Privacy policy

Last updated 7 October 2026

The short version

Say The Password doesn't collect, receive or sell your personal data. There's no account to create, no server holding your codes, and no analytics or advertising. Your 2FA accounts are encrypted on your device with a key only your master password can unlock.

Who we are

Say The Password is made by Dimitrios Daskalakis, a sole proprietorship in Greece, in the European Union ("we"). For anything about privacy, email privacy@saythepassword.com.

On your device

Your accounts (service name, account name, setup key and settings) are stored in an encrypted vault on your Mac or iPhone. The vault is encrypted with AES-256-GCM using a random key, and that key is encrypted with your master password. If you turn on Touch ID or Face ID, the key is also kept in your device's keychain, protected by biometrics and never synced. We never see your master password, your setup keys or your codes.

Between your devices

If iCloud Drive is on, the same encrypted vault and its version history are saved to your own iCloud Drive so your devices stay in sync. Apple stores these files as part of your iCloud account under Apple's privacy policy. Because they're encrypted with your master password, neither Apple nor we can read them.

Service icons

To show each account's logo, the app downloads the icon directly from that service's own website (for example, github.com). No third-party icon service is used, and no account details are sent. Icons are stored on your device. You can turn them off in Settings.

Safari and Chrome extensions

When you open an extension, it reads the address of the current website to suggest a matching account. It fills a code into the page only when you choose Autofill. If you pick an account for a site, that site is remembered on your device so it's suggested next time. Nothing is sent anywhere.

Screen scanning on Mac

When you use Scan the Screen, the app captures the area around the scanner to look for a QR code. Images are processed on your Mac, never saved and never sent. macOS asks for your permission first, and you can withdraw it at any time in System Settings.

Beta testing

If you test the iPhone app through TestFlight, Apple may share crash reports, usage information and any feedback you choose to send with us, as described in Apple's TestFlight privacy notice. We use this only to fix problems.

Our website

This website uses no cookies, analytics or trackers. Like any website, our hosting provider may keep short-lived server logs (such as IP address and pages requested) to keep the site running and secure.

Who helps us

Apple provides iCloud Drive, the App Store, TestFlight and notarization. Our website host serves these pages. We don't have your vault, so we have nothing to share.

Why we're allowed to

Where we process any personal data at all, such as TestFlight feedback or website logs, we do so on the basis of our legitimate interest in making the app work and keeping the website secure (GDPR Article 6(1)(f)), or to answer you when you contact us.

How long we keep it

Your vault stays on your devices and in your iCloud Drive until you delete it. Deleted accounts remain in Recently Deleted for 30 days, and version history keeps daily snapshots for up to six months. Emails you send us are kept only as long as needed to help you.

Your rights

Under the GDPR you have the right to access, correct, delete and export your personal data, and to object to or restrict its processing. Since your vault is under your control, you can export or delete it in the app at any time. For anything else, email privacy@saythepassword.com. You can also complain to the Hellenic Data Protection Authority, Kifisias 1-3, 115 23 Athens, or to the data protection authority where you live.

Security

Your vault is protected by AES-256-GCM encryption, a master password strengthened with PBKDF2 (600,000 rounds), and Apple's keychain and biometrics. Your master password can't be recovered or reset, so keep it somewhere safe.

Children

Say The Password isn't directed at children under 16, and we don't knowingly process their data.

Changes

If we change this policy, we'll update it here and change the date above. If a change is significant, we'll also mention it in the app's release notes.