← Back to PassMentor

Privacy Policy

Effective date: June 28, 2026

What PassMentor is

PassMentor is a credential management service operated for a defined set of affiliated organisations — currently Stella Maris Safe, Coal City Vault, MyStar Technologies, Naija Kids Vault, Patemax Building, Patemax Vault, Pepper Gril Vault, Stella Maris Maintenance, and Xandria Vault. Wherever this policy refers to "your organisation," it means whichever of these you are a member of. This policy explains what information we collect, how it's used, and the zero-knowledge design that prevents us from reading the credentials you store.

What we collect

  • Account information: your name and email address, set by your organisation's administrator.
  • Encrypted credential data: the passwords, keys, and other secrets you store, encrypted on your own device before it ever reaches our servers. We do not have the ability to decrypt this content — see "Zero-knowledge design" below.
  • Audit/security records: login times, IP addresses, browser/device user-agent strings, and a record of actions taken (e.g. "credential created," "member role changed") — kept for security and compliance purposes.
  • Biometric unlock data: if you enable Face ID, Touch ID, or fingerprint unlock, the biometric data itself never leaves your device and is never transmitted to or stored by us — your device's operating system handles this entirely on-device.
  • Two-factor authentication secrets: if you enable TOTP-based 2FA, the shared secret is encrypted at rest on our servers.

Zero-knowledge design

Your master password is never sent to or stored by our servers. It's used on your own device to derive an encryption key that locks and unlocks your stored credentials locally. We store only the already-encrypted result. This means PassMentor has no technical ability to read your credential contents, including in response to a request from your organisation, a government, or anyone else — we simply don't hold the key.

How we use this information

To operate the service: authenticating you, enforcing your organisation's access controls, detecting and investigating suspicious activity, and maintaining the audit trail your organisation's administrators rely on for security and compliance. We do not sell personal information, and we do not use it for advertising. We do not share it with third parties except infrastructure providers strictly necessary to run the service (e.g. hosting), under confidentiality obligations.

Data retention

Audit/security records are retained for as long as your organisation maintains its account, for legitimate security and compliance purposes, even after an individual account is deleted (see below). Encrypted credential data is retained until deleted by you or your organisation's administrator.

Deleting your account

You can delete your own account at any time from Settings → Danger zone on the website, or Profile → Security → Delete account in the mobile app. This deactivates your account and erases your name, email, and all personal encryption material (your vault key, passkeys, and two-factor secret) from our records immediately. As noted above, security audit records referencing your prior activity are retained for legitimate business and security purposes, consistent with this policy. If you are the only Org Owner of your organisation, you'll be asked to promote another member first, so the organisation's vault isn't left without an owner.

Children's privacy

PassMentor is a business tool intended for use by adult members of affiliated organisations. It is not directed at, and we do not knowingly collect information from, children.

Changes to this policy

If this policy changes materially, we'll update the effective date above and, where appropriate, notify your organisation's administrators.

Contact

Questions about this policy or your data can be directed to your organisation's administrator, who can escalate to the PassMentor team on your behalf.