TL;DR: Your data is encrypted on your device. We don't collect it, we don't see it, we can't access it. Auto-save keeps your data safe in real time. All scanning and OCR happens on your device. Sync and backup are always end-to-end encrypted — no one but you can read your vault. Optional feedback, breach checks, and Loginator Pro billing are described below.
Overview
Loginator is a local-first password, card, and document manager. We believe your sensitive data belongs to you and only you. This privacy policy explains how we handle (or rather, don't handle) your data.
Data Collection
What We Collect
Nothing by default.
We do not collect vault contents or personal information by default. Optional features that send limited data (feedback, breach checks, or Loginator Pro billing) are described below
We do not collect usage analytics
We do not use cookies or tracking technologies
We do not operate servers that store your plaintext data. Optional sync uses an encrypted relay that cannot read your vault.
We do not sell, share, or monetize any user data
The iOS and Android apps are free with no in-app purchase. Optional Loginator Pro is available only on desktop, web, and browser extensions, billed through Stripe (our payment processor). We receive only your subscription status — never your full payment card details — and Pro activates via a signed license with no account linked to your vault.
Data Storage
All your data is stored exclusively on your device:
Passwords and authentication entries are stored in encrypted local storage
Payment card information is encrypted and stored locally
Scanned document data (IDs, passports, driver's licenses) is stored locally
Your encryption keys never leave your device
Optional sync and cloud backup are always end-to-end encrypted — providers (relay, Dropbox, Google Drive) never see your plaintext data
A swarm backup stays encrypted on this device. A software recovery key (same RSA-OAEP algorithm as a DoD CAC or civilian PIV) or an in-person friend key can unwrap it. Paired devices that are online at create time also receive a copy.
Auto-Save
Loginator automatically saves your data as you enter or modify it, regardless of how you input it — whether by manual typing, scanning, or editing an existing entry. This means your changes are persisted to your device's local encrypted storage in real time.
Auto-saved data never leaves your device
You retain full manual control with Save and Delete buttons at all times
No data is transmitted externally as part of the auto-save process
Scanning & Image Processing
Loginator can scan QR codes, credit/debit cards, passports, identity documents, driver's licenses, and other documents using your device's camera:
All image analysis and optical character recognition (OCR) is performed entirely on your device
Captured images are processed in memory and are not stored permanently
No images or extracted text are transmitted to any server
Scanned data is saved only to your local encrypted storage
Encryption
Loginator uses industry-standard encryption to protect your data:
AES-256-GCM nested inside XChaCha20-Poly1305 for stored credentials (two independent implementations)
Nested encryption so a bug in one cipher implementation cannot expose vault data at rest or in transit
ML-KEM-768 (post-quantum) for relay sync key exchange
ML-DSA-65 (post-quantum) for device key signatures
HKDF for key derivation
All cryptographic operations happen on-device using the Web Crypto API and an independent noble-ciphers implementation
Data Retention & Backup
Your data stays encrypted in all states:
On Android: App data is backed up via Android Auto Backup to your Google Drive (encrypted). Data is restored when you reinstall.
On iOS: Enable sync or export a backup to preserve data if you reinstall. All data remains encrypted.
All data is double-encrypted at rest (AES-256-GCM nested inside XChaCha20-Poly1305) before storage.
Bluetooth Sync
When you use Bluetooth sync between your devices:
Data is encrypted before transmission using your device keys
Sync happens directly between your devices (peer-to-peer)
No intermediary servers are involved
Both devices must explicitly approve the sync
Bluetooth, Camera, and Photo Permissions
Loginator may request the following permissions:
Bluetooth: Used only to discover and connect to nearby devices for device-to-device sync. That transfer stays between the two devices.
Camera: Used to scan QR codes, credit cards, identity documents, passports, driver's licenses, and other items. All processing happens on-device. No photos are stored or transmitted.
Photo Library: Used only if you choose to save or select images. We do not access or upload your photos.
Device Sync
Device sync is off until you turn it on. Nearby sync uses Bluetooth and stays between the two devices. Online sync sends only encrypted ciphertext through the relay. The relay cannot read your vault. Auto-save and scanning do not use the relay.
Feedback Feature
Opt-In Feature: Anonymous logging is disabled by default. Submit, Report Crash, and Request Feature send only the report you choose to send.
If you enable the optional feedback feature or tap Submit, Report Crash, or Request Feature:
All feedback is anonymous, opt-in, and disabled by default — nothing is collected until you turn it on or send a report
Reports are sent to Loginator's feedback collector (not your email app). Only crash logs and feature feedback you explicitly submit are sent
No passwords, credentials, or personal data is ever included
You can stop logging or disable feedback at any time in Settings
If you enable Ultra Logging, it stays on until you turn it off and may record the names (labels) of custom fields you add — never their values — so commonly-used fields can be improved for everyone in future updates
All feedback received (crash reports, behavior logs, auto logs, error reports, and form submissions) is automatically deleted one year after receipt, regardless of whether it has been used, for your privacy
Optional Breach Checks
Password Health and Email Breach Monitoring are optional checks you start from Settings. They never send your vault or full passwords to us.
Password leak checks use k-anonymity: only the first 5 characters of a one-way hash of each password are sent to Have I Been Pwned. Your full password never leaves your device. Matching hash suffixes are compared locally.
Email leak checks, when available, send the email address stored on an entry to Have I Been Pwned so it can be compared against public breach lists. This check is off until you tap Check Emails.
Have I Been Pwned is an independent third party. We do not receive your passwords or a copy of your vault from these checks.
Third-Party Services
Loginator does not integrate with any third-party analytics, advertising, or tracking services. The app works offline after installation. Optional features may use third-party infrastructure (encrypted relay for sync, Dropbox or Google Drive for cloud backup), but all data is end-to-end encrypted before leaving your device — these providers cannot read your vault.
Your Rights
Since all data is stored locally on your device:
Access: You have full access to all your data through the app
Portability: Export your data anytime using the backup feature
Deletion: Delete individual entries or all data via Settings
Control: You control your data completely - we can't access it
GDPR & EU/EEA Users
If you are in the European Union or European Economic Area, the following applies:
Legal basis: We do not process personal data on servers. All data remains on your device. Optional features (feedback, crash reports) are based on your consent, which you can withdraw anytime in Settings.
Data retention: Your data is stored only on your device. Permanent delete overwrites the item, rotates the vault key, and syncs a purge tombstone so paired devices will not restore it. Factory Reset overwrites local copies and destroys the encryption key. Copies you keep in backup files or on another service remain your responsibility. Any feedback you submit (crash reports, behavior logs) is automatically deleted one year after receipt.
Right to lodge a complaint: You may lodge a complaint with your local data protection supervisory authority if you believe your rights have been violated.
International transfers: Loginator does not transfer your data to any servers. Optional sync uses end-to-end encryption through a relay that cannot read your data.
Children's Privacy
Loginator is not directed at children under 13. We do not knowingly collect any information from anyone, including children.
Changes to This Policy
If we make changes to this privacy policy, we will update the "Last Updated" date and notify you through the app. Continued use of Loginator after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this privacy policy or Loginator's privacy practices: