Privacy Policy
This policy explains how XApp Studio processes information when you use PassNote, visit passnote.dev, contact support, or purchase PassNote PRO.
1. Scope and controller
XApp Studio is the developer of PassNote and the controller of information processed for the service. This policy covers the PassNote mobile app, passnote.dev, and support communications.
Apple, Google, Firebase, RevenueCat, and advertising partners may act as independent controllers or processors for their services. Their policies also apply to information they process.
2. Information we process
2.1 Account information
When you sign in with Google or Apple, Firebase Authentication processes an account identifier and available profile information, such as your email address, display name, and profile image URL. Apple may provide a relay email address.
2.2 Encrypted vault information
Your vault may contain logins, passwords, payment-card details, Wi-Fi credentials, secure notes, URLs, and other fields you add. PassNote encrypts vault fields on your device with AES-256-GCM before synchronization. Firebase Firestore stores the encrypted payload with your account record.
Your encryption key is not included in the synchronized vault record. It is kept in protected local device storage. An optional key hint is stored with your account and is not encrypted, so do not place the key or other secrets in the hint.
2.3 Device and app information
PassNote may process app version, operating system, language, configuration values, and device-level identifiers needed to operate Firebase, advertising, purchase, update, and security features.
2.4 Analytics information
Firebase Analytics records app interactions such as screen views, selected tabs, sign-in method, plan type, settings changes, import actions, and whether a vault item includes certain categories or notes. Analytics events are designed not to include vault field values, passwords, encryption keys, or imported file contents.
2.5 Advertising information
The free tier may display Google AdMob advertising when ads are enabled. Subject to consent choices and platform settings, AdMob may process advertising identifiers, device information, IP-derived information, ad interactions, and diagnostics. PassNote PRO removes in-app ads while the entitlement is active.
2.6 Purchase and entitlement information
Apple or Google processes your payment details. PassNote does not receive your full card number. RevenueCat and the applicable app store provide PassNote with purchase and entitlement information such as product identifier, store, transaction status, plan type, expiry date, renewal state, trial eligibility, and an app user identifier.
2.7 Support and website information
If you contact support, we process your email address, message, and any information you choose to provide. Standard hosting infrastructure may process request data such as IP address, browser type, requested URL, and timestamp for security and delivery.
2.8 Biometrics
Biometric verification runs through your device operating system. PassNote receives the success or failure result and does not receive or store your face or fingerprint template.
3. Why we process information
We process information for these purposes:
- Provide authentication, encrypted synchronization, offline access, support, and account management
- Verify PassNote PRO purchases, restore entitlements, and apply plan limits
- Maintain security, prevent abuse, and diagnose service failures
- Understand feature usage and improve the app
- Display and measure ads when enabled and permitted
- Comply with legal obligations and enforce our Terms of Service
Depending on your location, our legal bases may include performing our contract with you, your consent, our legitimate interests in operating and securing the service, and compliance with law. You may withdraw consent for future processing where consent is the applicable basis.
4. Service providers and sharing
We share information only as needed to operate PassNote, complete a transaction, comply with law, or protect the service. We do not sell your vault contents.
- Google Firebase: Authentication, Firestore, Analytics, and Remote Config
- Google and Apple: Sign-in, app distribution, in-app purchases, refunds, and subscription management
- RevenueCat: Purchase validation and Premium entitlement management
- Google AdMob: Advertising and ad measurement when ads are enabled
- Firebase Hosting: Delivery and security of passnote.dev
Review the privacy information published by Google, Apple, and RevenueCat.
We may disclose information in response to valid legal process, to protect rights and safety, or as part of a business transaction subject to appropriate safeguards.
5. Encryption and security
PassNote uses authenticated AES-256-GCM encryption for vault fields, protected local storage for the encryption key, and HTTPS for network transport. No security method eliminates every risk. Protect your device, store your encryption key safely, and do not disclose it to support staff.
Because XApp Studio does not keep a copy of your encryption key in the synchronized vault record, support may be unable to recover encrypted vault data if you lose the key.
6. Retention and deletion
We retain your account record and encrypted vault payload while your account remains active. Support messages are retained as needed to resolve requests, maintain records, and comply with law.
When you delete your account in the app, PassNote requests deletion of the Firebase Authentication account and the associated Firestore user record containing the encrypted vault. Deletion from provider backups may follow each provider's backup rotation. Analytics, advertising, fraud-prevention, transaction, and tax records may remain for the provider's retention period or where law requires them.
Deleting your PassNote account does not automatically cancel an Apple or Google subscription. Manage cancellation through the store where you purchased it.
Use the account deletion page if you cannot access the app.
7. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to appeal or complain to a data protection authority.
You can update some profile settings in the app, delete individual vault items, delete your account, manage subscription settings through Apple or Google, and use device or consent controls for advertising. To make another privacy request, email support@passnote.dev. We may need to verify that the request relates to your account.
PassNote does not use vault contents for cross-context behavioral advertising. If applicable law treats certain AdMob processing as a sale or sharing, available consent and platform controls apply.
8. International transfers
Our providers may process information in countries outside your residence. Where required, transfers rely on contractual safeguards, adequacy decisions, or another lawful mechanism used by the relevant provider.
9. Children
PassNote is not directed to children under 13 or under the minimum age required to consent to digital services in their location. If you believe a child provided personal information without valid authorization, contact us so we can review and delete it where required.
10. Changes and contact
We may update this policy when the service, providers, or legal requirements change. We will update the effective date and provide additional notice when required.