Privacy Policy
Last updated: October 2026
The short version: MSafe makes no network connections - on Android it isn't even granted permission to, and on iOS it ships with no networking code at all. There are no servers to breach, no accounts, no analytics, and no tracking. Your vault never leaves your phone unless you explicitly export it.
Data Collection
MSafe collects no data. Specifically, there is:
- No personal information collection
- No analytics, telemetry, or usage tracking
- No crash reports or diagnostics sent to the developer
- No advertising identifiers or ad SDKs
- No cookies, fingerprinting, or any other tracking mechanism
- No account creation, email collection, or phone verification
Network Access
On Android, MSafe is built without the internet permission, so the operating system refuses to let the app make any network connection at all. On iOS, MSafe contains no networking code whatsoever and links no analytics, advertising, or sync SDKs - it never opens a connection. On neither platform can it phone home, sync to a cloud, fetch updates, or contact any server.
How Your Vault Is Stored
Your credentials are stored on your device, encrypted with AES-256 using a key derived from your master password. The master password itself is never saved in plain text.
If someone gets hold of your phone's storage without your master password, the vault contents are unreadable.
On Android, you can attach a TOTP authenticator to a credential. Its setup secret is encrypted with the credential and included in encrypted exports. Codes are generated on your phone using its clock, with no network connection.
On Android 14 and later, and on iOS 17 and later, MSafe can create and keep passkeys for websites and apps. A passkey's private key is encrypted with its credential like any other secret, and it never leaves the vault in readable form. Signing in with a passkey happens on your phone: MSafe signs the site's challenge and hands the answer back to the browser or app that asked. MSafe itself never contacts the site.
Authentication and Wipe
MSafe authenticates you with your master password. By default, after ten consecutive incorrect attempts the entire vault is wiped from the device; you can turn this off in Settings if you prefer. There is no recovery email, no "forgot password" link, no back door. This is a deliberate trade-off: the strongest guarantee that nobody else gets in is the same guarantee that you are responsible for remembering your master password.
Optional biometric unlock - fingerprint on Android, Face ID or Touch ID on iOS - is gated by the platform's secure hardware (the Android Keystore, or the iOS Secure Enclave / Keychain) and requires your biometric every time. The stored payload is bound to your current enrolled biometrics, so re-enrolling a fingerprint or face invalidates it. On Android 11 and later you can choose to also accept your phone's screen lock (PIN, pattern or password). The same secure hardware checks it, every time, and anyone who knows it can then open MSafe, so it is off unless you turn it on. Your master password is never saved to the device in readable form when biometric unlock is on - it stays in secure storage gated behind your biometric, or in memory only while the app is open.
Backups and Exports
MSafe never backs up your vault automatically. You decide when and where a backup lives. The app supports three explicit, user-initiated export formats:
- QR-code PDF - a single credential or your full vault as scannable encrypted QR codes you can print
- NFC tag - write a credential to an NFC tag and tap your phone against it later to import
- Encrypted
.msafefile - the vault as an encrypted file you can move between devices
All exports are encrypted the same way as your live vault, and the encrypted format is identical across platforms - an export made on Android imports on iPhone and vice versa, as long as you use the same master password. Anyone who picks up an exported QR or file still needs your master password to read it. MSafe is also kept out of automatic cloud backup - excluded from Android's auto backup to Google, and stored in an iOS location not copied to iCloud - so nothing is uploaded in the background.
Passkeys are included in all three export formats, encrypted like the rest of the vault. Anyone with an export and your master password can sign in with those passkeys, so keep exports as safe as the vault itself. A passkey made on Android signs in on iPhone and the other way round. Older MSafe versions without passkey support do not keep passkeys when importing and re-exporting credentials, so keep your original backup.
Authenticator data is supported by Android 4.88 and later. iOS and older Android versions do not preserve it when importing and re-exporting credentials. Keep the original Android backup if you move these credentials through an app without authenticator support.
Permissions
MSafe declares only the permissions it needs to do its job, and each one is scoped to an explicit user action:
- Camera - only when you scan a QR code to import a credential or set up an authenticator on Android
- NFC - only when you read or write an NFC tag (more limited on iPhone, where tag reads are always tap-initiated)
- Biometric - only if you turn on biometric unlock; fingerprint via Android, Face ID / Touch ID via iOS, managed entirely by the operating system
- Autofill - only if you enable MSafe as your provider in Android autofill settings, or as a Password AutoFill provider in iOS Settings
- Passkeys and passwords - only if you turn on MSafe in Android's passwords and passkeys settings (Android 14 and later), or as a Password AutoFill provider in iOS Settings (passkeys need iOS 17 and later). Apps and browsers then ask MSafe for passkeys and passwords through the operating system, and MSafe asks for your biometric or master password every time
On Android, MSafe does not declare the Internet permission, so the app cannot make any network connection even if it wanted to. On iOS there is no internet-permission concept, but MSafe ships with no networking code, so it never connects either way.
These permissions are managed by the operating system. You can revoke them at any time in System Settings (Android: Apps > MSafe > Permissions; iOS: Settings > MSafe).
Third-Party Services
MSafe does not connect to any third-party services. There is no analytics, no crash reporting, no advertising, and no tracking. QR scanning is fully on-device (the open-source ZXing decoder with CameraX on Android, AVFoundation on iOS); no camera frames or decoded barcode data ever leave your phone, and nothing is sent to Google, Apple, or any other server.
On Android, to know which browsers it can trust to say which website is asking for a passkey, MSafe ships with a fixed list of known browsers and their signing certificates. The list is part of the app and is only updated with app updates; MSafe never downloads it. On iPhone, iOS itself checks which app or website is asking, so no such list is needed. To show your passkeys in its sign-in sheet, iOS keeps a list of each passkey's website and user name; the passkey itself stays in your vault.
Editions and Pricing
Android comes in a free edition and a Pro edition; they have identical privacy guarantees and differ only in the credential cap. Pro is a one-time Google Play purchase processed by Google.
iOS is a single paid app with no free tier and no credential cap, purchased once on the App Store and processed by Apple. There is no subscription and no in-app purchase.
codfishworks does not see your payment information on either platform.
Children's Privacy
MSafe does not knowingly collect any data from anyone, including children under 13. Since no data is collected or transmitted, there are no COPPA concerns.
Changes to This Policy
If this privacy policy changes, the updated version will be published on this page with a new "Last updated" date. Since MSafe collects no data and cannot connect to the internet, significant policy changes are unlikely.
Contact
If you have questions about this privacy policy, reach out via email at msafeworks@gmail.com.