
Zen Passwords · Privacy Policy
This Privacy Policy explains how ZENPRODUCTS TECHNOLOGIES PRIVATE LIMITED ("we," "us," or "our"), trading as zenproducts, handles information in connection with the Zen Passwords application for iPhone, iPad, and Mac (the "App") and related pages on www.zenproducts.ai (the "Site").
Controller: ZENPRODUCTS TECHNOLOGIES PRIVATE LIMITED. Primary contact: hello@zenproducts.ai. For a current registered address or formal data protection correspondence, use the same email with the subject line "Zen Passwords · Privacy."
This Policy is meant to be specific. Where a practice depends on Apple infrastructure (iCloud, App Store, Keychain, Local Authentication), Apple's own terms and privacy policy also apply.
1. Summary
- Vault secrets (passwords, TOTP secrets, card and bank fields, secure notes, sealed titles, attachments, and similar) are encrypted on your device. Keys are derived from your master password. We do not receive your master password and cannot decrypt your vault.
- Optional sync uses Apple's private CloudKit database for the App's container, under your Apple ID. We do not run a Zen-hosted vault server.
- The App build described here does not embed third-party advertising or analytics SDKs that report vault contents or vault activity to us. Local logs and Apple system diagnostics (if you opt in with Apple) are separate; see Section 9.
- The Site (not the App vault) uses hosting logs and may use aggregate analytics or performance tools when configured. Those tools cannot read your vault. See Section 3.5.
- Zen Premium is sold through Apple In-App Purchase. We receive entitlement status via StoreKit, not your payment card number.
The summary does not replace the rest of this Policy.
2. Scope
This Policy covers:
- Use of the Zen Passwords App on Apple devices;
- Visits to Zen Passwords pages and related Site content on our domain; and
- Messages you send to us (for example support email).
It does not govern websites you open from saved URLs, other zenproducts apps (each may have its own policy), or Apple services you use under Apple's terms.
3. Information we process
3.1 Vault content you enter in the App
Depending on how you use the App, vault items may include:
- Logins and related fields (usernames, passwords, URLs, notes, custom fields);
- Passkeys and related credential material managed by the App;
- One-time password (TOTP) secrets;
- Payment cards, identity details, bank account fields, Wi-Fi credentials, and software licenses;
- Secure notes and attachments (for example images);
- Folders, tags, favorites, archive and pin state, and sort preferences.
Sensitive item bodies, sealed list titles and tags, sealed folder names, and sealed attachments are stored as ciphertext under keys derived from your master password (see Section 4).
3.2 Cryptography and biometrics
Unlock uses on-device key derivation (currently Argon2id for new vaults, with migration support for older PBKDF2 wraps). Vault payloads are sealed with AES-GCM. Exact parameters may change with App versions when we publish a migration path.
If you enable Face ID, Touch ID, or Optic ID, related key material may be stored in the Apple Keychain under biometric access control and processed through Local Authentication and the Secure Enclave. We do not receive biometric samples or templates.
3.3 Preferences and free-tier state
The App stores preferences on device (for example appearance, lock timing, clipboard clear timing, whether to load website icons, biometric unlock toggles, sync-related preferences, and subscription status caches). Free-tier selection state may also sync limited non-secret identifiers (for example item UUIDs and flags) through iCloud Key-Value storage when you use Apple's account features, so limits stay consistent across your devices.
3.4 Information you send to us
If you email hello@zenproducts.ai or use App Store contact links, we receive your address, message content, and any attachments or diagnostics you choose to include. We use that to respond, improve the product, and meet legal obligations. Do not send your master password in email.
3.5 Website visitors (Site, not vault)
When you visit the Site, our hosting and analytics providers may process standard technical data such as IP address, device and browser information, approximate location derived from IP, referrer, pages viewed, and similar event data.
- Hosting: our Site hosting environment processes request logs needed to deliver the Site.
- Site analytics and performance metrics: when enabled, aggregate product and performance metrics help us understand traffic and fix issues. These tools cannot access your vault.
- Optional measurement tools: when enabled via Site configuration, additional measurement processors may receive standard web analytics events under their own terms. They are not embedded in the App and cannot access your vault.
You can limit some Site measurement with browser controls, OS privacy settings, or industry opt-outs where available. Blocking analytics does not affect App vault encryption.
3.6 Network requests the App may make
Besides Apple services you enable, the App may:
- Contact Apple for CloudKit sync, StoreKit product and purchase flows, App Store lookup helpers (for example review links), and opening Apple legal pages you choose to view;
- When Settings → Privacy → Load website icons is on (the default), fetch site icons for saved domains from a public favicon service. The request includes the domain name, not your password or vault ciphertext. Turn the setting off to use letter or monogram placeholders only, with no icon network requests.
- Open URLs you save, using the system browser, when you tap to open them.
The App does not call a Zen Passwords publisher API to upload vault plaintext, and does not use advertising identifiers (IDFA) or App Tracking Transparency prompts for cross-app tracking.
4. Storage, sync, AutoFill, and metadata
4.1 On-device storage
Primary vault storage uses SwiftData (and related files) on your device. Where the OS supports it, the App may apply file-protection attributes. Exact protection depends on your device settings, OS version, and backup configuration.
4.2 Optional iCloud / CloudKit sync
When you are signed into iCloud and sync is enabled, records may sync through your private CloudKit database for the App container. Encrypted payloads travel as ciphertext. A key envelope (salt and wrapped data-encryption key material, and recovery wrap fields if you configure recovery) may sync so your other devices can unlock with the same master password or recovery key. The master password and recovery key themselves are not stored by us and are not uploaded as plaintext.
4.3 Non-secret metadata
To show lists, merge changes, and model CloudKit records, some fields are not full ciphertext of every display attribute. Examples include record identifiers (UUIDs), item type, sort order, favorite / archive / pin flags, timestamps, folder accent color, and free-tier related UUID lists or flags. This metadata is not a substitute for your encrypted secrets. Field sets may evolve with App versions.
4.4 AutoFill and credential provider extension
If you enable AutoFill or passkey features, the App may maintain an App Group index and place credentials needed for filling into the shared Keychain used by the credential provider extension while the vault is unlocked. When you lock the vault, the App clears that fill mirror (indexes, fill Keychain secrets, and system credential identities) so AutoFill should not keep offering vault passwords until you unlock again. Separate pending queues can briefly hold secrets that the extension just saved or registered so they can merge into the vault on the next unlock; those queues are cleared on vault reset. Treat device lock, OS updates, and extension permissions as part of your security posture.
4.5 Apple backups
Device backups and iCloud Backup may include App data according to your Apple ID and device settings. Encrypted vault payloads remain ciphertext without your master password.
4.6 No publisher-hosted vault cloud
We do not operate a centralized Zen Passwords cloud that stores your decrypted vault or your master password.
5. How we use information
We process information to:
- Provide and maintain the App (including sync, search, organization, security features, and Premium gating);
- Operate and improve the Site;
- Respond to support and communicate about security or policy updates;
- Comply with law, enforce our Terms, and protect rights and safety.
We do not sell your personal information. We do not use vault contents for advertising. We do not train generalized machine-learning models on your vault data.
6. Legal bases (EEA, UK, and similar regimes)
Where the GDPR or similar laws apply, we rely on:
- Contract: providing the App and features you request;
- Legitimate interests: security, abuse prevention, Site analytics, product improvement, and support, balanced against your rights;
- Consent: where required (for example optional marketing email if we offer it later; support email today is transactional);
- Legal obligation: where retention or disclosure is required by law.
You may have rights to access, rectify, erase, restrict, port, or object, and to lodge a complaint with a supervisory authority. Because most vault secrets are encrypted with keys we do not hold, deleting items in the App, resetting the vault, or removing the App (and managing iCloud copies under your Apple ID) is usually the practical path to remove vault data from your environment. For Site analytics or support mail we hold, email hello@zenproducts.ai.
7. Sharing and processors
7.1 Apple
Apple provides the OS, App Store, In-App Purchase, iCloud, CloudKit, Keychain, Local Authentication, and related infrastructure. Apple's privacy policy applies to those services.
7.2 Site and support processors
We use hosting and analytics processors needed to operate the Site, and we may use email or ticketing providers for support. They process data only to provide their services to us.
7.3 Favicon provider
Domain-only favicon requests may be handled by a public favicon service as described in Section 3.6.
7.4 Legal and safety
We may disclose information if we believe in good faith disclosure is required by law, legal process, or to protect rights, safety, or security.
7.5 Business transfers
If we merge, are acquired, or sell assets, information may transfer to a successor under safeguards required by law.
8. International transfers
If you use iCloud, Apple may process data according to Apple's infrastructure. Site analytics and support mail may be processed in countries where our providers operate. Where required, we rely on appropriate transfer mechanisms (for example Standard Contractual Clauses offered by providers).
9. Analytics, logging, and diagnostics
9.1 Inside the App
Current App builds do not ship third-party advertising or analytics SDKs that phone home vault activity to us. The App may write technical logs locally (including Apple unified logging) for debugging. Those logs are not a product for selling personal data.
9.2 Apple diagnostics
If you opt in to sharing analytics with Apple, Apple may collect diagnostics under Apple's privacy policy. That relationship is between you and Apple.
9.3 Site measurement
Site measurement is described in Section 3.5 and is separate from App vault processing.
9.4 Future App telemetry
If we later add optional crash reporting or feature telemetry inside the App, we will update this Policy and in-App disclosures before or when that ships.
10. Retention
- Vault data remains until you delete items, reset the vault, or remove the App, subject to backups and sync copies under your Apple ID.
- Support email is kept as long as needed to resolve issues and for legitimate business or legal needs, then deleted or minimized where feasible.
- Site analytics retention follows our providers' configurations and our operational needs for traffic analysis.
- Subscription status is determined by Apple; we do not receive or store your payment card number for App Store purchases.
11. Security
We design the App so vault secrets are encrypted on device and so we do not hold your master password. No software or transmission path is perfectly secure. You reduce risk by using a strong unique master password, keeping devices updated, enabling device passcodes and disk encryption, reviewing AutoFill permissions, and treating exports and shared files as highly sensitive.
12. Clipboard and screen privacy
When you copy a field, content is placed on the system pasteboard so you can paste into other apps (for example Safari). Cross-app paste requires the general pasteboard under platform rules. The App shortens how long that content stays available: a Settings timer (default about 45 seconds) can clear the clipboard after copy if the value was not replaced, and on supported iOS versions the pasteboard item may also carry a matching expiration. Manual and idle lock clear the pasteboard immediately. Background or scene auto-lock keeps a short grace window so a password you just copied can still be pasted, then clears the pasteboard.
On supported iOS versions, the App may blur sensitive UI while the screen is being captured, and may mark locked UI as privacy-sensitive in the app switcher. These are best-effort OS features, not cryptographic guarantees.
13. Password health and similar tools
Password health and related checks run on your device against decrypted data in memory during the scan. We do not receive your plaintext passwords for that feature, and the App does not call third-party breach lookup APIs for those checks in the current design.
14. Children
The App is not directed at children under 13 (or the higher age required in your country). Do not use the App to collect children's personal information without appropriate authority. If you believe we received child data improperly through support channels, contact hello@zenproducts.ai.
15. California residents (summary)
California law may grant rights to know, delete, and opt out of certain "sales" or "sharing." We do not sell vault contents. Site analytics may involve disclosures to analytics providers as described above. For requests about information we hold through support or Site tools, email hello@zenproducts.ai with "California privacy request" in the subject. We will verify requests as required by law.
16. Your choices
- Edit or delete vault items, export encrypted backups, import data, or use in-App reset flows.
- Disable biometric unlock and manage Keychain entries through system settings if needed.
- Turn iCloud sync on or off subject to Apple account status and App behaviour.
- Cancel or manage Zen Premium in Apple's subscription settings.
- Limit Site analytics with browser or OS controls where available.
17. Changes
We may update this Policy. We will change the "Last updated" date and post the new version on the Site. For material changes, we may provide additional notice in the App or by other reasonable means where required. Continued use after the effective date means you accept the updated Policy where the law allows that approach.
18. Contact
Privacy inquiries: hello@zenproducts.ai
Suggested subject: Zen Passwords · Privacy
You may also use App Store "Contact developer" where available.