Privacy Policy
Effective Date: October 10, 2026
Armor Pass ("we", "our", or "the application", package name: com.sumpena.armorpass) is committed to protecting your privacy. This Privacy Policy explains how Armor Pass handles your information.
🔒 Zero-Knowledge Architecture: Armor Pass operates on a strict zero-knowledge model. All your passwords, accounts, and credentials are encrypted locally on your device. We do not have access to your master password or your decrypted vault data.
1. Information We Process
Armor Pass processes the following types of information strictly to provide offline password management and optional encrypted backup services:
- Vault Credentials: Usernames, passwords, notes, PINs, and custom fields that you enter into the application. All credentials are encrypted locally using AES-256-GCM authenticated encryption with keys derived via Argon2id.
- Google Account Information: If you choose to enable Google Drive Sync, the app accesses your basic Google account identity (email address and name) solely to authenticate and connect to your Google Drive account.
- Biometric Data: If you enable biometric authentication (fingerprint or face unlock), verification is handled entirely by the Android operating system (Android BiometricPrompt & KeyStore). Armor Pass never collects, stores, or accesses your biometric data.
2. How We Use Your Information
- Encrypt and decrypt your vault data locally on your device.
- Fill credentials securely into apps and browsers via the Android Autofill service when requested by you.
- Backup and synchronize encrypted vault files to your personal Google Drive storage (only if enabled).
3. Local Data Storage
Your vault data and master password are never stored in plaintext and are never sent to our servers. All sensitive data remains securely stored on your local device storage.
4. Google Drive Integration & Google API Limited Use Disclosure
Armor Pass includes an optional feature allowing you to backup and sync your encrypted vault file with your personal Google Drive account.
- Restricted Scope: Armor Pass only requests access to the Google Drive Application Data folder (
https://www.googleapis.com/auth/drive.appdata) and files created by the app (https://www.googleapis.com/auth/drive.file). - No Access to Personal Files: Armor Pass cannot read, view, modify, or delete any other files, photos, or documents in your Google Drive.
- Direct Communication: Communication occurs directly between your device and Google's official Drive API endpoints. We do not operate intermediary proxy servers and never access your Google tokens or data.
- Limited Use Compliance: Armor Pass's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Your Google user data is never transferred to third parties, never used for advertising, and never used to train machine learning models.
5. Analytics & Advertising
Armor Pass does not use analytics services or tracking libraries. Armor Pass does not display advertisements.
6. Data Sharing
We do not sell, rent, monetize, or share your personal information or vault data with third parties.
7. Security
We implement industry-standard cryptographic practices to safeguard your data, including:
- Zero-Knowledge client-side encryption (AES-256-GCM).
- High-memory key derivation (Argon2id KDF).
- Screen capture protection (Android
FLAG_SECURE) to prevent unauthorized screenshots and recordings. - Secure hardware-backed biometric authentication.
8. Data Deletion and User Rights
You have full control over your data at all times:
- Local Data: You can delete your vault data at any time from within the application or by clearing the app data in Android Settings.
- Google Drive Backup: You can delete your hidden backup file at any time from Google Drive web settings (Settings > Manage Apps > Armor Pass > Delete hidden app data) or by disconnecting your Google account in Armor Pass settings.
9. Contact
Developer: Langit Biru Cerah
Application: Armor Pass (com.sumpena.armorpass)
Email: bantu.uwang@gmail.com
Kebijakan Privasi
Tanggal Berlaku: 10 Oktober 2026
Armor Pass ("kami", atau "aplikasi", package name: com.sumpena.armorpass) berkomitmen penuh untuk melindungi privasi pengguna. Kebijakan Privasi ini menjelaskan bagaimana aplikasi Armor Pass mengelola informasi Anda.
🔒 Arsitektur Zero-Knowledge: Armor Pass beroperasi dengan prinsip zero-knowledge. Seluruh kata sandi, akun, dan data brankas Anda dienkripsi secara lokal di perangkat Anda. Kami tidak memiliki akses ke master password maupun data brankas Anda.
1. Data yang Diproses
- Kredensial Brankas: Nama pengguna, kata sandi, catatan rahasia, PIN, dan bidang kustom dienkripsi secara lokal menggunakan AES-256-GCM dengan kunci dari fungsi Argon2id.
- Informasi Akun Google: Jika mengaktifkan Sinkronisasi Google Drive, aplikasi mengakses identitas akun Google dasar (email dan nama) untuk menghubungkan brankas ke Google Drive pribadi Anda.
- Data Biometrik: Verifikasi biometrik ditangani sepenuhnya oleh Android BiometricPrompt & KeyStore. Armor Pass tidak pernah menyimpan data fisik biometrik Anda.
2. Integrasi Google Drive & Kepatuhan Google API
Armor Pass hanya meminta akses cakupan terbatas (restricted scope) yaitu drive.appdata dan drive.file. Kami tidak mengakses file pribadi lain di Google Drive Anda. Komunikasi berlangsung secara langsung dari perangkat Anda ke Google API tanpa server perantara pihak ketiga.
3. Tanpa Iklan dan Tanpa Pelacak
Armor Pass tidak menggunakan library analitik pelacak dan bebas dari iklan.
4. Kontak
Pengembang: Langit Biru Cerah
Aplikasi: Armor Pass (com.sumpena.armorpass)
Email: bantu.uwang@gmail.com