1. Who we are
PassKo is a 2FA authenticator and password/PIN vault published by SaaSKo. Website: https://passko.app. Android package: com.passko.saasko. Contact for any privacy request: support@passko.app.
2. Scope
This policy applies to the PassKo mobile app (Android now, iOS planned) and to this website. It does not cover third-party services you protect with PassKo — those services have their own policies.
3. Data we process
Account data
- Your Google account email and Google Sign-In tokens, if you sign in with Google.
- Your phone number, if you sign in with phone.
- An internal user ID that identifies your account.
- An optional birthdate you enter, used as an additional check when resetting your PassKo account password. It is not a replacement for your vault password.
- Your PassKo account password, stored in hashed form by our cloud authentication provider. It is never shown, entered or stored on this website.
App and device data
- App settings such as language, notification toggle and whether Passkey/app lock is enabled.
- Purchase and entitlement status from Google Play and RevenueCat — whether a subscription is active. We never receive full card numbers.
Vault contents
2FA secrets, passwords, PINs, labels and related history are created by you. They are encrypted on your device and stored locally. We never ask you to paste vault secrets into this website, and vault contents are never used for advertising.
Backup files
A backup file exists only when you export one. You choose where it is saved, and it stays under your control.
Support emails
Whatever you send to support@passko.app, including your email address and the content of your message.
Website
This website uses no Google Analytics, no advertising pixels, no Facebook pixel and no tracking cookies. Our hosting provider keeps standard technical logs (IP address, user agent, timestamp) for security and operations, retained for a short period.
4. Android permissions and why we ask
- Internet: sign-in, checking subscription status, and opening these policy pages.
- Camera: only to scan 2FA QR codes. Camera frames are processed on the device and are not uploaded.
- Biometric / credential: to unlock the app and confirm edits. Biometric templates stay on your device — we never receive fingerprint or face images.
- Notifications (optional): local reminders if you enable them; you can turn them off in Settings.
- Files / storage access: only for import and export of backup files that you start yourself.
5. Third parties
- Google — Google Sign-In, Google Play Billing and Play services.
- Our cloud authentication provider — creating and verifying your account.
- RevenueCat — subscription entitlement management. Payments themselves are processed by Google Play (and later Apple); RevenueCat does not receive full card data from us.
- Our website host — serving this website.
We do not sell personal information and we do not share vault contents with anyone.
6. Why we are allowed to process this data
To provide the service you asked for, to keep accounts secure, to meet legal obligations, and for the legitimate operation of PassKo (for example fixing bugs and preventing abuse).
7. How long we keep it
- Account data: until you request deletion, or after prolonged inactivity, plus any period required by law.
- Vault data: on your device until you delete entries or uninstall the app. Uninstalling may erase the local vault permanently.
- Backup files: for as long as you keep them — they are under your control.
- Support emails: as long as needed to resolve your request and keep a basic record of it.
8. Deleting your account
Email support@passko.app with the subject “Delete my PassKo account”, sent from the same email address or phone number you used to sign in. We will delete or anonymise your account data within 30 days unless the law requires us to keep it longer. Your local vault is removed by deleting vault items or uninstalling the app. Purchase records are held by Google or Apple and may remain in their store records.
9. Children
PassKo is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will remove it.
10. International users
Your data may be processed in the regions where our providers operate, which may be outside your country. We rely on those providers' contractual and technical safeguards.
11. Security
Vault data is encrypted in the app before local storage, this website is served over HTTPS, and access to account systems is limited. No method of storage or transmission is perfect. Please use a strong PassKo password, enable app lock, and protect any backup files you export.
12. Your rights
You can ask for access, correction, deletion, or object to certain processing by emailing support@passko.app. Users in the EU, UK and other regions with similar laws can use the same address, and we handle those requests the same way.
13. Changes to this policy
If this policy changes, we update this page and the “Last updated” date at the top. Significant changes may also be announced in the app.
14. Google Play Data safety summary
In reviewer-friendly terms, PassKo relates to these data types:
- Account info — email or phone number, optional birthdate for account reset.
- User IDs — internal account identifier and auth identifiers.
- App activity / settings — language, notification and app-lock preferences.
- Purchase history — subscription entitlement status only.
- Photos / videos — camera frames are processed on the device to read a 2FA QR code and are never uploaded or stored.
- Files — only backup files you choose to import or export.
- Audio, Location, Contacts, SMS — none collected.
Vault contents (2FA secrets, passwords, PINs) are encrypted on the device and are not collected by us.
15. Contact
PassKo by SaaSKo — support@passko.app