Last updated: March 2026
We cannot see your data. We do not want to. This is not a marketing claim. It is an architectural fact.
All your vault data (passwords, secrets, notes, files, auth codes) is encrypted with AES-256-GCM using a key derived from your master password via Argon2id. The encrypted database is stored locally on your device using SQLCipher.
Your master password is never stored anywhere. Not on your device, not on any server, not in any log.
Almost nothing. The only network communication happens when you use the Whisper feature to share a secret:
If you enable cloud sync, your data is encrypted before leaving your device. The encrypted blobs are stored in your own iCloud or Google Drive account. We never see or process your synced data.
Lockbox does not integrate with any third-party analytics, advertising, or tracking services. The only external service is the Whisper relay, which is operated by us on our own infrastructure.
Uninstall the app and all local data is gone. If you used cloud sync, delete the Lockbox folder from your iCloud or Google Drive. If you used the Dead Man's Switch, the app automatically deletes all data after your configured inactivity period.
Our encryption module is open source. You can inspect exactly how your data is encrypted, what keys are derived, and verify that no data leaks occur.
Questions about privacy? Email privacy@lockboxnow.app