Privacy Policy
We follow the principles of “end-to-end encrypted, zero knowledge, minimal collection”: your passwords, secret notes and encrypted images are encrypted on your device, and only ciphertext is ever synced to the cloud — we cannot read your plaintext.
1. Introduction and Scope
Micro Zero Vault (wljpassmgr, “we”, “us” or “our”) is an end-to-end encrypted password management service that helps you securely store, organize, retrieve and manage passwords, secret notes and encrypted images, with optional encrypted cross-device sync.
This Privacy Policy (the “Policy”) explains how we handle information when you use Micro Zero Vault products and services, the security measures we take, and the rights you have.
This Policy applies to the Micro Zero Vault apps (iOS / Android / desktop), browser extension, official website and related services we operate.
2. Information We Collect
1. Your data is encrypted by you — our servers only ever see ciphertext. Your vault, secret notes, encrypted images and other core data are encrypted locally on your device. Even when you enable cross-device sync, only ciphertext is uploaded to and stored on our servers; we technically cannot read your plaintext.
2. Account information (only when you actively use it). Only when you choose to register an account and enable cross-device sync do we process the minimum information required to provide that feature, such as a registration email or username and the security credentials used for authentication (never your plaintext master password).
3. Necessary service information. When you use features that require network access (such as sync or update checks), we may process limited technical information such as device model, OS version and network status, solely to keep the service running securely.
4. What we explicitly do not collect. We do not collect your browsing history, web page contents or ad-click behavior, we do not build behavioral profiles, and we do not serve behaviorally targeted advertising.
3. Data Storage and Encryption
1. Encrypted at rest. All sensitive data is encrypted with AES-256 before being written to storage. On mobile, key material is kept in the system secure storage (SecureStorage / Keychain); on desktop and browser, equivalent local secure-storage mechanisms are used.
2. Key separation. We use an architecture that separates data-encryption keys from authentication keys. Your master password is used only to derive keys locally on your device; it never leaves your device and is never uploaded.
3. Zero-knowledge architecture. Data synced to our servers is always ciphertext. Encryption and decryption happen only on your devices, and the keys required for decryption are held exclusively by you: our servers merely host ciphertext and, by design, have no capability to recover your plaintext. Key material is also kept in encrypted form at all times.
4. Biometrics stay on-device. Fingerprint and face recognition are performed locally through your device's built-in security capabilities. Biometric data never leaves your device and is not accessible to us.
4. Sharing and Disclosure of Information
1. No sharing by default. We do not sell, rent, or share your personal information with any third party for marketing or other purposes. We do not integrate advertising SDKs, and we do not provide your personal data to data-analytics companies.
2. Limited exceptions. We may disclose necessary information only in the following circumstances: (a) with your explicit consent; (b) where required by applicable laws, regulations or binding orders from judicial or administrative authorities; or (c) where necessary in an emergency to protect your or another person's life or property.
3. Business transitions. In the event of a merger, acquisition or reorganization, we will require the receiving party to continue to honor this Policy, or seek your consent before transferring data.
5. Data Transmission and Security Measures
1. Encrypted in transit, end-to-end protected. We communicate over encrypted channels (HTTPS/TLS). Sensitive data is end-to-end encrypted before it leaves your device; the cloud stores only ciphertext, and the decryption keys remain exclusively in your hands.
2. Least-privilege design. We request only the permissions necessary for core features — no unnecessary system access, no silent background reporting.
3. Security engineering practices. We employ auto-lock, configurable session timeouts, log redaction in production, code obfuscation and a security-aware development process to continuously reduce exposure.
4. Incident response. If an event occurs that may affect the security of your data, we will notify you and the relevant authorities in a timely manner as required by applicable law.
6. Your Rights and Choices
1. Access and correction. You can view and edit your vault contents and profile information at any time within the app.
2. Export. We provide data export capabilities so you can take your data with you in a readable format at any time. Your data sovereignty is always yours.
3. Deletion and account closure. You can delete local data or close your account. Upon closure, we will delete or anonymize personal information associated with your account, except where otherwise required by law.
4. Withdrawing consent and complaints. You may withdraw any authorization you have granted at any time and file a complaint with us or the competent regulatory authority.
5. Response time. We process requests in accordance with applicable law (including, without limitation, the PRC Personal Information Protection Law and the GDPR), and typically respond within 15 business days of receiving a request.
7. Cookies and Local Storage Technologies
1. Official website. Our official website does not use tracking cookies and does not integrate third-party ad tracking. Where local preferences are used, they rely on browser local storage only, and the data never leaves your browser.
2. Client apps. Micro Zero Vault stores encrypted data and preferences in your device's local secure storage (e.g. IndexedDB, SecureStorage, Keychain). You control this data and can clear it at any time.
3. Your choice. You may clear local data on your device at any time. Please make sure you have a proper backup first: under our zero-knowledge architecture, we cannot recover it for you.
8. Children's Privacy
We take the protection of children's personal information very seriously. Our services are intended for the general public, and we do not knowingly collect personal information from children under the age of 14.
If you are under 14, please read this Policy with your parent or guardian, and use our services only after obtaining their consent.
If we learn that we have collected a child's personal information without verifiable parental consent, we will delete the relevant data as soon as possible.
9. Updates to This Policy
We may revise this Policy from time to time. For material changes, we will notify you in advance through reasonable means such as in-app announcements or notices on our website, and publish the updated version and effective date on this page.
The revised Policy takes effect upon publication. Your continued use of our services after the Policy is updated constitutes acceptance of the updated Policy.
10. Contact Us
Terms of Service
These Terms set out the agreement between you and Micro Zero Vault regarding your use of the Service. Please read them carefully before use, especially the clauses concerning security responsibility, disclaimers and limitation of liability.
1. Acceptance and Scope of These Terms
By starting to use any product, service or feature of Micro Zero Vault (wljpassmgr, “we”, “us”, “our” or “the Service”), you acknowledge that you have read, understood and agree to be bound by these Terms of Service (the “Terms”).
These Terms apply to the Micro Zero Vault apps (iOS / Android / desktop), browser extension, official website and related services. If you do not agree to these Terms, please stop using the Service.
2. Description of the Service
The Service provides end-to-end encrypted password, secret-note and image management, together with optional features you actively enable such as encrypted cross-device sync, autofill and biometric unlock.
The Service follows a zero-knowledge architecture: your master password is yours alone and is used to protect your data locally on your device.
We may adjust, optimize or retire features as the product evolves, and will notify you through reasonable means such as in-app announcements.
3. Account Security and Your Responsibilities
1. Your master password. The master password is the only credential that unlocks your encrypted data. You set it and you are responsible for keeping it safe. Under our zero-knowledge architecture, we cannot view, reset or recover your master password. If it is lost, your data cannot be recovered.
2. Your security obligations. Please safeguard your master password, login credentials and devices, avoid signing in on untrusted devices, and enable security features such as auto-lock and biometric unlock. To the extent permitted by law, you are responsible for loss or disclosure caused by your own failure to safeguard them.
3. Account information. You must keep your registration information truthful and accurate, and you are responsible for all activity that occurs under your account.
4. Acceptable Use
You agree to comply with all applicable laws and regulations while using the Service, and agree not to:
- Use the Service to store or transmit content that violates applicable laws or infringes the rights of others;
- Attempt to crack, reverse-engineer or circumvent the encryption or security mechanisms of the Service;
- Interfere with or disrupt the normal operation of the Service, or access our systems and data without authorization;
- Infringe our or any third party's intellectual property, trade secrets or other legitimate rights in any way.
5. Intellectual Property
The interface design, copy, icons, trademarks, software code and related materials of the Service are the intellectual property of us or the respective rights holders, and are protected by law.
We grant you a personal, non-exclusive, non-transferable, revocable license to use the Service in accordance with these Terms.
The data you keep in the Service belongs to you; these Terms do not change your ownership of your own data.
6. Disclaimers
To the maximum extent permitted by law, the Service is provided on an “as is” and “as available” basis. We do not warrant that the Service will be uninterrupted or error-free.
To the extent permitted by law, we are not liable for data loss or damage caused by: a forgotten master password, clearing or overwriting local data yourself, loss of or damage to your device, force majeure, network failures, or causes attributable to third parties.
You understand and agree that, under our zero-knowledge architecture, we cannot help recover data that can no longer be decrypted due to a forgotten master password. This is the inherent trade-off between privacy and recoverability in an encrypted product.
7. Limitation of Liability
To the maximum extent permitted by law, we are not liable for any indirect, incidental, punitive, special or consequential damages, or for any loss of data or profits, arising out of or in connection with your use of, or inability to use, the Service.
To the maximum extent permitted by law, our total aggregate liability to you shall not exceed the greater of: (a) the fees you actually paid for the Service in the 12 months preceding the claim; or (b) RMB 100. For free users, the cap is RMB 100.
8. Changes to and Termination of the Service
You may stop using the Service at any time and export or delete your data yourself.
We may adjust, suspend or terminate part or all of the Service for business or compliance reasons. For paid features, we will provide advance notice and handle the matter properly as agreed.
If you materially breach these Terms, we may suspend or terminate your access to the Service.
9. Updates to These Terms
We may revise these Terms from time to time. Material changes will be announced in advance through reasonable means such as in-app announcements or notices on our website, and the updated version and effective date will be published on this page.
Your continued use of the Service after these Terms are updated constitutes acceptance of the updated Terms.
10. Governing Law and Disputes
The formation, validity, interpretation and dispute resolution of these Terms are governed by the laws of the People's Republic of China.
Any dispute arising out of or in connection with these Terms or the Service shall first be resolved through friendly negotiation. If negotiation fails, either party may submit the dispute to the competent people's court.