We cannot seeyour data.
Last updated: 30 August 2026
This policy is unusually short on disclosures, because EverLatch is built so that there is almost nothing to disclose. Everything below is a consequence of one decision: no servers.
01
The short version
EverLatch has no servers, no accounts and no cloud. Your vault is one encrypted file on your own device. We do not receive it, cannot read it, and hold no copy of it.
- We collect nothing from the apps. No account, no email, no telemetry, no analytics, no crash reporting, no advertising identifiers.
- One network feature exists, and only if you press it: the known-leaks check, described in clause 06.
- This website sets no cookies and makes no third-party requests.
- We never sell or share your data, because we never have it.
The clauses below spell all of that out in full, including the few places where a third party unavoidably sees something.
02
Who we are
EverLatch is made and published by HelperAn, a business registered in India (Udyam registration UDYAM-PB-12-0260075).
Where data-protection law calls for a controller or a data fiduciary, that is HelperAn. In practice the role is close to empty: the design of the product means almost no personal data ever reaches us.
For any privacy question, correction or complaint, write to info@everlatch.app. The same address serves as our grievance contact under the Indian Digital Personal Data Protection Act, 2023.
03
What EverLatch stores, and where
Everything you put into EverLatch stays on the device you put it into. That includes:
- passwords, usernames, URLs and custom fields
- passkeys and TOTP two-factor secrets
- payment cards, bank details and identities
- secure notes, links, files and attachments
- your settings, folders, favourites, edit history and the contents of the trash
It is held in a single SQLCipher database on your device. The encryption key is derived from your master password with Argon2id, and sensitive fields carry a further layer of XChaCha20-Poly1305 encryption via libsodium.
We hold no copy of this file, no copy of your master password, and no key that could open it. There is no server-side backup and no recovery path through us — by design, and there is no way for us to add one without breaking the guarantee.
04
What we collect about you
From the Windows app, the Android app and the browser extension: nothing. Specifically, none of the following exist in EverLatch:
- user accounts, sign-up, sign-in or email collection
- usage analytics, product telemetry or event tracking
- automatic crash or diagnostic reporting
- advertising, ad identifiers, profiling or cross-app tracking
- fingerprinting of your device or network
- any sale, rental or sharing of personal data with anyone
We do not build a profile of you, because we receive nothing to build one from.
05
Sync between your own devices
When you pair two of your devices, they exchange vault data directly with each other over your own local network. Devices find each other using mDNS on that network, you confirm the pairing once by scanning a QR code, and the transfer is end-to-end encrypted.
No server sits in the middle, because there is none. Nothing is relayed, staged or backed up anywhere along the way. If your devices are not on the same network, they simply do not sync.
Other devices on your local network can see that an EverLatch instance is present — that is how mDNS discovery works — but they cannot read the contents of a sync or join one without completing the QR pairing.
06
The opt-in known-leaks check
This is the only feature in EverLatch that makes an outbound internet request, and it runs only when you press its button. It is never automatic, never scheduled, and off until you use it.
When you run it, for each password checked:
- a SHA-1 hash of the password is computed on your device
- only the first five characters of that hash are sent to a public breach-data service
- the service returns the full range of hashes sharing that prefix
- the comparison happens on your device
Your password never leaves the device. Neither does its full hash. The service that answers the query cannot tell which password you were asking about, or even whether any of them matched. This technique is called k-anonymity.
That service is operated by a third party and will see the network request itself, including your IP address, as any web request would. If you would rather it never happen at all, do not press the button.
07
The browser extension
The extension reads page content — login forms and their fields — in order to fill credentials and to offer to save new ones. That reading happens locally, inside your browser.
Anything it reads or captures is passed only to the EverLatch app on the same machine, over the browser native-messaging channel. It is never sent to a server. The extension has no analytics and makes no network requests of its own.
EverLatch complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data obtained through the extension is used only to provide the fill-and-save features you asked for, and is never transferred, sold, or used for advertising or profiling.
08
Permissions the apps ask for
Each permission exists for one feature, and is used for nothing else.
Android
- Autofill service — to offer credentials in other apps and browsers when you ask for them.
- Credential Manager provider — to supply and create passkeys.
- Camera — to scan QR codes for device pairing and for importing TOTP secrets. No image is stored or transmitted.
- Biometric / device credential — to unlock the vault. Your fingerprint or face never leaves the operating system, and EverLatch only ever receives a yes or no.
- Local network access — to discover and sync with your other devices.
- File access — only for files you explicitly attach, import or export.
Windows
- Windows Hello and TPM — to unlock the vault and to act as a system passkey provider.
- Local network access — to discover and sync with your other devices.
- Global hotkey and input simulation — for auto-type into other applications, on your keypress.
09
This website
everlatch.app is a static site. It sets no cookies, runs no analytics, and makes no third-party requests — fonts and scripts are served from this domain, so loading a page contacts nobody but this site.
The site is hosted on GitHub Pages. Like any web host, the hosting provider processes the technical request data needed to deliver a page — your IP address, browser user agent, and the page requested — and may retain it briefly for security and abuse prevention. We do not receive, query, or store those logs.
Under the GDPR, our legal basis for that limited processing is legitimate interest (Article 6(1)(f)) in serving and protecting the website.
10
If you contact us
If you email us, we receive what you send: your email address, your message, and anything you attach. We use it only to answer you.
Please never send us your master password, a vault file, a backup, or the contents of an entry. We do not need any of it to help you, and we do not want to hold it.
Correspondence is kept only as long as it is useful for handling your request and any follow-up, and is deleted after that. Legal basis under the GDPR: legitimate interest, or performance of a contract where your message concerns the software you use.
11
App stores and distribution
If you install EverLatch from an app store or extension gallery, that platform is a separate company with its own privacy policy. It will know that you downloaded the app, and may collect installation, device, purchase and crash information under its own terms.
That happens between you and the platform. We do not control it, and the aggregate figures a store shows us tell us nothing about any individual person.
Installing from a direct download instead avoids that entirely, except for the ordinary web-server logs described in clause 09.
12
Children
EverLatch is a general-purpose security tool and is not directed at children. We do not knowingly collect personal data from anyone, children included — there is no mechanism in the product that could.
Where local law requires verifiable parental consent for a child to use software of this kind, that consent is the responsibility of the parent or guardian who installs it.
13
Retention and deletion
Because your vault lives only on your devices, you delete it the same way you delete any other file:
- uninstall the app, or delete the vault file directly
- delete any encrypted backups you exported
- unpair or wipe any other device you synced to, since each holds its own full copy
Once those are gone, the data is gone. There is nothing to request deletion of from us, because we were never sent anything to delete. The only exception is email correspondence, which you can ask us to erase at any time.
14
How it is protected, and the limits
EverLatch uses established, published cryptography rather than anything invented for it: Argon2id for key derivation, SQLCipher for the database, and XChaCha20-Poly1305 via libsodium for field-level encryption. The vault auto-locks when idle, and the clipboard clears itself after copying.
Being honest about what that does not cover:
- A weak master password is the weakest link. Argon2id makes guessing expensive, not impossible.
- If your device is compromised — malware, a keylogger, someone with your unlocked screen — the protection at rest cannot help you.
- Anyone holding both your master password and a copy of your vault file can open it, wherever they got it.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to info@everlatch.app rather than disclosing it publicly, and we will work with you on it.
15
Your rights
Under the GDPR, the Indian Digital Personal Data Protection Act, 2023, and comparable laws elsewhere, you have rights to access, correct, erase, restrict, object to, and port your personal data.
For your vault, those rights are already satisfied by the design: the data is in your hands, in a file you control, and you can read, change, export or destroy it without asking anyone. We could not action such a request even if you made one, because we hold nothing.
For the only personal data we may ever hold — an email you chose to send us — write to info@everlatch.app and we will act on it. You also have the right to complain to your local data protection authority, or in India to the Data Protection Board.
16
International transfers
Your vault never crosses a border because it never leaves your device.
HelperAn operates from India, so an email you send us is read there. The website is served from the hosting provider global edge network, which means the page itself may be delivered from a server near you. Neither involves transferring anything you stored in EverLatch.
17
Changes to this policy
If this policy changes, the updated version is posted on this page with a new date at the top. We will not quietly reduce the protections described here.
If a future change ever meant EverLatch started collecting something it does not collect today, that would be announced clearly in the app and in the release notes — not buried in a policy update.
18
Contact
HelperAn, India — Udyam registration UDYAM-PB-12-0260075.
Privacy, data protection and grievance contact: info@everlatch.app
We aim to answer any privacy request within 30 days, and sooner where the law requires it.