No cloud account for the vault
Storing your vault needs no central account that holds your secrets.
Privacy does not begin with a promise in an advertisement. It begins with architecture. BlindLock creates no cloud vault and has no access to your vault contents.
Storing your vault needs no central account that holds your secrets.
BlindLock transmits no vault contents to our servers and does not analyse them.
Your secrets stay on your device, inside an image file (PNG) or a vault file.
Activation and every new unlock need a brief encrypted licence and version check. Wallet features, once you switch them on yourself, additionally talk to vetted blockchain nodes. No vault contents travel with either of them.
Many password managers cannot read your data, and yet they still keep encrypted vaults on their servers. BlindLock removes that central collection point for customer vaults.
Privacy comes from what a piece of software never collects in the first place, not from a privacy policy. Storing your vault needs no BlindLock cloud account. Purchase and licensing do process an email address along with licence, device, platform, version and technically necessary connection data. Those technical records stay strictly separate from your vault contents.
Passwords, TOTP secrets and secure notes sit fully encrypted inside an ordinary-looking PNG carrier file. Larger files stay separate, in encrypted and disguised file vaults. Access is additionally bound to the protected hardware of your device — TPM 2.0, Secure Enclave or StrongBox, depending on the platform.
Honesty belongs to real privacy, so here are the clearly limited network connections:
Picture a cloud password service reporting a break-in on its servers. Even if the vaults stored there were encrypted, they are now in someone else's hands and can be attacked at leisure. With BlindLock that central store does not exist. An attacker would have to find your carrier file and then defeat both your master password and the hardware anchor. That is no guarantee against every attack, but it does make mass theft of customer vaults considerably harder.
No. You set the vault up locally. Purchase and licensing process your email address, but no cloud account holding your vault contents is created.
No. There is no telemetry of vault contents, no analytics scripts and no hidden tracking. Online connections serve the licence and version check, plus wallet network features you switched on yourself.
Yes. BlindLock operates no central vault database and transmits no vault contents to its servers. Data leaves your device only through actions you take yourself.