Effective 5 October 2026 · Version 1.7
TriPass is run by Nischal Khanal, an individual developer, who decides how personal information handled through TriPass is used and is responsible for it: the controller under the EU and UK GDPR, the Data Fiduciary under India’s DPDP Act, and the equivalent responsible party under other privacy laws. Contact: support@tripass.com.au.
The short version
Your passwords, card details, secure notes and authenticator secrets are encrypted on your device before anything is uploaded. The key is derived from your master password using PBKDF2-SHA256 (600,000 iterations for accounts created now; 210,000 for accounts created earlier and for the key wrap on your device), and the data is sealed with AES-256-GCM. What reaches our servers is ciphertext. We hold no key that opens it.
We do collect some things, and they are listed below rather than summarised away.
Everything we store, and whether we can read it
| Where | What | Can we read it? |
|---|---|---|
| Firebase Auth | Your email address, and whether it has been verified | Yes |
users/{id} |
A random salt, a one-way verifier, and the iteration count — enough to check a master password is correct, never enough to learn it | Yes |
users/{id}/vault/blob |
Your logins, usernames, passwords, notes and tags | No — encrypted |
users/{id}/cards/blob |
Your saved payment cards | No — encrypted |
users/{id}/authenticator/blob |
Your two-factor authentication secrets | No — encrypted |
users/{id}/inbox/{entry} |
Logins saved by older versions of the TriPass Chrome extension, waiting for the iPhone app to add them to your vault. Deleted once the app has done so | No — encrypted |
users/{id}/devices/phone |
Which iPhone is using your account (one at a time): a random identifier made by the app, the word “iPhone”, and when it signed in | Yes |
users/{id}/recovery/kit |
Your encryption key, wrapped under your Recovery Kit code, plus a salt and a one-way verifier for that code | No — needs your code |
users/{id}/billing/* |
Whether your subscription is active, its product and expiry, and an identifier linking it to your Apple purchase | Yes |
Your master password is never transmitted, stored or logged
Not in plaintext, not hashed, not in any recoverable form. The value Firebase holds to sign you in is a separate one-way derivation of it under a different salt and domain tag, which cannot be reversed to your password and cannot decrypt your vault.
Where your data is held
All account data and encrypted blobs are stored in Google Cloud's australia-southeast1 region, in Australia, wherever you use TriPass from. If you are outside Australia, this means your account data is sent to and stored in Australia, which may have different data protection laws from your country. It is not transferred elsewhere for storage. Google Cloud processes it for us under its data processing terms.
Diagnostics and analytics
Crash reports. TriPass uses Firebase Crashlytics to record crashes, and some handled errors that did not crash the app: a stack trace, your iOS version and device model, and the app version. Crash reports are deliberately stripped of anything identifying your data — no vault contents, no item titles, no passwords, no keys, no email address. Crash reporting is on by default. You can turn it off in Settings → Privacy → Send crash reports; turning it off also deletes any report that has not been sent yet.
Usage analytics. TriPass sends anonymous, aggregate usage events to TelemetryDeck, an analytics provider based in Germany, so we can see which features are used and where people get stuck. Each event contains only: the event name (for example "app launched" or "password generated"), a SHA-256 hash of a random identifier created on your device (regenerated if you reinstall, and tied to nothing), a per-launch session identifier, the app version and the platform. Never vault contents, item titles, email addresses, or anything you type. Analytics are on by default; you can turn them off in Settings → Privacy → Share anonymous usage, and nothing is sent while they are off. TriPass does not track you across other apps or websites, and has no advertising identifiers.
Features that contact third parties
Two features reach outside TriPass. Both are described here because their privacy cost is real, not theoretical.
Breach checking uses the Have I Been Pwned Pwned Passwords API. It never sends your password. Your password is hashed with SHA-1 on your device and only the first five characters of that hash are sent; the service returns every hash beginning with those five, and the comparison happens on your device. This is k-anonymity: the service cannot determine which password you were asking about.
Site logos are fetched from Clearbit and Google's favicon service. This necessarily reveals to those providers which services you hold accounts with — never your usernames, passwords or codes. Because that is a genuine disclosure, this feature is off by default and stays off until you enable it in Settings.
Every server the app can contact
This is the complete list, so you can verify it against the app's actual traffic rather than take our word for it.
firebaseapp.com,googleapis.com— your account, and your encrypted blobs. Google Cloud, Australia.api.pwnedpasswords.com— breach checking, five hash characters at a time. Premium feature, only when you run a check.logo.clearbit.comandgoogle.com/s2/favicons— site logos. Off by default.nom.telemetrydeck.com— anonymous usage analytics. On by default; off in Settings.cloudfunctions.net— our own server, for subscription activation and Recovery Kit redemption.firebasecrashlytics.googleapis.com(part ofgoogleapis.com) — crash reports. On by default; off in Settings.
The website and the Phishing Scanner
tripass.com.au is hosted on Cloudflare, which processes standard request information such as your IP address to serve and protect the site. Pages load fonts from Google Fonts, so your browser contacts Google. The website sets no cookies and runs no advertising or analytics.
The website demos run in your browser. The breach-check demo sends only the first five characters of a SHA-1 hash to Have I Been Pwned, directly from your browser.
The web vault. If you create an account or sign in on tripass.com.au, your browser derives your keys itself and talks directly to the same Google Firebase services the app uses (identitytoolkit.googleapis.com and firestore.googleapis.com). It sends only what the app sends: your email address, a one-way sign-in value derived from your master password, the salt and verifier record, your Recovery Kit wrap and encrypted data. Your master password is never sent. Your decrypted vault exists only in that page’s memory; it is never written to cookies or browser storage, and it is cleared when you lock, close the tab or leave it idle for 10 minutes. After a lock, the page keeps your sign-in (not your key) in its memory so that unlocking within the hour needs only your master password; Sign out or closing the tab forgets it. On the web vault you can also add, edit and delete logins, cards and two-factor codes; each change is encrypted in your browser before it is saved, and reaches your iPhone and the Chrome extension the same way a change made on your iPhone does. If you forget your master password, the web vault can use your Recovery Kit: it derives a one-way proof from the code in your browser and sends only that proof and your email address to our recovery function (cloudfunctions.net), which checks it and returns your vault key still wrapped under the code; your browser unwraps it, re-encrypts everything under your new master password and gives you a new Recovery Kit. The code itself is never sent.
AutoFill on iPhone. If you turn on TriPass in Settings → Passwords → AutoFill, the app keeps an encrypted copy of your logins (names, usernames, passwords and websites; never cards, notes or two-factor secrets) in a folder on your iPhone that only TriPass and its AutoFill extension can reach. It is encrypted to a key that iOS releases only after Face ID or your passcode, every time a password is filled. It never leaves the iPhone and is deleted when you sign out.
The TriPass Chrome extension (in beta). It signs in and decrypts your vault in your browser in the same way as the web vault, and talks only to the same Google services (identitytoolkit.googleapis.com, securetoken.googleapis.com and firestore.googleapis.com). To suggest your logins and offer to save new ones, it runs on the web pages you visit and looks for login forms. It never sends page contents anywhere. It shows a site only the logins saved for that site, and fills one only when you click it. When you submit a login form, it holds the username and password you typed in your browser’s memory for up to 3 minutes to ask whether to save them, and forgets them as soon as you choose. If you press Save, the login is encrypted in your browser and saved to your vault, and reaches your iPhone and the website. You can also add, edit and delete logins, cards and two-factor codes from the extension; every change is encrypted in your browser first. It also works with login forms inside frames on a page, matching each form to the site that frame belongs to. While unlocked, the vault key is kept in the browser’s memory-only session storage, which is cleared when the extension locks (after the idle time you choose) or when Chrome closes. On disk it keeps only your email address (to fill in the sign-in form) and your settings: the auto-lock time and any sites you told it never to save for. Sign out removes the email.
The Phishing Scanner (web checker, installable app and Outlook add-in) checks emails on your device; email content is never uploaded unless you choose to send us a report (see “Reporting a mistake” below). Pictures and attached web pages in an email are read on your device too (to find QR codes and fake sign-in pages); remote images are never fetched.
Known phishing sites. To check whether a link goes to a known phishing site, the scanner turns the site's name into a one-way hash on your device and downloads one of 4,096 small files from tripass.com.au, chosen by the first three characters of that hash. Each file covers about 180 unrelated sites, so our server learns only which file was requested, never the site you're checking. Cloudflare sees the request like any other page request.
Live domain age check (optional, off until you turn it on). It sends the registered domain names of the sender and the links (for example example.com, never a full address or any email text) to our server at tripass.com.au, which looks up when each domain was registered through the public RDAP service at rdap.org. Nothing about the request is stored: results are cached briefly at Cloudflare's edge under a one-way hash of the domain.
Reporting a mistake. Under each result there is a button to send a report: “Send a missed-phishing report to TriPass” or “Send a false-alarm report to TriPass”. Nothing is sent unless you press it. When you do, the scanner sends to our server at tripass.com.au: on the website, the sender, subject and text you pasted (or the link you checked); in Outlook, the email's sender, subject, text and links, plus the sender-check lines from its headers (Authentication-Results, Received-SPF, Return-Path, Reply-To and From). It also sends the scanner's verdict and the reasons it gave. Attachments are never sent. A report can include personal information about you or other people that appears in that email, so don't send one if the email contains information you're not entitled to share.
We store each report on Cloudflare (Workers KV) with the time it was sent. We don't store your IP address with it, and reports aren't linked to a TriPass account. To stop abuse, the number of reports from one connection is limited using a one-way, salted hash of your IP address that changes daily and is not stored with the report.
Reports are not used automatically. A person at TriPass reads each report and decides whether it is correct before it is used, because a report can be mistaken or deliberately misleading. A report we judge to be wrong, or that holds information we shouldn't keep, is not used and is deleted. A report we accept may be used to train and test the scanner. Each report is deleted from our server automatically 12 months after it was sent; a reported email we used may remain, in processed form, in the scanner's training data after that. To have a report deleted sooner, write to us with roughly when you sent it and its subject or sender, so we can find it.
Payments
Subscriptions are sold through Apple's In-App Purchase. Apple processes the payment; we never see your card number, billing address or any payment credential. We receive from Apple a signed receipt and an anonymous account identifier so we know which TriPass account to activate. Apple's handling of your payment information is governed by Apple's own privacy policy.
Why we hold what we hold
- Your email address — to create your account, verify it is yours, and let you sign in.
- Salt, verifier and iteration count — to confirm your master password is correct without ever learning it.
- Encrypted blobs — so your vault survives a lost or replaced device. We cannot read them.
- Recovery Kit material — so a forgotten master password is recoverable by you, using the code only you hold.
- Subscription state — to know which features your account is entitled to.
- Crash reports — to find and fix defects. You can disable crash reporting in Settings.
- Anonymous usage events — to improve the app. They cannot identify you, and you can turn them off in Settings.
Legal bases. Where a law such as the EU or UK GDPR asks us to name one: your account, encrypted backups, Recovery Kit material and subscription state are processed to provide the service you signed up for (performance of a contract); crash reports and the security of our systems rest on our legitimate interest in a reliable, secure app, which you can object to by turning crash reports off; Phishing Scanner reports rest on your choice to send one; anonymous usage analytics rest on your choice in Settings, which you can change at any time; and where a law requires consent, such as India's DPDP Act, we rely on the consent you give at sign-up, which you can withdraw by deleting your account.
We do not sell or share your personal information, and we do not disclose it for advertising or profiling. We have never received a government or law enforcement request for user data; were we to receive one, we could only produce your email address, your subscription state, and ciphertext we cannot decrypt, plus any Phishing Scanner reports, which are not linked to an account.
How long we keep it
Your data stays until you delete it. Deleting your account from within the app removes your encrypted blobs (including logins waiting from the Chrome extension), your salt and verifier, your Recovery Kit material and your billing record, and then deletes the account itself. Local data on your device is erased at the same time. Crash reports are retained by Firebase Crashlytics for up to 90 days. Phishing Scanner reports are deleted automatically 12 months after they are sent.
Your rights
Wherever you live, you can ask us for a copy of the personal information we hold about you, ask us to correct it, and ask us to delete it. Access and export are also built into the app: you can export your entire vault at any time, and read access is never withheld, including if your subscription lapses. Deleting your account in the app erases your data from our servers.
Depending on where you live, you may have further rights, and we will honour them:
- EU, EEA and UK (GDPR): access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent at any time, plus the right to complain to your local data protection authority.
- Australia (Privacy Act 1988): access and correction under Australian Privacy Principles 12 and 13, and the right to complain to the Office of the Australian Information Commissioner (oaic.gov.au).
- India (DPDP Act 2023): access to a summary of your data and its processing, correction, completion, updating and erasure, grievance redressal, nominating someone to act for you, and approaching the Data Protection Board of India.
- United States: where a state privacy law gives you rights to know, delete or correct, you can use them the same way. We do not sell or share personal information, and we do not use it for targeted advertising.
To exercise any of these rights, or to raise a grievance, write to support@tripass.com.au. We will respond within 30 days, or sooner where the law where you live requires it. We will not treat you differently for exercising a right.
Children
TriPass is not directed at children. We do not knowingly create accounts for anyone under 16, and we do not profile or advertise to anyone. If you believe a child has created an account, contact us and we will delete it.
If there is a data breach
If we suspect a breach, we will assess it promptly and notify you and the relevant regulators within the time the applicable law requires (for example, within 72 hours of becoming aware of it for regulators under the GDPR, and as soon as practicable for affected people).
What a breach of our servers would actually expose: email addresses, subscription status, and ciphertext. Your vault contents, master password and Recovery Kit code are not on our servers in any readable form, so a database compromise does not expose them. We would still tell you, promptly and specifically, rather than leave you to guess whether you were affected.
Who to contact
Privacy questions, access and correction requests, and grievances all go to the same place, because a single developer publishes this app and routing them separately would only add delay:
Privacy and grievance contact: support@tripass.com.au
We acknowledge within 2 business days and respond substantively within 30 days.
What we are not
We would rather say this plainly than let a badge imply it. TriPass holds no compliance certification, and for most of these regimes there is nothing to certify:
- HIPAA does not apply. It binds healthcare providers, health plans, clearinghouses and their business associates handling protected health information. A consumer password manager is none of those, and storing a login for a medical portal is not us handling your health information. HIPAA also has no certification scheme, so nobody can be "HIPAA certified".
- GDPR compliance is not a certificate. We follow the EU and UK GDPR for people there, as described in this policy, but there is no official GDPR certification for an app like this, and we do not claim one.
- We hold no SOC 2 or ISO 27001 report. Those require an external audit of a company's controls, and we have not had one.
What we do have is a design where the server cannot read your data, and a policy that describes it accurately. Judge it on that.
Changes
If this policy changes in a way that materially affects you, we will say so in the app before the change takes effect, and the version and date at the top of this section will change. Previous versions are available on request.
Version 1.1 (4 October 2026): usage analytics switched on (with the opt-out in Settings); a Settings switch for crash reports, which also cover some handled errors; current key-derivation figures; a section for the website and the Phishing Scanner's optional live domain check.
Version 1.2 (4 October 2026): rights and legal bases for people in every country where TriPass is used, including the EU, UK and US; where data is stored, stated for international users; the website section brought up to date, including the web vault.
Version 1.3 (5 October 2026): the Phishing Scanner's private check against known phishing sites; reports of missed phishing and false alarms that you choose to send; the optional domain check no longer consults URLhaus.
Version 1.4 (5 October 2026): scanner reports are now sent directly to our server when you press the report button, instead of through your email app; what a report contains, that it is stored without your IP address and that it is deleted automatically after 12 months.
Version 1.5 (5 October 2026): scanner reports are read by a person before they are used; reports judged wrong, or holding information we shouldn't keep, are not used and are deleted.
Version 1.7 (5 October 2026): changes made on the website or in the Chrome extension now save straight to your encrypted vault (no inbox); account recovery with your Recovery Kit on the website; one iPhone per account, recorded in users/{id}/devices/phone; iPhone AutoFill, which keeps an encrypted copy of your logins on the iPhone that only Face ID or your passcode opens.
Version 1.6 (5 October 2026): encrypted backup is available on every plan, not only Premium; the TriPass Chrome extension, including logins saved from Chrome and held encrypted in users/{id}/inbox until the iPhone app adds them to your vault; the web vault keeps your sign-in in memory after a lock.