1. Controller and scope
The private Publisher who releases MASTRpass under the project name MASTRlabs is the controller for personal data actually received through mastrpass.xyz or support communications. Contact: support@mastrapps.com. Legally required identity and residence information must be added to the store profile and other required notices and kept current.
This Policy covers the MASTRpass app, mastrpass.xyz, official distribution channels and support. It does not cover separate MASTR products or independent services opened through external links. MASTRlabs has no server access to locally encrypted app data it never receives.
2. Data-flow summary
MASTRpass is designed around data minimisation and privacy by design.
- No registration, MASTRpass account or profile.
- No app backend, cloud sync, telemetry, advertising, trackers, crash uploads or remote configuration.
- Android has no INTERNET or ACCESS_NETWORK_STATE permission and no WebView.
- Vaults and related data remain authenticated and encrypted in the private app area or user-created exports.
- The website uses no analytics cookies; only the language is stored in browser localStorage.
3. App data processed locally
Depending on use, MASTRpass locally processes passwords, usernames, recovery phrases and keys, TOTP secrets, passkeys, secure notes, attachments, tasks, journals, tags, timestamps, backups, local activity events and analysis inputs you provide. These data are not sent to MASTRlabs.
Local reports may include technical information such as package ID, app version, signing certificate, permission state, opaque item IDs and limited event types. Titles and secret values are not written to the local Exposure Ledger.
4. Biometrics, keystores, autofill and clipboard
Optional biometrics, Android Keystore, StrongBox/TEE, Windows Hello and Apple LocalAuthentication are provided by the operating system. MASTRpass receives no raw biometric data or templates; it receives only the local authentication result and device-bound cryptographic operations.
Autofill and Credential Provider disclose selected data only after user action and from an unlocked session to the selected target app or web origin. Copying places individual secrets on the system clipboard; MASTRpass marks them sensitive and attempts prompt removal. The operating system, keyboard, target app and clipboard history remain outside MASTRpass’s full control.
5. Backups, imports, QR and Guardian
Backups, exports, imports, file transfers and QR transfers are performed locally and only at your request. You choose the destination, medium and recipient. Any external backup or file service then processes the data under your direction and its own terms.
The Solana Guardian processes supplied messages locally without RPC, simulation, signing or broadcast. Transaction payloads and Guardian reference profiles are not sent to MASTRlabs.
6. Deletion and control in the app
There is no server-side MASTRpass account. Local items, vaults and profiles can be deleted in the app; uninstalling removes private app-area data according to operating-system rules.
Backups, screenshots, files, clipboard histories or copies in other apps are not automatically removed. You must delete those at every location you selected. Because MASTRlabs cannot access local vault data, support cannot delete or provide them from a server.
7. Data on mastrpass.xyz
The website has no user account, contact form, advertising technology or audience analytics. The selected language is stored as mastrpass-language in browser localStorage and is not sent to a MASTRpass backend.
The website is intended to be hosted by Infomaniak in Switzerland. As with any website, hosting and security logs may technically process IP address, date/time, requested URL, transfer status, referrer and browser/device information. This supports delivery, abuse prevention, troubleshooting and security; MASTRlabs does not use it for advertising or profiling.
8. Support and security communications
If you email support@mastrapps.com, the email address, metadata, content, attachments and conversation history are processed to answer the request, investigate security reports, prevent abuse and meet legal obligations.
Never send real seed phrases, recovery keys, master passwords, vault files, keystores or signing keys. Only the minimum necessary and redacted information will be requested for identity verification or troubleshooting.
9. Donations, blockchain and external links
The Solana address shown on the website is public. A donation places wallet addresses, amount, time and transaction data on a public blockchain, where MASTRlabs cannot delete them. Opening Solscan or another external destination sends connection data directly to that provider.
External services, including Solana Mobile, Solscan, app stores, X and Linktree, act as independent controllers under their own privacy policies. A link does not mean the MASTRpass app itself transmits data.
10. Purposes and legal bases
Where data-protection law requires a legal basis, processing relies on contract or pre-contract steps for requested support, legitimate interests in secure website delivery, abuse prevention, troubleshooting and legal enforcement, legal obligations, and consent for voluntary submissions where required.
We do not sell personal data, use it for targeted advertising or create user profiles. Consent may be withdrawn for future processing without affecting prior lawful processing.
11. Recipients and international processing
Website or support data may be processed as necessary by hosting and email providers, technical or legal advisers, or authorities. App vault data are not shared with these recipients because they are not transmitted to MASTRlabs.
Planned website hosting is in Switzerland. Email routing, your own provider or external services you open may process data in other countries. Where MASTRlabs initiates a transfer, applicable adequacy decisions, contractual safeguards or legal exceptions are considered. Current recipient and country details may be requested at support@mastrapps.com.
12. Retention
Local app data remain on your device or in exports until you delete them. The browser language preference remains until you clear website data.
Support communications are retained only as long as needed for handling, security remediation, abuse prevention and legal evidence. Hosting logs follow the host’s security and retention configuration. Data are deleted or anonymised when the purpose and legal obligations end.
13. Security and data incidents
MASTRpass uses local authenticated encryption, bounded parsers, atomic writes and platform-specific protections. The website and support channels use appropriate technical and organisational safeguards.
No safeguard offers absolute security. If a personal-data breach occurs, risk, containment and applicable notice duties are assessed. An app vulnerability is not automatically a server data breach because MASTRlabs does not hold local vault data.
14. Children and sensitive data
MASTRpass is not directed to children under 16 and does not knowingly collect child profiles. The app also does not transmit sensitive vault content to MASTRlabs.
If MASTRlabs receives a child’s data or unnecessary sensitive information through support, appropriate restriction or deletion steps will be taken. A parent or guardian may contact support@mastrapps.com.
15. Your privacy rights
Depending on applicable law, you may request access, correction, deletion, restriction, disclosure or portability, object to processing and withdraw consent. You may also complain to the data-protection authority competent for you or the private Publisher.
Send requests to support@mastrapps.com. We may reasonably verify identity. For exclusively local app data, the response may be that MASTRlabs does not process them; you control those data directly in the app and your backups.
16. No advertising, sale or automated decisions
MASTRlabs does not sell or rent MASTRpass user data, run cross-site tracking or use personal data for targeted advertising.
MASTRpass makes no automated decision about you that produces legal or similarly significant effects. Local security scores and warnings are transparent technical aids and are not sent to MASTRlabs.
17. Changes, contact and complaints
This Policy will be updated if app permissions, SDKs, hosting, support processes, law or data flows change. The current version and date will be published on mastrpass.xyz.
Privacy and legal requests: support@mastrapps.com. Security reports should contain reproducible technical details but no real secrets.