Not released yet. The protocol is unaudited and half the clients are unfinished. See what works

What we keep, and what we can't read

Your vault is encrypted on your device before it is sent. We store it, but we cannot open it. This page covers the hosted service at passoword.eu, the apps and the browser extension. A server you run yourself keeps whatever you configure it to.

What the server stores

Your vaults, items and attachments, encrypted on your device. We see how many there are, how large they are and when they change. We never see their contents, names or the sites they belong to.

Your email address, encrypted at rest. It is used to verify your account and send account messages. Email goes out through Migadu.

What sign-in needs: an OPAQUE record that does not contain your password, your devices' public keys, sessions, and WebAuthn keys if you enroll one.

Your IP address is used to rate-limit sign-in attempts. It is held in memory, not written to the database, and may appear in server logs.

If you buy a plan, Stripe handles the payment. We never see your card.

What we don't do

No analytics, no tracking, no advertising. None of the apps or the extension report usage. We do not sell or share your data.

The browser extension talks only to the server you sign in to. It reads a page only when you ask it to fill, on a site you have granted.

Where it runs, and your rights

passoword.eu is run by OW-OPS - OWO, an association under the French law of 1901 (SIREN 109 986 448), Paris. Servers and backups are in France.

Under the GDPR you can ask for a copy of your data, have it corrected, or have your account erased. Write to privacy@passoword.eu from the address on your account. Erasure removes your account and its stored files.

Complaints can also go to the French data protection authority: CNIL

Last updated 27 September 2026.