1. Scope and who we are
This Privacy Policy explains how F1v3 Group LLC ("F1v3," "Stax Pass," "we," "us," or "our") handles personal information when you use the Stax Pass applications, website, account services, support, and related services (collectively, the "Service"). It does not govern a third-party website or service merely because you save its credentials in Stax Pass or follow a link to it.
2. Information we process
We collect information from you, from the app or device you use, from people who invite or share with you, from app-store and payment providers, and automatically from ordinary service operations.
| Category | Examples | Why we process it |
|---|---|---|
| Account and contact data | Email address; internal user ID; email-verification status; an encrypted account display name, if provided. | Create and administer the account, communicate about security or service matters, and provide support. |
| Encrypted vault content | Encrypted item fields, notes, one-time-password seeds, recovery codes, encrypted attachments and file metadata, encrypted vault names, tags, preferences, and contact profiles you choose to save. | Store, sync, restore, organize, and share the encrypted content at your direction. |
| Cryptographic and authentication records | Password-authentication verifier and protocol records, encrypted key wrappers, public sharing keys, encrypted recovery records, key versions, salts, and key-derivation parameters. | Authenticate the account and make encrypted vault access, recovery, and sharing work without storing raw vault keys. |
| Device and session data | Random app-generated device ID; user-editable device name; platform, model, operating-system and app version; locale; approval and revocation status; last-seen timestamps; token and session records. | Approve and identify trusted devices, keep sessions working, show device activity, revoke access, troubleshoot compatibility, and prevent abuse. |
| Sharing and collaboration data | Vault membership, roles and permissions; invitations; recipient account identifiers and public keys; encrypted shared-vault metadata; ownership and rotation records. | Carry out the sharing choices made by vault owners, managers, and members and enforce access permissions. |
| Sync, security, and operational data | Record IDs, routing IDs, versions, cursors, encrypted sizes, timestamps, deletion markers, rate-limit buckets made with one-way keyed hashes, security events, safe error codes, and request-level service logs. | Route and synchronize records, detect conflicts, enforce limits, maintain reliability, investigate abuse or security events, and diagnose failures. |
| Billing and entitlement data | Plan and subscription identifiers, product and provider, subscription state, trial or entitlement status, renewal and expiration dates, hashed store identifiers and proofs, limited transaction references, and family-plan membership. | Verify purchases, provide paid access, manage family coverage, prevent duplicate or fraudulent claims, and maintain required financial records. Apple, Google, or another payment provider processes your payment credentials; Stax Pass does not need your full payment-card number. |
| Communications | Support requests, privacy requests, feedback, and related correspondence. Do not send us passwords, recovery phrases, private keys, or vault contents. | Respond, investigate, improve the Service, and maintain a record of the request. |
| Website data | IP address, user-agent, requested page, referrer, timestamp, and security or delivery logs that may be created by our hosting and network providers. | Deliver and secure the website, prevent abuse, and diagnose availability. The Stax Pass website does not use third-party advertising pixels or analytics scripts. |
Your vault content may contain sensitive information
You control what you place in Stax Pass. Depending on your choices, encrypted vault content may represent passwords, financial information, identity information, health information, private communications, or information about other people. You should store only content you are authorized to possess and process. We do not use vault content to infer characteristics about you, advertise to you, or build a profile about you.
Information designed to stay off our servers
The Service is designed so our servers do not receive your raw account password, raw recovery phrase, raw durable encryption keys, readable vault item fields, or readable imported password rows. A plaintext import file is selected and processed locally; accepted records are encrypted before ordinary synchronization. If you voluntarily include a secret in a support request or another communication outside the vault, that communication is not protected by the vault's zero-knowledge boundary.
Biometrics
If you enable biometric unlock, your device's operating system performs the biometric check. Stax Pass does not receive or store your face image, fingerprint, voiceprint, or biometric template. The app uses the successful local check to release device-protected cryptographic material on that device.
3. How we use information
We use personal information only as reasonably necessary to:
- provide, synchronize, secure, maintain, and support the Service;
- authenticate accounts, verify email ownership, manage devices, recovery, permissions, and encrypted sharing;
- process subscriptions, trials, entitlements, storage limits, and family-plan access;
- detect, prevent, and investigate fraud, abuse, unauthorized access, malware, and security incidents;
- diagnose errors, preserve service integrity, and improve reliability and accessibility;
- communicate about account activity, security, policy changes, and support; and
- comply with law, enforce our agreements, and protect users, Stax Pass, and others.
We do not use encrypted vault content for advertising, train machine-learning models on it, or attempt to decrypt it for product analytics.
4. When we disclose information
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We may disclose limited information in these circumstances:
- At your direction. When you invite someone, join a shared vault, assign permissions, share an item, transfer permitted control, or otherwise direct a disclosure. A recipient may retain information they were able to decrypt or copy while authorized.
- Service providers. To vendors that help provide cloud hosting, data storage, network delivery, transactional email, customer support, security, and similar operations, subject to contractual restrictions appropriate to their work.
- App stores and billing providers. To Apple, Google, or another purchase provider as needed to verify and administer subscriptions and entitlements. Their own privacy terms also apply to data they collect directly.
- Legal and safety reasons. If we reasonably believe disclosure is required by valid legal process or is necessary to protect rights, safety, security, or the integrity of the Service. Because we do not hold the material needed to decrypt zero-knowledge vault content, we cannot provide readable vault content we do not possess.
- Business changes. In connection with financing, due diligence, reorganization, acquisition, merger, or sale of assets, subject to confidentiality measures and applicable law.
We may use and disclose information that has been aggregated or de-identified so it cannot reasonably be linked to you. We do not attempt to re-identify it except to test whether de-identification remains effective.
5. Retention and deletion
We retain each category only as long as reasonably necessary for the purposes described above, including to provide an active account, honor deletion and synchronization state, secure the Service, resolve disputes, meet legal obligations, and enforce agreements. Retention depends on the record:
- active account, encrypted vault, device, and sync records are generally kept while the account or record remains active;
- deleted items may remain as versioned deletion markers long enough to synchronize the deletion and protect against accidental reappearance;
- short-lived authentication, approval, and verification challenges expire under their security limits;
- security, fraud-prevention, support, billing, transaction, and legal records may be kept longer when reasonably necessary for those purposes;
- encrypted backups are overwritten or expire under our backup cycle and are not restored for ordinary use after a valid deletion request; and
- when deletion is complete, we may retain a narrowly limited tombstone, de-identified record, or other information required to document the request, prevent fraud, resolve disputes, or comply with law.
Deleting the app does not delete the server account. Use the in-app account-deletion control, if available, or contact us. Removing a device immediately cuts off future server access, but an offline device may retain its local encrypted copy until it reconnects or is wiped. Information another user already decrypted, copied, or exported from a shared vault is outside our technical control.
6. Your choices and privacy rights
You can review and change certain account and device information in the app, delete vault records, remove sharing access, revoke devices, and request account deletion. Depending on where you live, you may also have rights to request access, correction, deletion, or a portable copy of personal information; to appeal a denied request; or to limit or object to certain processing.
Send a request to privacy@stax-pass.com from the account email and describe the right you want to exercise. We may verify your identity and authority before acting. We will not discriminate against you for exercising an applicable privacy right. Some requests may be limited where an exception applies, where fulfilling the request would expose another person's information, or where we cannot identify data inside encrypted vault content.
California disclosures
California residents may have rights to know, access, correct, and delete covered personal information and to receive information about its collection and disclosure. During the preceding 12 months, the categories we may have collected and disclosed for the business purposes described in this Policy are the categories listed in Section 2. We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information to infer characteristics or for purposes that would require a right to limit under California law.
Do Not Track and Global Privacy Control
The website does not use cross-site advertising trackers, so changing a browser's Do Not Track setting does not change our current practices. Where legally required, we treat a recognized Global Privacy Control signal as a request to opt out of sale or cross-context behavioral advertising; we do not currently engage in either practice.
7. Security and the shared responsibility model
We use administrative, technical, and organizational safeguards designed for the sensitivity of the information we process. The product is built around local cryptographic operations, encrypted vault records, separate key roles, protected authentication records, access controls, and limited operational metadata. We review and improve safeguards as threats and the Service change.
No system can guarantee absolute security. Zero-knowledge architecture reduces what our servers can read, but it cannot protect information after you unlock, copy, export, disclose, or share it; prevent malware, phishing, screen capture, clipboard access, weak device security, or compromise of an authorized device; recover a forgotten account password without a working recovery path; or remotely erase an offline device immediately.
You are responsible for using a strong and unique account password, safeguarding recovery material separately, securing and updating your devices, reviewing trusted devices and sharing permissions, and reporting suspected unauthorized access promptly. We remain responsible for the obligations imposed on us by applicable law and for operating the safeguards we describe; this Policy does not transfer those obligations to you.
To report a suspected vulnerability or security incident, email security@stax-pass.com. Do not include live credentials, recovery phrases, or private vault content.
8. Children
Stax Pass is not directed to children under 13, and they may not create or use an account. If you are under the age of legal majority where you live, you may use the Service only with permission and supervision from a parent or legal guardian who accepts the Terms. If we learn that we collected personal information directly from a child under 13, we will take appropriate steps to delete it. Contact privacy@stax-pass.com.
9. Processing in the United States
Stax Pass is operated from the United States. If you use the Service from another country, information may be processed in the United States and other locations where our providers operate, subject to applicable safeguards and law.
10. Changes to this Policy
We may update this Policy as the Service, our practices, or legal requirements change. We will post the updated version and revise the date above. If a change materially reduces privacy protections or materially changes how we use personal information, we will provide additional notice when required and seek consent when the law requires it.
11. Contact us
F1v3 Group LLC operates Stax Pass. For privacy questions or requests, email privacy@stax-pass.com. For general support, email support@stax-pass.com.