Legal
Privacy Policy
Last updated: July 2026
1. Introduction
This Privacy Policy explains how GBpass collects, uses, and protects the personal data of users accessing the Application globally.
2. Personal Data We Collect
GBpass is built with encryption that prevents us from viewing your data. This means we cannot access, view, or decrypt your vault data, master password, or stored credentials.
We may collect:
We do not collect:
The Application does not track users across apps or websites owned by other companies. No automated decision-making or profiling is performed on your personal data. Where consent is required by law, you may withdraw it at any time without affecting the validity of any processing done before the withdrawal.
3. Purpose of Data Use
We use personal data to:
Legal Basis for Processing (EU/EEA Users)
For users in the European Economic Area, personal data is processed based on one or more of the following:
4. Payments & Billing
All subscription payments are handled by the applicable app store (such as Google Play or Apple App Store). The Operator does not store or have access to payment card data.
5. Data Sharing & Disclosure
We do not sell, monetize, or use personal data for advertising. Data may only be shared with:
Encrypted vault data is never shared with third parties except as technically necessary to provide the Service.
6. Website Analytics
Our website (gbpass.net) measures aggregate visitor activity (pages viewed, the referring website, ad-campaign tags, approximate device type, and country) using our own web server. No third-party analytics service receives your visit data:
This processing is based on our legitimate interest in understanding overall website usage. Because it sets no cookies, accesses no information stored on your device, and shares nothing with third parties, it does not require a consent banner under GDPR or the ePrivacy Directive.
Our website is delivered through Cloudflare, our content-delivery and security provider, which processes network traffic (including IP addresses) to route and protect the site. See Cloudflare's Privacy Policy.
7. Data Retention
Personal data is kept only for as long as:
You may request deletion by contacting us via email. Encrypted vault data is permanently deleted when your account is deleted, subject to technical limitations. Support messages may be kept for a reasonable period to resolve inquiries and meet legal requirements. Where required by law, deletion requests will be completed within the legally required timeframe.
8. Your Rights
California (CCPA/CPRA)
Singapore (PDPA)
You may request access to or correction of your personal data.
United Kingdom & Australia
You have rights under applicable data protection laws, including access, correction, deletion, and data portability where applicable.
European Union (GDPR)
You have the right to access, correct, delete, restrict, and object to the processing of your personal data. You also have the right to file a complaint with a data protection authority.
All requests are handled via email.
9. Data Security
We use reasonable security measures, including encryption and access controls, to protect your personal data and stored credentials. However, no method of data transmission or storage is completely secure.
10. International Data Transfers
Data may be processed on servers located outside your country. Appropriate safeguards are applied to protect your data during any such transfer.
11. Policy Updates
This Privacy Policy may be updated from time to time. Continued use of the Application means you accept the updated policy. Where required by law, we will notify you of significant changes.
12. Contact
For privacy-related questions or data requests, contact us at: [email protected]