Password Manager
Secure password storage with master password encryption and recovery codes
Add the bot and say what you need.
Capabilities
- AES-256 encryption
- Password generator
- Recovery codes
Your data
Password Manager Privacy Policy
What This App Stores
- Master password hash - Argon2id hash of your master password (never stored in plain text)
- Salt - Cryptographic salt for key derivation
- Password entries - For each stored credential:
- Service name/description (stored unencrypted to enable search)
- Password (encrypted)
- Username (encrypted, optional)
- Email (encrypted, optional)
- URL (encrypted, optional)
- Notes (encrypted, optional)
- TOTP/2FA secret (encrypted, optional)
- Recovery code hashes - Argon2id hashes of your recovery codes (codes themselves are shown once, then discarded)
- Vault 2FA secret - Encrypted TOTP secret if you enable two-factor authentication for vault access
- Categories - User-defined category names, icons, and colors for organizing passwords
- Security state - Failed login attempt count and temporary lockout timestamp
App-Specific LLM Processing
- What: Your service names are included as context when messages are routed to this app
- Purpose: Helps the AI understand which credential you're referring to (e.g., "show me my github password")
- Credentials: Passwords and other secret values are never placed in routing or agent context. When you retrieve or generate a password, the app's own AI lane composes the reply that contains it; the secret is returned only in that direct response to you, with automatic message deletion where the platform supports it. Any secret value that would flow back into routing AI context is re-masked before the AI sees it
App-Specific Security
- Application-layer AES-256-GCM encryption - All sensitive credential fields are encrypted using a key derived from your master password, separate from the system-wide database encryption
- Argon2id key derivation - Your master password derives the encryption key using memory-hard Argon2id
- Automatic session timeout - Sessions expire after 15 minutes of inactivity; the encryption key is only held in memory while authenticated
- Account lockout - Temporary lockout after multiple failed authentication attempts
- Recovery codes - One-time-use codes that allow emergency access if you forget your master password
This policy covers only data specific to this app. For information about core data handling (user identity, database encryption, data deletion, your GDPR rights), see the Saasis Service Privacy Policy.
Read how storage and encryption work across every app on the security page.
FAQ
›How are my passwords stored?
All sensitive fields (passwords, usernames, emails, URLs, notes) are encrypted using AES-256-GCM. Your master password is never stored - it is hashed with Argon2id and used to derive the encryption key.
Service names are stored unencrypted to enable search functionality, so the list of services you have credentials for is visible, but not the credentials themselves.
›What if I forget my master password?
Use recovery codes with !password recover. Without recovery codes, your stored passwords cannot be recovered - they're encrypted with your master password.
Recovery codes are shown once when you set up your vault. Save them somewhere safe immediately - they cannot be viewed again later.
›Does searching for a service name need to be exact?
No, service name search is case-insensitive. Searching "github" will find "GitHub".
›Why did my vault lock itself?
The vault automatically locks after 15 minutes of inactivity. This is a security measure - the encryption key is only held in memory while you're actively using the vault.
›What happens if I enter my master password wrong multiple times?
Your account is temporarily locked after several failed attempts to prevent brute-force attacks. Wait for the lockout period to expire before trying again.