Pinzen
Use casesFAQSupportOpen Pinzen
  1. Home
  2. Privacy

Privacy

Privacy policy

Pinzen is built to store encrypted PINs, passwords, payment cards, and notes without turning their contents into readable server data.

Last updated August 14, 2026

What we store

Pinzen stores the display name and sign-in information needed for your account, passkey public-key metadata, encrypted vault and family-vault records, public encryption keys, membership roles, revision counters, and security-gate state. Google sign-in supplies a basic profile and verified email. Passkey-first users choose a display name and may later link a verified email for magic links; magic-link users associate their verified email with the account. Support messages are readable service data, so never put a vault secret in one.

What remains encrypted

PIN values, account passwords and usernames, payment-card details, secure notes, labels, preferences, and retired secret history are encrypted in your browser before storage. Your master phrase is not sent to Pinzen. The browser-generated Account Secret is written to the Recovery Kit you download. Pinzen+ device approval may relay a short-lived RSA-encrypted copy that only the requesting device can open; it never relays the readable secret. If you opt into Google recovery, a separate root recovery copy is uploaded only after the warning and encrypted under Pinzen's server key.

Google sign-in data

If you choose Google sign-in, Pinzen receives your basic profile, email address, profile image when available, and Google account identifier. We use this information to authenticate the account and locate its encrypted vault. Pinzen does not request access to Gmail, Google Drive, Contacts, Calendar, or files, and does not use Google bearer or refresh tokens for ongoing API access. Google sign-in alone cannot decrypt a vault; if you separately enable email recovery, control of the linked Google email becomes part of the reset boundary described below.

Browser extension data

The optional extension stores a separately encrypted point-in-time snapshot of website login URLs, usernames, passwords, payment cards, and identity profiles that you explicitly synchronize. PINs, secure notes, attachments, the master phrase, Account Secret, authenticator seeds, recovery codes, and abandoned generated passwords are not copied. The extension checks the current HTTPS origin only after you open it. A save prompt runs only on a site for which you separately approve optional access, and that access can be removed at any time. Pinzen does not collect or sell browsing history, does not auto-submit forms, and does not use extension data for advertising.

Browser extension Limited Use

Pinzen's use of information obtained through browser-extension permissions is limited to providing and improving the user-facing pairing, encrypted local storage, login capture, saved-password history, copy, and autofill features described in the extension and its store listing. We do not sell this information, use or transfer it for personalized advertising, transfer it for unrelated purposes, or permit humans to read it except with the user's affirmative consent for support, when necessary for security, to comply with law, or as aggregated and anonymized internal operations.

Family sharing

When you use a live family vault, Pinzen stores member email addresses, roles, invitation state, public encryption keys, encrypted key wraps, encrypted records, and a limited activity log of actions such as joining, adding, or removing an item. Item names and values are not placed in the activity log. Exact-email directory lookup is available only to signed-in paid organizers and is rate-limited.

Password exposure checks

If you run Password Health, strength and reuse checks happen locally. For known-breach checks, the browser hashes each password and sends only the first five hexadecimal characters of that hash through Pinzen to Have I Been Pwned's padded Pwned Passwords range service. Pinzen does not send the password or complete hash, and the matching suffix comparison happens in your browser.

Offline copies and backups

On devices where you open a vault, Pinzen may keep the latest encrypted server snapshot in browser IndexedDB for offline read-only access. It also keeps the account locator needed to find that snapshot. A backup you download is an encrypted file under your control; Pinzen cannot inventory, delete, or recover copies stored in your files or cloud drive.

Reveal protection

A registered passkey or hardware security key can approve a reveal after local user verification. Pinzen stores only the public credential and a short-lived, one-time challenge for that approval; it never receives the private key. A valid time-based authenticator code or unused recovery code remains available as a fallback. After either method succeeds, the server releases its factor share to start a 10-minute reveal window on the unlocked device. The factor share cannot derive a vault key without the local Account-Secret-bound root. Adding an item uses a write-only public key and does not require reveal approval. Do not send authenticator or recovery codes to support.

Payments and subscriptions

Lemon Squeezy is Pinzen's Merchant of Record. When you choose Pinzen+, Pinzen sends Lemon Squeezy your account identifier, name, and account email to create and link the checkout. Lemon Squeezy processes payment details, billing addresses, tax information, invoices, subscription status, cancellations, refunds, and fraud checks under its own terms and privacy policy. Pinzen stores only provider/customer/subscription identifiers, the selected plan, status, renewal or end dates, and webhook-processing records. Lemon Squeezy does not receive your master phrase, Recovery Kit, authenticator secret, vault keys, item names, or vault ciphertext.

Service providers

Vercel serves the web application. Cloudflare runs the private API and encrypted database. Google processes Google sign-in when selected and consented public-page analytics when enabled. Resend processes magic-link, family-invitation, and optional account-recovery email delivery. Lemon Squeezy processes Pinzen+ checkout and subscription administration. Have I Been Pwned returns padded password-hash ranges only when you explicitly run Password Health. Each provider receives only the information required for its role.

Recovery information

For the default Recovery Kit reset, Pinzen stores an encrypted root envelope that can be opened only with the Account Secret from your Kit and a server factor share released after a fresh authenticator code. The Account Secret and opened root are not uploaded. Google email recovery is a separate opt-in fallback: if enabled, Pinzen stores another encrypted root copy that its server recovery key can open after a rate-limited, single-use link reaches your verified Google email. That convenience reduces protection against a combined database-and-server-key compromise. Disabling it deletes the email-recovery copy and pending links without disabling Recovery Kit reset.

Public-site analytics and advertising

Pinzen does not sell personal information or use vault contents for advertising. If Google Analytics is configured, Pinzen asks before measuring public marketing and help-page visits. No Google analytics script runs in the browser. After consent, the browser sends Pinzen a random analytics identifier, a short-lived session number, and one allow-listed public route. The Cloudflare Worker replaces the route with a fixed page title and relays that limited event to Google Analytics. The relay rejects arbitrary URLs and cannot accept form values, email addresses, vault contents, master phrases, Account Secrets, authenticator codes, item names, or signed-in vault events. Your choice is stored in this browser and can be changed through Analytics choices in the public-site footer.

Retention and deletion

Account and encrypted vault data remain while the account is active. You can permanently delete the account and its server records from Settings. Local browser caches and downloaded backups remain under your device's control and should be removed separately. You may also contact privacy@pinzen.app from the address associated with the account for a data request.

Security contact

Report a suspected vulnerability to security@pinzen.app. Never include a real PIN, master phrase, authenticator code, recovery code, or live secure link.

Pinzen

A private place for the passwords your household depends on.

ProductFeaturesFamily use casesPlatformsPricing
ResourcesFAQSecurityHelp & supportShare your story
LegalPrivacy policyTerms of use© 2026 Pinzen