Vault storage and unlocking
Your vault is stored as an encrypted file using AES-256-GCM. A key is derived from your master password using Argon2id and a random salt. Biometric unlock uses iOS Keychain access controls. Your master password is not stored in the Secure Enclave. The app decrypts data locally when you unlock or use a credential.
Imports are processed on your device. CSV and JSON exports can contain readable secrets. Exported files, copied text, and links you share are outside the encrypted vault's storage protections.
Optional iCloud sync
Sync is off by default. If enabled, RookPass sends an encrypted vault blob to your private CloudKit database through your Apple Account. This is not a user-visible iCloud Drive file. RookPass does not send the master password or vault decryption key with the blob. Apple processes the account and connection information needed to provide iCloud.
Breach checks
Password checks contact Have I Been Pwned using the first five characters of a SHA-1 password hash. The complete password and complete hash are not sent. The service receives connection information when handling a request.
Secure sharing
Rook Send encrypts selected content on your device and uploads ciphertext to a Cloudflare-hosted relay. The receiver page decrypts the share using key material in the link fragment. Anyone who receives a usable share link may access its content subject to the share's controls. Sharing is separate from local vault storage.
Purchases and diagnostics
Apple handles subscription purchases and provides transaction information used to verify Pro access. RookPass does not receive your payment-card details. The app uses local diagnostics and Apple's platform diagnostics; it does not include a third-party advertising SDK.
Optional usage analytics
The current App Store release, version 3.6, does not upload product analytics. We are preparing an optional usage-analytics feature for a future release. Where offered, it is off by default and requires your explicit choice in Usage Analytics before any events are collected. Existing users are not opted in automatically. Declining does not restrict your vault or free features.
If you opt in, events describe setup, imports, AutoFill handoff observations, paywall visits, and purchase outcomes. Each event includes a random event identifier, a random installation identifier, a new/existing-user label, days since consent, and fixed event and screen categories. The server adds a receipt day. The installation identifier links events over time, so these records are pseudonymous, not anonymous. They are used to understand and improve RookPass.
These events exclude passwords, vault contents, websites, item counts, email addresses, advertising identifiers, transaction identifiers, and free-text errors. An AutoFill observation means a credential was handed to iOS, not that a website accepted it. Analytics are not sold, used for targeted advertising, or combined with other companies' data for tracking.
The collector is operated for RookPass on Cloudflare Workers and KV, at rook-product-analytics.rookapp.workers.dev. It stores received event records with a 30-day expiry and has no public read endpoint. Worker request logging is disabled. The app queues up to 64 unsent events and excludes events older than 30 days from uploads; expired queued records are cleared during later app activity. Turning analytics off clears the unsent queue and stops future collection. An upload already delivered cannot be recalled. Resetting the identifier clears unsent events and creates a new identifier; previously received events expire automatically rather than being immediately deleted.
Network providers and the website
Providers process connection information, such as IP addresses and request metadata, to deliver and protect their services. The analytics collector does not put IP addresses or request headers in event storage. Its 30-day event expiry is not a promise about all provider operational or security records. Cloudflare describes its processing and retention in its privacy policy. Services may process data outside your country.
This website is hosted on GitHub Pages. GitHub processes website requests under its privacy statement. Opening an external link connects you to that provider.
Contacting us
If you email support, we receive the message and contact details you choose to send. Do not send passwords, recovery codes, or vault exports. You can review a support email before sending it. Contact us at the address below with privacy or data-control questions.
Changes to this policy
If we make material changes to this policy, we will update the effective date above and post the updated version here.
Contact
If you have questions about this policy, email privacy@rookpass.com.