Privacy Policy
Lockwell ("the App") is a KeePass-compatible password manager. Your vault data stays on your device or storage you choose.
Shown in-app under Settings → About → Privacy Policy.
Support: yogendra.danwar@gmail.com
Data we collect
The App does not collect personal data on our servers. There is no Lockwell account and no first-party analytics.
Data stored on your device
- Password vault files (
.kdbx) and entries you create or import. - An optional app unlock PIN and biometric preference.
- App preferences (theme, clipboard timer, etc.).
- App purchase status via Apple/Google (paid download; handled by the store; we do not receive payment card details).
- Optional tip purchases via Apple In-App Purchase / Google Play Billing (consumable; unlock no features).
Vault credentials and master passwords are stored encrypted in KeePass format. The app unlock PIN is stored in iOS Keychain / Android Keystore.
Network
The App works offline by default. Network is used only when you enable optional features:
- Have I Been Pwned (optional): when you enable breach checks and run a scan, Lockwell sends only the first five characters of a SHA-1 password hash to the Have I Been Pwned range API (k-anonymity). Your full password never leaves the device.
-
Vault import from URL / WebDAV / SFTP (optional):
connects only to addresses you enter, to download a
.kdbxonto this device. Credentials you type for those servers stay on device for the session and are not sent to Lockwell. -
Google Drive (optional): when you choose Google Drive
and sign in, Lockwell uses Google OAuth to request Drive access so you
can browse folders, open a
.kdbx, and write your edits back to that same Drive file when you save. Access tokens stay in the device Keychain/Keystore. Lockwell does not send your vault to Lockwell servers. You can disconnect anytime in the Drive browser. -
Dropbox / OneDrive / iCloud (optional): you can open a
.kdbxthrough the system Files (or storage) picker when those locations are available on your device. Lockwell copies the chosen file locally. If you later connect Dropbox or OneDrive with in-app sign-in, edits can be written back to that cloud file; tokens stay on device. - Local network transfer (optional): briefly listens on your Wi-Fi so another device can send a vault file directly to this phone. Traffic stays on your local network.
- Favicon fetch (optional): requests icons from URLs derived from your entry websites.
- Store payments: Apple / Google process the paid app purchase and any tip payments; Lockwell does not receive card details.
Lockwell does not upload your vault to our servers.
Third parties
Lockwell is an independent product and is not affiliated with Apple, Google, or KeePass. All trademarks belong to their respective owners.
Contact
Questions about this policy: yogendra.danwar@gmail.com
Deletion
Uninstalling the App removes locally stored vaults, PIN, and preferences from the device (subject to platform backup behavior).