Skip to content
LostPass

LOSTPASS / Privacy

Where your data lives

Personal storage, transfers and Commerce use different storage models.

Personal vault

Personal entries are stored on your computer. Working with your personal database does not require the internet. You control exports, backups and deletion of local data.

Code-based transfer

The server temporarily holds the transfer package in memory. It is deleted after collection, cancellation or expiry. The service processes IP addresses and technical request information to operate.

Password checks

Pwned Passwords checks are off by default and can be enabled in security settings. The app computes SHA-1 locally and sends only the first 5 hash characters to api.pwnedpasswords.com. The service sees this prefix, your IP address and LostPass version; the full password and hash are not sent. A separate Have I Been Pwned email check requires your own API key and sends the email address being checked.

Company workspace

Commerce sends data to your organization’s server. Your organization defines access, backup and retention policies. The server decrypts entries during use.

Contact

The contact link opens your email application. This website does not accept passwords or vault files. Do not include secrets in your message.

Website analytics

Optional analytics may be enabled by the website operator. The current status is shown below.

Google Analytics is enabled on this website.

The team’s contact details will be published here.