Least-privilege: We request only the permissions required for features you enable. Defense in depth: Secure defaults, auto-lock, and biometric gates reduce exposure. No system can guarantee absolute security, but we continuously improve our safeguards. Your Rights Depending on your region (e.g., GDPR/UK-GDPR, CCPA/CPRA), you may have the right to: Access, correct, export, or delete your data. Object to or restrict certain processing. Withdraw consent for optional features at any time. You can exercise most rights directly in the app’s settings (export/delete). For anything else, contact us. Children’s Privacy PassaLock is not directed to children under 13 (or the age defined by local law). We do not knowingly collect personal data from children. Data Retention Vault data remains on your devices (and, if enabled, in your encrypted cloud storage) until you delete it. Support emails are retained as needed to address your request and for legitimate business/legal purposes. International Transfers If you enable cloud sync with a provider operating outside your region, your encrypted data may be stored in other jurisdictions according to that provider’s policies. Changes to This Policy We may update this policy from time to time. We’ll post updates in-app and/or on our website, and update the “Effective date” above. Contact Questions or requests? Email support@passalock.com. For security issues, please avoid sending sensitive data via email. No Ads · No Trackers · End-to-End Encryption · On-Device by Default © 2025 PassaLock. All rights reserved.