PassSumo
Privacy Policy
Overview
PassSumo is a native macOS app that reads and writes password vaults entirely on your Mac. It does not collect, transmit, or store any of your data outside your own machine. There is no analytics, no telemetry, no crash reporting, and no user account of any kind.
What PassSumo collects
Nothing.
There is no analytics, no telemetry, no crash reporting, no advertising, no third-party SDK, and no account. Your vault and everything in it never leave your Mac — not to the developer, not to anyone.
The app makes network requests for exactly one purpose: Apple's own purchase infrastructure. StoreKit contacts Apple to load the subscription options, complete a purchase, restore an earlier one, and learn when a subscription renews or ends. That exchange is between your Mac and Apple, it carries nothing from your vault, and the developer never receives your payment details. There is no other server in the picture, because there is no other server.
Your vault
Your passwords live in a single .kdbx file, in the standard KDBX format, at a
location you choose — in iCloud Drive, or on local disk. PassSumo does not pick that
location for you and does not run a sync service of its own; whatever already moves that
file between your machines (iCloud Drive, or nothing at all) is what moves it. The vault's
contents are encrypted under a key derived from your master password, using the encryption
the KDBX format itself specifies (AES-256 or ChaCha20 under an Argon2-derived key) — the
same protection any compliant KDBX reader or writer applies.
PassSumo runs inside Apple's App Sandbox, so the vault file you open or create — the one you explicitly picked through the standard macOS file chooser — is the only place outside its own container it can read or write at all.
Touch ID unlock
Touch ID unlock is optional and off until you turn it on. Enrolling it stores your master credential in the macOS Keychain, protected behind Touch ID through Apple's own LocalAuthentication framework. Your fingerprint itself is never available to PassSumo, or to any app — it is handled entirely by Apple's Secure Enclave. PassSumo only ever receives a yes-or-no answer from the system.
Backups
Before saving over an existing vault, PassSumo keeps a backup copy inside its own app container — never as a file next to your vault. Backups stay on your Mac, and are never uploaded anywhere.
Subscription
Editing your vault requires an auto-renewable subscription after the free month, purchased through Apple's App Store. All billing, payment collection and subscription management is handled entirely by Apple under Apple's own Privacy Policy — the developer never receives or has access to your card, your billing address, or your Apple ID. What the developer does receive is Apple's ordinary sales reporting: aggregate counts of purchases and refunds by country, which identify nobody. Manage or cancel the subscription any time in your Apple ID account settings.
Reading your vault does not depend on the subscription, so letting it lapse does not lock you out of your own passwords — see the Terms of Use.
This website
This site is static HTML with no cookies, no analytics, and no tracking scripts of any kind. The one page that sends anything anywhere is the feedback form, and it sends what you type into it — your message, an email address if you chose to leave one, and which app the message is about. That submission is handled by the site's hosting provider, which forwards it through a third-party messaging service to a private chat the developer reads; the message, the optional email address, and the app name all sit with that third party. Messages stay in that chat until deleted by hand — nothing removes them automatically. None of it is used for anything other than replying to you.
Like any hosted site, the provider's infrastructure may log standard web-server data (such as IP addresses) as part of normal operation, independently of PassSumo and of anything you do in the app. Providers are described here by what they are rather than by name, so that changing one is a deployment change and not a rewrite of this page.
Requesting deletion, or withdrawing consent
There is nothing collected here to delete or to withdraw consent for — PassSumo doesn't hold anything about you on any server. If that ever changes, or if you have a question about it, the feedback form is the one route to reach the developer, and any such request is handled there.
Who is responsible
PassSumo is made and operated by an independent individual developer, not a company. The feedback form is the way to reach them.
Children
PassSumo is not directed at children, and the feedback form is not intended for use by them.
Changes to this policy
If this policy changes, the update is posted here with a new "Last updated" date above.
Contact
Questions about this policy: the feedback form.