Privacy Policy
BipPass is built so that we can operate the service without ever being able to read your secrets. This policy explains what we do and don't collect — and why our architecture limits what we could collect in the first place.
What we cannot see
Secret values are encrypted on your device before transmission. We receive and store only opaque ciphertext and the metadata required to route it — project, environment, and version. We do not hold the keys required to decrypt any secret.
What we collect
- Account details — your name, email, and workspace membership.
- Device fingerprints used for trust and approval.
- Audit records of actions taken within a workspace.
- Billing information, processed by our payment provider (we never store card numbers).
How we use it
To operate and secure your account, show you who did what and when, prevent abuse, and provide support. We do not sell your data, and we do not use secret metadata for advertising.
Retention
Audit and version history persist for the lifetime of the workspace unless you delete them. Ciphertext is removed within 30 days of a hard delete. Closing your account removes personal data within 30 days, subject to legal retention requirements.
Your rights
You can access, export, correct, or delete your personal data at any time. To exercise these rights or ask a question, email privacy@bippass.dev.