Privacy Policy

HatePassword is built around privacy by design. This policy explains what information we collect, how we use it, and the steps we take to protect your data.

Back to home

1. What information we collect

We collect account details such as your email address. When you add items to your vault, your device encrypts them before they reach our servers. We store only encrypted data. We cannot read your vault contents.

We also collect limited technical data through our authentication provider, Firebase. This includes IP address, device and browser type, and sign-in timestamps. We use this data to keep your account secure and to detect suspicious sign-in activity.

Our hosting provider, Vercel, automatically logs standard technical request data such as IP address and browser type as part of serving the site. We use this only to operate and secure the service.

We do not collect analytics data or use tracking cookies.

2. How we use your information

We use your information to create and manage your account, authenticate sign-in requests, detect and prevent unauthorized access, and maintain and improve the reliability of the service.

We do not use your information for advertising. We do not sell your information to any third party.

3. Your passwords and encrypted data

Your device encrypts vault items before they leave it. We never receive your master password or your decrypted vault contents. We have no technical means to decrypt your data, which means we cannot produce your vault contents in response to any request, including a legal one.

Some vault metadata is not encrypted, including entry names, creation dates, and item counts. This lets the service function, such as displaying your vault list without decrypting every entry. Anyone with access to our servers could see this metadata, but not your passwords.

If you forget your master password, we cannot recover it or your vault contents. This is a direct result of how the encryption works, not a policy choice.

4. Third-party services

We use Firebase, a Google service, for authentication and storage of your encrypted vault data. Firebase processes the technical data described in Section 1 and stores your encrypted vault data. Firebase does not have access to your decrypted vault contents. Firebase's own privacy practices govern their handling of this data, and you can review their policy at firebase.google.com/support/privacy.

We use Vercel for hosting infrastructure. Vercel processes standard technical request data as described in Section 1 in order to serve the site. Vercel does not have access to your decrypted vault contents. You can review their policy at vercel.com/legal/privacy-policy.

We use GitHub.com for hosting source code. GitHub does not have access to any of your private information. You can review their policy at: github.com/site-policy/privacy-policies/github-general-privacy-statement

We do not share your information with any other third party.

5. Data retention and deletion

If you delete your account, we permanently delete your vault data and account details within 30 days.

If your account is inactive for 12 months, we may delete it after notifying you at the email address on file.

6. Your choices and rights

You may request access to, correction of, or deletion of your account information. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA, including the right to access, correct, delete, or export your data, and to object to certain processing. Because your vault contents are encrypted, we cannot view or edit individual vault items on your behalf. You control that data directly through your account.

If you would like to close your account or request further information, please contact us through the support channels available on the service.

7. Children's privacy

HatePassword is not intended for children under 13, and you must be at least 13 years old to create an account. We do not knowingly collect information from anyone under 13. If you are a parent or guardian and believe a child under 13 has provided us information, contact us through the support channels available on the service and we will delete it.

8. Changes to this policy

We may update this privacy policy from time to time. When changes are made, we will revise the effective date shown below. If a change materially affects how we handle your data, we will make reasonable efforts to notify users directly.

Effective date: August 3, 2026