Privacy

Last updated: 11 October 2026.

What we collect

In local mode, nothing. The app contacts no server, except the breach check if you run it (5 SHA-1 hash characters, Have I Been Pwned service).

In Cloud mode: your e-mail address, a hash of the authentication key, the public derivation parameters, the encrypted blobs of your vault, the name and platform of your devices, login dates, and the IP address of requests in technical logs (14 days).

What we cannot read

Your vault content is encrypted on your device with keys the server does not hold. We can neither read it nor restore it without your master password or recovery kit.

Use

Data is used exclusively to provide sync, account security and support. No advertising, no resale, no third-party tracking on the site or in the app.

Hosting

Servers are located in the European Union. Backups are encrypted and kept for 30 days.

Your rights

You can delete your account from the app: all server data is erased immediately. For any access or rectification request, write to contact@rempar.org.

Questions: contact@rempar.org