Privacy notice · Effective 6 September 2026
Your vault never leaves your device in a readable form.
This notice covers SiliconPass on iPhone, iPad and Mac, including its AutoFill extension. The data controller is LorisLabs, operated by Christine Martin in France. Contact: [email protected].
1. What LorisLabs receives
Nothing. SiliconPass has no account, no analytics SDK, no advertising SDK, no crash reporting service and no tracking domain. It ships with zero third-party dependencies. We cannot read your vault, and we do not receive a copy of it, a fingerprint of it, or a count of what is in it.
2. Your vault
Your master passphrase is stretched with Argon2id and, where the device provides one, bound to the Secure Enclave. Every record is sealed individually with AES-GCM. The vault database, its manifest and its audit journal are stored on your device under Apple's file protection, and secrets held in the Keychain are marked device-only and non-synchronizable.
The master passphrase cannot be reset or recovered — not by us, not by Apple. That is a design decision, and it is the reason the vault is yours.
3. Breach checking — off unless you turn it on
If you enable it, SiliconPass computes a SHA-1 hash of a password on your device and sends only the first five characters of that hash to api.pwnedpasswords.com, operated by Have I Been Pwned. The password never leaves the device, and neither does the site it belongs to. The service returns a range of hash suffixes and the comparison happens locally. Requests are padded and shuffled, and no response is cached.
What the service can still observe is that some IP address is running SiliconPass and how many prefix queries it makes. That is stated here rather than omitted.
4. Email aliases — only with your own account
If you connect a SimpleLogin account, SiliconPass uses your API token to create aliases through app.simplelogin.io or the self-hosted instance you configure. The token is stored in the Keychain, device-only, outside any shared access group, so the AutoFill extension cannot read it.
Aliases are created against a constant domain rather than the site you are signing up to. SimpleLogin therefore never learns which of your accounts an alias belongs to.
5. iCloud sync
If you enable sync, records travel through your own private CloudKit database. Titles, hosts, usernames and passwords are sealed before they leave the device: Apple sees the encrypted content, plus the technical metadata the merge needs — a record kind, a vector clock, a device identifier and a signature. It does not see what any record is for.
6. Pairing a second device
Pairing happens over your local network. The two devices agree on a key, you compare an eight-digit code shown on both screens, and every message that follows is sealed under a key derived from that same agreement. Nothing about your vault crosses the network in readable form.
7. Retention and your rights
Because LorisLabs holds no personal data from this app, there is nothing for us to retain, export or erase on your behalf. Deleting the app removes the local vault. Under the GDPR you retain your rights of access, rectification, erasure, restriction, portability and objection; write to [email protected] and we will answer even where the answer is that we hold nothing.
8. Changes
Material changes will be dated on this page. A change will not silently add telemetry, nor send vault content to LorisLabs.