Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
25 commits
Select commit Hold shift + click to select a range
ccc8843
Localize onboarding and fix the crash that translating it would cause
aditya-I0063 Sep 16, 2026
14e62de
Upgrade toolchain to Gradle 9.7.1 / AGP 9.4.0 / Kotlin 2.3.21
aditya-I0063 Sep 16, 2026
4045804
Resolve UI text at the call site, harden the clipboard, finish locali…
aditya-I0063 Sep 16, 2026
0519798
Secure sheets and dialogs, keep secrets off disk, add DB transactions
aditya-I0063 Sep 16, 2026
89f43e7
Replace the plaintext CSV export with an encrypted backup format
aditya-I0063 Sep 16, 2026
6796870
Make the forced-update gate actually force
aditya-I0063 Sep 16, 2026
4dc7477
Re-lock the vault on background and idle
aditya-I0063 Sep 16, 2026
c8ede1e
Make password analysis work outside English
aditya-I0063 Sep 16, 2026
f5eb611
Correct the privacy claims, and translate About/Privacy/Terms into al…
aditya-I0063 Sep 16, 2026
9e2352d
Replace the build-time database key with a per-install key in three s…
aditya-I0063 Sep 16, 2026
855695e
Finish 5.7.0: recovery password change, rescue export, and fix key wr…
aditya-I0063 Sep 16, 2026
947a2bb
Fix the layering inversion and replace the bypassed preferences abstr…
aditya-I0063 Sep 16, 2026
4d7133c
Introduce domain models so Room entities stop crossing layers
aditya-I0063 Sep 16, 2026
83634be
Collect effects and state lifecycle-aware
aditya-I0063 Sep 16, 2026
1488bf6
Replace string routes with type-safe navigation
aditya-I0063 Sep 16, 2026
b9a9a11
Convert the preview screen to single-state MVI, fixing the swipe-dele…
aditya-I0063 Sep 16, 2026
35c665c
Convert the detail screen to single-state MVI and fold in the passwor…
aditya-I0063 Sep 16, 2026
ef6821c
Convert the settings screen to single-state MVI
aditya-I0063 Sep 16, 2026
e4a2fdd
Give splash and onboarding their own effects and delete the global Ui…
aditya-I0063 Sep 16, 2026
cda53b9
Add the autofill service the onboarding screen has always promised
aditya-I0063 Sep 16, 2026
5c42334
Add authenticator codes and password history to the schema
aditya-I0063 Sep 16, 2026
dcc0499
Show authenticator codes and password history on the detail screen
aditya-I0063 Sep 16, 2026
3feda80
Bring the docs and the About text up to what 5.8.0 actually does
aditya-I0063 Sep 16, 2026
4c7e0a8
Cover the backup round trip end to end
aditya-I0063 Sep 16, 2026
f04ea0a
Close the last four plan items: language source of truth, and three g…
aditya-I0063 Sep 16, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .idea/deploymentTargetSelector.xml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions .idea/kotlinc.xml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

7 changes: 7 additions & 0 deletions .idea/ktlint-plugin.xml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

167 changes: 83 additions & 84 deletions Privacy Policy.md
Original file line number Diff line number Diff line change
@@ -1,84 +1,83 @@
# Privacy Policy

Aditya Bhardwaj built the PassKey app as an Open Source app. This SERVICE is provided by Aditya
Bhardwaj at no cost and is intended for use as is.
This page is used to inform visitors regarding my policies with the collection, use, and disclosure
of Personal Information if anyone decided to use my Service.
If you choose to use my Service, then you agree to the collection and use of information in relation
to this policy. The Personal Information that I collect is used for providing and improving the
Service. I will not use or share your information with anyone except as described in this Privacy
Policy.
The terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, which
are accessible at PassKey unless otherwise defined in this Privacy Policy.

# Information Collection and Use

For a better experience, while using our Service, I may require you to provide us with certain
personally identifiable information, including but not limited to Aditya Bhardwaj. The information
that I request will be retained on your device and is not collected by me in any way.
The app does use third-party services that may collect information used to identify you.
Link to the privacy policy of third-party service providers used by the app
Google Play Services

# Log Data

I want to inform you that whenever you use my Service, in a case of an error in the app I collect
data and information (through third-party products) on your phone called Log Data. This Log Data may
include information such as your device Internet Protocol (“IP”) address, device name, operating
system version, the configuration of the app when utilizing my Service, the time and date of your
use of the Service, and other statistics.

# Cookies

Cookies are files with a small amount of data that are commonly used as anonymous unique
identifiers. These are sent to your browser from the websites that you visit and are stored on your
device's internal memory.
This Service does not use these “cookies” explicitly. However, the app may use third-party code and
libraries that use “cookies” to collect information and improve their services. You have the option
to either accept or refuse these cookies and know when a cookie is being sent to your device. If you
choose to refuse our cookies, you may not be able to use some portions of this Service.

# Service Providers

I may employ third-party companies and individuals due to the following reasons:
To facilitate our Service;
To provide the Service on our behalf;
To perform Service-related services; or
To assist us in analyzing how our Service is used.
I want to inform users of this Service that these third parties have access to their Personal
Information. The reason is to perform the tasks assigned to them on our behalf. However, they are
obligated not to disclose or use the information for any other purpose.

# Security

I value your trust in providing us your Personal Information, thus we are striving to use
commercially acceptable means of protecting it. But remember that no method of transmission over the
internet, or method of electronic storage is 100% secure and reliable, and I cannot guarantee its
absolute security.

# Links to Other Sites

This Service may contain links to other sites. If you click on a third-party link, you will be
directed to that site. Note that these external sites are not operated by me. Therefore, I strongly
advise you to review the Privacy Policy of these websites. I have no control over and assume no
responsibility for the content, privacy policies, or practices of any third-party sites or services.

# Children’s Privacy

These Services do not address anyone under the age of 13. I do not knowingly collect personally
identifiable information from children under 13 years of age. In the case I discover that a child
under 13 has provided me with personal information, I immediately delete this from our servers. If
you are a parent or guardian and you are aware that your child has provided us with personal
information, please contact me so that I will be able to do the necessary actions.

# Changes to This Privacy Policy

I may update our Privacy Policy from time to time. Thus, you are advised to review this page
periodically for any changes. I will notify you of any changes by posting the new Privacy Policy on
this page.
This policy is effective as of 2022-08-30

# Contact Us

If you have any questions or suggestions about my Privacy Policy, do not hesitate to contact me at
yrkkh.cclub@gmail.com.
# Privacy Policy — PassKey: Password Manager

_Last updated: 2026-09-16_

## Summary

Your vault stays on your device. PassKey has no account, no sync and no server of its own. The
app does, however, bundle Google Firebase and Google Play libraries that send diagnostic and
usage data to Google. This document says exactly what does and does not leave your phone.

## What we never collect

PassKey does not collect, transmit or store the passwords, usernames, notes or any other entries
you save. They exist only in an encrypted database on your device.

We cannot read your entries and we cannot recover them for you. There is no server-side copy.

## What the app does send

PassKey includes the following third-party components, all provided by Google:

| Component | What it sends |
|---|---|
| Firebase Crashlytics | Crash stack traces, device model, OS version, app version, a Crashlytics installation identifier |
| Firebase Analytics | App usage events, session and screen information, device and installation identifiers, and an advertising ID (`AD_ID`) |
| Firebase Performance Monitoring | Startup, screen rendering and trace timings |
| Google Play in-app updates | Communicates with the Play Store to check for and install updates |

Because of these components the app requests the `INTERNET` permission, along with
`ACCESS_NETWORK_STATE`, `WAKE_LOCK`, `AD_ID` and the Play AdServices attribution permissions.
None of these components has access to your vault contents.

Data handled by these services is processed by Google under
[Google's privacy policy](https://policies.google.com/privacy).

## Autofill

If you make PassKey your autofill service, Android shows it the structure of the form you are
filling - the field types and the app package or web address it belongs to - so that it can
offer matching entries. That happens entirely on the device: nothing about the form, the site or
the entries offered is transmitted, logged or stored.

While the vault is locked, PassKey offers a single "unlock" suggestion and no entry names, so the
suggestion list drawn over another app never reveals which accounts you hold. Saving a login that
autofill captured only works while the vault is unlocked; otherwise the app says so rather than
keeping the credential anywhere.

Autofill is off until you turn it on in Android's settings, and it can be turned off there again
at any time.

## Backups

When you export a backup, the file is encrypted with AES-256-GCM using a key derived from a
password you choose, and written to the location you pick through the system file picker.

That file is then yours to manage. Anyone who obtains **both** the file and its password can read
it. We keep no copy and cannot recover the password for you.

## Device backup

PassKey sets `android:allowBackup="false"` and excludes its data from both Android cloud backup
and device-to-device transfer, so your vault is not uploaded to your Google account.

## Permissions

| Permission | Why |
|---|---|
| `USE_BIOMETRIC` | Unlocking the vault |
| `INTERNET`, `ACCESS_NETWORK_STATE`, `WAKE_LOCK` | Required by the Firebase and Google Play libraries above |
| `AD_ID`, AdServices permissions | Merged in by Firebase Analytics |

## Children

PassKey is not directed at children and does not knowingly collect information from them.

## Changes

This policy may be updated. Material changes will be noted in the app's release notes and in this
file's history.

## Contact

yrkkh.cclub@gmail.com
64 changes: 48 additions & 16 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,22 +30,54 @@ design -> https://www.figma.com/community/file/1116675775484733517

## 🤩 Features:

- Kotlin & Jetpack Compose.
- Clean Architecture.
- Kotlin Flows.
- Dark Mode Support.
- Biometric Authentication.
- Dagger-Hilt (Dependency Injection).
- DataStore Preferences.
- Encrypted Database.
- Screenshot Blocked.
- Open Source.
- Drag & Drop to reorder list.
- Swipe to Delete Feature.
- Separation of content.
- Import / Export data to and from storage.
- SQL Cipher (For Room DB Encryption and Decryption).
- Fully Offline : No internet permission required.
- Kotlin & Jetpack Compose, Material 3.
- Clean architecture with Kotlin Flows and Dagger-Hilt.
- Encrypted database (Room + SQLCipher).
- Biometric / device-credential unlock, with automatic re-lock on background and idle.
- Screenshot blocking, including dialogs and bottom sheets.
- Clipboard entries marked sensitive and cleared automatically.
- Autofill service: fills usernames and passwords into other apps and web pages, and offers to
save new logins.
- Built-in authenticator: RFC 6238 time-based codes, added from an `otpauth://` link or a typed
secret. No camera permission.
- Password history per entry, so a change can be traced or copied back.
- Password generator backed by SecureRandom.
- Vault analysis for weak and reused passwords.
- Password-protected encrypted backup and restore, written wherever you choose.
- Excluded from Android cloud backup and device-to-device transfer.
- Drag & drop reordering, swipe to delete, category separation.
- Dark mode and 17 languages.
- Open source.

## 🔐 Security model:

- The vault is a Room database encrypted with SQLCipher, stored only on the device.
- It is unlocked with device biometrics or the screen lock, and re-locks automatically after a
configurable idle period.
- Backups are encrypted with AES-256-GCM under a key derived from a password you choose
(PBKDF2-HMAC-SHA512), written through the system file picker.
- The app performs no network requests of its own and has no server or account.

- The database key is a per-install random key, never a build-time constant. It is wrapped three
independent ways - by a biometric-bound Keystore key unlocked through a `CryptoObject`, by a
device-credential-bound one, and by a recovery password - so losing any one of them, including
by re-enrolling a fingerprint, does not lose the vault.
- Vaults created before 5.7.0 are re-keyed once, on first launch, by exporting through
`sqlcipher_export()` into a sidecar file that only replaces the original after it verifies.
- Autofill never reveals entry names before the vault is unlocked: a locked vault offers a single
"unlock" suggestion and nothing else.

## 🌐 Network and privacy:

The app itself makes no network calls, but it bundles Google Firebase (Crashlytics, Analytics,
Performance Monitoring) and Google Play in-app updates. These require the `INTERNET` permission
and send crash diagnostics, usage events, performance traces and device/installation identifiers
— including an advertising ID — to Google. They never have access to vault contents.

Autofill runs entirely on the device: Android shows the app the structure of the form being
filled so it can offer matching entries, and nothing about that form or those entries is
transmitted or logged. See [Privacy Policy.md](Privacy%20Policy.md).


## 🌎 Released Android Application:

Expand Down
Loading