Privacy Policy
We follow the principles of “end-to-end encrypted, zero knowledge, minimal collection”: your passwords, secret notes and encrypted images are encrypted on your device, and only ciphertext is ever synced to the cloud — we cannot read your plaintext.
1. Introduction and Scope
Micro Zero Vault (wljpassmgr, “we”, “us” or “our”) is an end-to-end encrypted password management service that helps you securely store, organize, retrieve and manage passwords, secret notes and encrypted images, with optional encrypted cross-device sync.
App operator: Beijing Weilingji Technology Co., Ltd.
App developer: Beijing Weilingji Technology Co., Ltd.
The operator and the developer named above are the same legal entity (together referred to as “we”, “us” or “our company”), and are the personal information processor under this Policy. You may contact us using the methods listed in Section 12 of this Policy.
This Privacy Policy (the “Policy”) explains how we handle information when you use Micro Zero Vault products and services, the security measures we take, and the rights you have.
This Policy applies to the Micro Zero Vault apps (iOS / Android / desktop), browser extension, official website and related services we operate.
2. Information We Collect
1. Your data is encrypted by you — our servers only ever see ciphertext. Your vault, secret notes, encrypted images and other core data are encrypted locally on your device. Even when you enable cross-device sync, only ciphertext is uploaded to and stored on our servers; we technically cannot read your plaintext.
2. Account information (only when you actively use it). Only when you choose to register an account and enable cross-device sync do we process the minimum information required to provide that feature, such as a registration email or username and the security credentials used for authentication (never your plaintext master password).
3. Necessary service information. When you use features that require network access (such as sync or update checks), we may process limited technical information such as device model, OS version and network status, solely to keep the service running securely.
4. What we explicitly do not collect. We do not collect your plaintext passwords, the content of your secret notes, or the content of your encrypted images. We do not collect your browsing history or web page contents, we do not build advertising-oriented behavioral profiles, and we do not serve behaviorally targeted advertising.
5. Advertising identifier stripped out. At build time we remove the advertising-identifier related permissions (Android `AD_ID`, `freemme.permission.msa`) and disable the advertising-identifier collection flag, and no third-party SDK capable of obtaining your advertising identifier is present in the app.
3. Data Storage and Encryption
1. Encrypted at rest. All sensitive data is encrypted with AES-256 before being written to storage. On mobile, key material is kept in the system secure storage (SecureStorage / Keychain); on desktop and browser, equivalent local secure-storage mechanisms are used.
2. Key separation. We use an architecture that separates data-encryption keys from authentication keys. Your master password is used only to derive keys locally on your device; it never leaves your device and is never uploaded.
3. Zero-knowledge architecture. Data synced to our servers is always ciphertext. Encryption and decryption happen only on your devices, and the keys required for decryption are held exclusively by you: our servers merely host ciphertext and, by design, have no capability to recover your plaintext. Key material is also kept in encrypted form at all times.
4. Biometrics stay on-device. Fingerprint and face recognition are performed locally through your device's built-in security capabilities. Biometric data never leaves your device and is not accessible to us.
5. Private key and backup kit. The plaintext of your private key (Secret Key) is handled only in your device's memory: it is never uploaded to our servers, written into the URL, stored in localStorage / IndexedDB / cookies, or written to logs or analytics events. To support device management (avoiding repeated entry and validating new devices), an encrypted device key may be stored locally; it is derived from your master password using PBKDF2-HMAC-SHA256 (210,000 iterations) and encrypted with AES-GCM-256, so it can only be unlocked with your master password and cannot be decrypted by our servers. Any backup artifact you export from the app, the website or the browser extension (image, PDF or QR code) is equivalent to the private key itself — keep it offline. If the private key is lost, we cannot recover or reset it, and failing to back it up may permanently lock you out of your account and data.
4. Sharing and Disclosure of Information
1. No sharing by default. We do not sell, rent, or share your personal information with any third party for marketing or other commercial purposes. We do not integrate advertising SDKs, and we do not provide third parties with your vault contents, secret notes or encrypted images.
2. Third-party SDKs we do integrate. Our clients do not integrate any third-party analytics, advertising or tracking SDK, and we do not provide third parties with your vault contents, secret notes or encrypted images.
3. Limited exceptions. We may disclose necessary information only in the following circumstances: (a) with your explicit consent; (b) where required by applicable laws, regulations or binding orders from judicial or administrative authorities; or (c) where necessary in an emergency to protect your or another person's life or property.
4. Business transitions. In the event of a merger, acquisition or reorganization, we will require the receiving party to continue to honor this Policy, or seek your consent before transferring data.
5. Data Transmission and Security Measures
1. Encrypted in transit, end-to-end protected. We communicate over encrypted channels (HTTPS/TLS). Sensitive data is end-to-end encrypted before it leaves your device; the cloud stores only ciphertext, and the decryption keys remain exclusively in your hands.
2. Least-privilege design. We request only the permissions necessary for core features — no unnecessary system access, no silent background reporting.
3. Security engineering practices. We employ auto-lock, configurable session timeouts, log redaction in production, code obfuscation and a security-aware development process to continuously reduce exposure.
4. Incident response. If an event occurs that may affect the security of your data, we will notify you and the relevant authorities in a timely manner as required by applicable law.
6. Your Rights and Choices
1. Access and correction. You can view and edit your vault contents and profile information at any time within the app.
2. Export. We provide data export capabilities so you can take your data with you in a readable format at any time. Your data sovereignty is always yours.
3. Deletion and account closure. You can delete local data or close your account. For the detailed process, time limits and consequences, see Section 7 “Account Closure” of this Policy.
4. Withdrawing consent and complaints. You may withdraw any authorization you have granted at any time and file a complaint with us or the competent regulatory authority.
5. Response time. We process requests in accordance with applicable law (including, without limitation, the PRC Personal Information Protection Law and the GDPR), and typically respond within 15 business days of receiving a request.
7. Account Closure
Our app provides account registration and sign-in, so you have the right to close your account at any time. We provide the following closure channels:
1. Self-service in the app (recommended). After signing in, go to 「Me / Profile → Account & Security → Close Account」 and follow the on-screen steps to complete identity verification (email code / SMS code; dual verification is required when both channels are bound), then submit your closure request.
2. Request closure via our support email. If you cannot sign in, send a closure request from your registered email address to passgmr@weilingji.com with the subject “Account Closure Request”, including your account (registered email or phone number). After verifying your identity, we will complete the closure within 15 business days.
3. Assistance via our official website. You may also visit https://www.passmgr.com/ to obtain our contact details and ask us to assist with the closure.
Rules and consequences of closure:
- Data handling. Once closure is complete, we will delete or anonymize the personal information associated with your account (including account profile, cloud-synced ciphertext and backup records), except where retention is required by applicable law or to fulfil our legal obligations.
- Local data. Vault data stored locally on your device must be removed by you in the app or by uninstalling the app; under our zero-knowledge architecture we cannot remotely access or delete plaintext data on your device.
- Cooling-off period and re-registration. After closure you will not be able to re-register with the same email / phone number for 15 days, after which re-registration becomes available.
- Irreversibility. Closure is irreversible. After closure your account data and cloud-synced ciphertext will be deleted and cannot be recovered. Please export or back up your data using the in-app functions before closing your account.
- Time limits. In-app self-service closure takes effect immediately; requests submitted via the support email are processed within 15 business days after we verify your identity.
8. Personalization and Notifications
1. We do not offer personalized recommendations or targeted push. Micro Zero Vault is a password manager: we do not provide personalized content recommendations based on user profiles, and we do not carry out targeted or advertising push. We do not push goods, services or advertising based on your usage behavior.
2. Necessary notices we may send you. Only in the following scenarios directly related to your account security or service operation may we send necessary in-app notices or service notifications, such as: private key backup reminders, account security alerts (abnormal sign-in, changes to verification methods), account lock and unlock notices, and service change or shutdown announcements. These notices are not advertising or personalized push; their purpose is to protect the security of your account and data.
3. How to turn notifications off or adjust them. You may turn off private key backup reminders at any time under 「Me / Profile → General Settings → Backup Reminder」, or disable this app's notification permission in your device system settings to stop receiving push notifications. Turning these off does not affect your use of the core features of the Service.
4. Email and SMS. To complete identity verification (registration, sign-in, password change, account closure) we send verification codes to your registered email address or phone number. Such messages are a necessary prerequisite for using the corresponding features and cannot be turned off.
9. Cookies and Local Storage Technologies
1. Official website. Our official website does not use tracking cookies and does not integrate third-party ad tracking. Where local preferences are used, they rely on browser local storage only, and the data never leaves your browser.
2. Client apps. Micro Zero Vault stores encrypted data and preferences in your device's local secure storage (e.g. IndexedDB, SecureStorage, Keychain). You control this data and can clear it at any time.
3. Your choice. You may clear local data on your device at any time. Please make sure you have a proper backup first: under our zero-knowledge architecture, we cannot recover it for you.
10. Children's Privacy
We take the protection of children's personal information very seriously. Our services are intended for the general public and we do not knowingly collect personal information from children under the age of 14, nor do we carry out personalized recommendations or targeted push aimed at children under 14.
1. Rules for handling the personal information of children under 14. If you are under 14, please read this Policy together with your parent or guardian, and use our services only after obtaining their consent. Guardians should guide minors in using this service and keep their account and master password safe.
2. We do not knowingly collect children's personal information. Our registration and sign-in flows are not designed for children and do not proactively ask children to provide personal information. If, in the course of providing the service, we discover — or a guardian informs us — that we have collected the personal information of a child under 14 without prior verifiable parental consent, we will immediately stop processing it and delete the relevant personal information as soon as possible after verification.
3. How guardians can manage a child's information. If you are the guardian of a minor and wish to access, correct or delete the minor's personal information, or withdraw consent, please contact us using the details in Section 12 of this Policy. After verifying your status as guardian, we will handle your request within 15 business days.
4. Minors under 18. If you are under 18, please use this service with the consent and guidance of your guardian. We advise minors not to use this service to store sensitive credentials belonging to their guardians or others.
11. Updates to This Policy
We may revise this Policy from time to time. For material changes, we will notify you in advance through reasonable means such as in-app announcements or notices on our website, and publish the updated version and effective date on this page.
The revised Policy takes effect upon publication. Your continued use of our services after the Policy is updated constitutes acceptance of the updated Policy.