Effective Date: August 14, 2026 • Developer: pgdeveloper
Zero Knowledge
Your master password never leaves your device.
AES-256-GCM
Military-grade encryption for all saved credentials.
No Ads or Analytics
Zero tracking, zero analytics, zero profiling.
01 Introduction & Overview
Ironclad (developed by pgdeveloper, package com.pgdeveloper.ironclad) is a local-first, zero-knowledge password manager. Our core commitment is to protect your digital privacy and ensure that your passwords and personal sensitive data remain completely under your own control.
This Privacy Policy explains how data is handled within the Ironclad application.
02 Information We Collect & Store
We do NOT collect, transmit, store, or share any of your personal data or vault contents on any remote servers.
Vault Credentials: All usernames, passwords, URLs, and notes are encrypted locally on your device using AES-256-GCM with PBKDF2 key derivation (600,000 iterations). Plaintext data exists only in ephemeral device memory while unlocked.
Master Password: Your master password is never stored anywhere on your device or remote servers. Only a cryptographic validation hash is kept locally to verify password entry.
Biometric Data: Biometric authentication (fingerprint / Face Unlock) is handled entirely by Android's hardware-backed BiometricPrompt API. Ironclad never has access to raw biometric data.
03 Network Usage & Third-Party Services
Ironclad operates locally by default and requires minimal network connectivity:
Breach Detection (Have I Been Pwned): When using the security check feature, Ironclad calculates the SHA-1 hash of your password locally and sends only the first 5 characters of the hash over HTTPS to the Have I Been Pwned API (using the industry-standard k-Anonymity model). Your actual password and complete hash are never transmitted over the internet.
No Telemetry or Ads: Ironclad contains zero analytics SDKs, zero advertising networks, and zero tracking code.
k-Anonymity Security: Sending only the 5-character prefix of a SHA-1 hash ensures that your identity and real password can never be reconstructed or identified by external servers.
04 Data Storage & Security
Your vault database is stored in Android's protected application storage directory. Additional protection measures include:
Screenshot & Screen Recording Prevention: Protected via Android's FLAG_SECURE system flag.
Auto-Locking: Automatic vault locking after inactivity or when the app is placed in the background.
Clipboard Clearance: Automatic clearing of copied passwords after 30 seconds.
Cloud Backup Exclusion: Vault databases and encryption keys are explicitly excluded from Android Google Cloud Backups and device-to-device transfers.
05 Data Deletion & Your Rights
Because all data resides strictly on your local device:
You can permanently delete all stored vault data at any time by selecting "Clear Vault" in Settings or by uninstalling the application.
Uninstalling the Ironclad app immediately and permanently erases all local database records and secure key cache from your device.
06 Changes to This Privacy Policy
We may update our Privacy Policy from time to time. Any changes will be reflected on this page with an updated effective date.
07 Contact Us
If you have any questions or feedback regarding this Privacy Policy or Ironclad's security architecture, please contact us: