Last updated: 21 September 2026.
Summary
MyPwdTool is built so that there is as little of your data to protect, collect, or lose as possible. There is no MyPwdTool account, no analytics, no advertising, and no tracking of any kind. The sections below describe, precisely, everything the app does send over a network, and why. MyPwdTool is developed and hosted in France, and complies with the GDPR by design — see GDPR (EU/EEA users) below for the specifics.
Data stored on your device
Your vault — passwords, usernames, notes, card details, TOTP secrets, passkey metadata, and the local activity log — is stored only in an encrypted file on your own device. See Security & Encryption for exactly how it’s encrypted. This data is never uploaded to any server operated by MyPwdTool, because no such server exists.
Data sent to the sync relay (only if you enable sync)
If you turn on synchronization, encrypted messages pass through a relay server to reach your other devices. The relay stores and can only ever see:
- A random, pseudonymous device identifier and inbox identifier — not tied to your name, email, or any account
- The device name you (optionally) give each device — e.g. “Work MacBook” — stored in plain text (not encrypted), since it’s only ever used to label devices in your own paired-devices list. It’s never linked to an account (there isn’t one), but it is visible in plain text to anyone who could access the relay’s own database (i.e. nobody except the relay admin) — pick a name accordingly, the same way you would for a device name on any other Wifi network, Bluetooth service or online service.
- Opaque encrypted message blobs it cannot decrypt
- The minimum routing metadata needed to deliver a message to the right device, and to enforce abuse limits (message size and rate limits)
Full detail, including why the relay cannot decrypt this data even in principle, is in Synchronization. The relay’s source code is public at github.com/ThibaultDucray/e2eerelay.
Browser extensions (Safari, and Chrome, Edge & Firefox on macOS & Windows)
The Safari extension (macOS & iOS) and the Chrome, Edge & Firefox extensions (macOS & Windows) both exist only to fill your own vault entries into the page you’re looking at — none of them talks to the network on its own. See Browser Extensions & AutoFill for how each is set up.
- What they read: the current page’s URL/domain (to find matching entries) and the username/password form fields they fill in. Page content is never stored, logged, or sent anywhere — it’s read only at the moment you ask to fill.
- How they reach your vault: the Chrome, Edge & Firefox extensions talk exclusively to the MyPwdTool app running on the same computer, over each browser’s native-messaging mechanism (macOS) or through the same local channel (Windows) — never to a remote server. The Safari extension runs bundled inside the app itself and shares its data locally the same way. All of them require a one-time approval you grant yourself before any can connect.
- What they send over the network: nothing, by themselves. If you have sync enabled, entries you fill or edit follow the same encrypted relay path described above — the extensions themselves have no separate network access or permissions.
Data sent to third-party services (only when you use the specific feature)
- Breach check: the first 5 characters of a SHA-1 hash of a password you’re checking are sent to the Have I Been Pwned API. Your password and its full hash are never sent — see Password Health & Breach Check.
- Website icons: when MyPwdTool shows a small icon next to an entry, it may request that icon from a favicon lookup service, sending only the domain name involved (e.g. “github.com”), never any account information.
- Purchases (macOS, iOS, Android): subscription billing is handled entirely by Apple (App Store) for macOS or iOS purchases, Google (Play Store) for Android purchases — MyPwdTool never sees or stores your payment details, and has no way to.
- Purchases (Windows): Subscription billing is handled entirely by Lemon Squeezy — MyPwdTool receives a payment confirmation from Lemon Squeezy via email, which includes your name, email address and the licence key you have purchased. These emails are automatically deleted after one year. This information is also stored on Lemon Squeezy’s servers to keep your subscription active, in accordance with Lemon Squeezy’s Terms and Conditions. MyPwdTool does not use this information and only stores the emails (for one year) for financial management purposes.
- Update check (Windows): the Windows app checks a static file on this website for the latest available version number. This request contains no personal data — it’s the same request your browser would make to load any web page.
GDPR (EU/EEA users)
MyPwdTool is developed by an individual based in France, so it’s built with the GDPR in mind from the start, not bolted on afterward:
- Data controller: Thibault Ducray, France — reachable at contact@mypwdtool.com for any GDPR-related request.
- Lawful basis: the only personal data MyPwdTool’s servers ever see is the minimal, pseudonymous sync-relay data described above (a random device/inbox identifier, an optional plain-text device name, and opaque encrypted blobs it cannot read) — processed solely because it’s necessary to provide the synchronization feature you’ve chosen to turn on (Art. 6(1)(b) GDPR). Nothing else is collected, so there is no advertising or profiling purpose to have a lawful basis for in the first place.
- Data location: the sync relay is built and hosted in France (EU) — sync data never leaves the EU/EEA, and there is no international transfer to consider.
- Your rights (access, rectification, erasure, portability): because there’s no account and no server-side vault, most of this is already in your own hands without needing to contact anyone — renaming or removing a device from Settings → Sync removes its relay-side record immediately, and disabling sync entirely removes this device’s relay registration. Your vault itself (the only place your actual data lives) is exportable and deletable directly from the app at any time. For anything not covered by those in-app controls, contact contact@mypwdtool.com.
- No profiling, no automated decision-making: MyPwdTool doesn’t build a profile of you — it couldn’t, since it doesn’t know who you are.
- Data Protection Officer: not required — MyPwdTool’s processing is small-scale and low-risk (no large-scale monitoring, no special-category data processed by the service itself). The contact address above reaches the controller directly.
What MyPwdTool never does
- No analytics or usage tracking of any kind
- No advertising, and no data sold or shared with advertisers
- No third-party SDKs bundled for tracking purposes
- No account system, so there is no email address or profile tied to your usage
- No server-side storage of your vault or any of its contents, encrypted or otherwise
Children’s privacy
MyPwdTool is not directed at children and does not knowingly collect data from them — the app collects essentially no personal data from anyone, as described above.
Changes to this policy
If this policy changes, the “Last updated” date at the top of this page will change accordingly. Material changes will also be reflected in the app’s release notes.
Contact
Questions, requests, or reports related to privacy: contact@mypwdtool.com
MyPwdTool