Privacy

Privacy by architecture

Privacy does not begin with a promise in an advertisement. It begins with architecture. BlindLock creates no cloud vault and has no access to your vault contents.

No cloud account for the vault

Storing your vault needs no central account that holds your secrets.

No analysis of your vault

BlindLock transmits no vault contents to our servers and does not analyse them.

Local vault

Your secrets stay on your device, inside an image file (PNG) or a vault file.

What is transmitted anyway

Activation and every new unlock need a brief encrypted licence and version check. Wallet features, once you switch them on yourself, additionally talk to vetted blockchain nodes. No vault contents travel with either of them.

Why this matters

Many password managers cannot read your data, and yet they still keep encrypted vaults on their servers. BlindLock removes that central collection point for customer vaults.

Data minimisation as a principle

Privacy comes from what a piece of software never collects in the first place, not from a privacy policy. Storing your vault needs no BlindLock cloud account. Purchase and licensing do process an email address along with licence, device, platform, version and technically necessary connection data. Those technical records stay strictly separate from your vault contents.

Passwords, TOTP secrets and secure notes sit fully encrypted inside an ordinary-looking PNG carrier file. Larger files stay separate, in encrypted and disguised file vaults. Access is additionally bound to the protected hardware of your device — TPM 2.0, Secure Enclave or StrongBox, depending on the platform.

What BlindLock sends and what it does not

Honesty belongs to real privacy, so here are the clearly limited network connections:

  • Activation and every new unlock need a brief encrypted connection for a licence and version check. Technical licence, device, platform and version information is processed along the way.
  • Wallet network features, once explicitly switched on, can exchange public addresses, balance queries, signed transactions and their status with vetted blockchain nodes.
  • BlindLock transmits no passwords, notes, 2FA secrets, private keys or files to our servers.
  • BlindLock operates no central vault database. That is why we can neither look inside your vault nor hand it over on request.

Who BlindLock suits

  • People who deliberately want no cloud copy of their credentials.
  • Anyone working with particularly sensitive material: credentials, private documents, confidential notes.
  • Everyone who would rather own a one-time lifetime licence than run yet another subscription account with a provider.

Who it suits less

  • Anyone expecting automatic sync across many devices without ever securing a file themselves will not find that here.
  • Anyone looking for comfort features such as shared family vaults in the cloud is better served by a classic provider.
  • Anyone unwilling to take responsibility for their own recovery phrase. Without it, losing both the device and the security key leaves no way back.

An everyday example

Picture a cloud password service reporting a break-in on its servers. Even if the vaults stored there were encrypted, they are now in someone else's hands and can be attacked at leisure. With BlindLock that central store does not exist. An attacker would have to find your carrier file and then defeat both your master password and the hardware anchor. That is no guarantee against every attack, but it does make mass theft of customer vaults considerably harder.

Common questions about privacy

Do I need a cloud account for my vault?

No. You set the vault up locally. Purchase and licensing process your email address, but no cloud account holding your vault contents is created.

Does BlindLock collect usage data or statistics?

No. There is no telemetry of vault contents, no analytics scripts and no hidden tracking. Online connections serve the licence and version check, plus wallet network features you switched on yourself.

Does my data stay entirely in my hands?

Yes. BlindLock operates no central vault database and transmits no vault contents to its servers. Data leaves your device only through actions you take yourself.

What BlindLock does not claim: privacy at the architecture level does not replace your own care. A compromised operating system, an insecure device or a badly stored recovery phrase remain risks that no software takes off your hands entirely.