Password Manager

Logins, cards and notes, behind the same PIN as everything else.

It is opt-in

The vault is off until you turn it on, under Settings → Modules → Password Manager. Turning it off hides the entry from your account menu; nothing stored is deleted.

Generator

Builds passwords locally. Nothing generated is transmitted, logged, or reused across entries.

Breach check

Tells you whether a password appears in known breach corpora, without your password ever leaving the device in a readable form.

Expiry & audit

Flags entries that are stale, weak, or reused, so a vault that has grown over years does not quietly rot.

CSV import

Brings entries in from another manager, parsed on-device. Logins that look like card numbers are reclassified rather than silently stored as passwords.

One PIN, one key

The vault is not a separate product with its own password. It is encrypted with the same PIN-derived key as your financial data, held in memory only and never written to disk. That is why the vault requires a PIN even when app lock is otherwise relaxed: without the key there is nothing to decrypt, so the surface cannot be shown at all.

A forgotten PIN is not recoverable by us

There is no account, so there is no reset link and no support route back in. The recovery kit generated in Settings is the only way to unwrap your PIN — print it, or store it somewhere that is not this device. See Data Privacy and Security Architecture for how the kit is sealed.