Open the vault

Privacy

Alpha is a password manager built so that the people who run it cannot read what you keep in it. This page says exactly what reaches our server, what we can read once it arrives, and what we cannot.

Last updated 26 August 2026.

The short version

Your master password never leaves your device. Everything in your vault is encrypted on your device before it is sent, with a key derived from that password. We store the result. We cannot decrypt it, and neither can anyone who compels or breaches us.

Alpha contains no analytics, no telemetry and no crash reporting. There is no third-party SDK in the app. The Android app requests one permission, INTERNET, and it is used to reach our server and nothing else. We do not use cookies for tracking, we do not build a profile of you, and we have nothing to sell to advertisers because we do not collect it.

What we store, and whether we can read it

WhatCan we read it?
Your email addressYes. It identifies your account and is where we send recovery mail.
Names you give your devices, e.g. “Vivek’s iPhone”Yes. Shown to you when approving a recovery.
Your password hint — only if you turned on emailing itYes, and only then. See below.
Every item: passwords, notes, one-time-code secrets, passkeys, attachmentsNo. Encrypted on your device.
Your master passwordNo. It never leaves your device, in any form we could reverse.
Your recovery keyNo. It is never uploaded.
Your password hint — if you did not turn on emailingNo. Encrypted like an item.

What we can see without reading anything

Encryption hides contents, not the existence of contents. We can see how many items you have, roughly how large each one is, when you last synced, how many devices you use, and who you have shared an item with. We would rather say so than imply otherwise.

The password hint

A hint is optional. By default it is encrypted like everything else and we cannot read it — your own devices can, which is how it appears on your lock screen.

If you ask Alpha to be able to email your hint to you, we keep a readable copy, because a hint we cannot read is a hint we cannot send. That copy is the single piece of text you write that we can read. It is capped at 100 characters, the app refuses a hint that contains your password, and you can remove it at any time. If you never turn this on, we never have it.

Email

We send email for one reason: getting you back into your account. Recovery codes, device-approval requests, and your hint if you asked for it. We send no marketing, and there is no list to unsubscribe from.

Mail is delivered through Cloudflare, who handle it on our behalf and see the messages in transit as any mail provider does. Seven days after a message is delivered we erase its contents from our system, keeping only the record that it was sent and to whom.

How long we keep things

Who else is involved

Our server runs on Railway, and stores its database and files there. Email goes out through Cloudflare. Both hold what is described above — which for your vault means ciphertext they cannot read. We use no other processor, and we share your data with nobody else. We have never received a government request for user data; if we do, what we are able to hand over is what this page says we can read, and no more.

Your data is yours

Children

Alpha is not directed at children under 13 and we do not knowingly create accounts for them.

If this page changes

The date at the top changes with it. If a change means we can read something we could not read before, we will say so in the app, not only here.

Contact

privacy@alphapassword.app