KutunaCo Privacy Policy
Last updated:
Summary
KutunaCo is an offline password vault that stores your passwords and other records only on this device. It never asks you to create an account, never connects to the internet (the Android version does not even hold the internet permission) and never collects, uploads or shares any data with anyone. It contains no advertising, analytics or crash-reporting libraries.
What is stored
The passwords, cards, API keys, notes and subscriptions you add, plus your app settings (theme, lock preferences, and a salted hash of your app PIN; the PIN itself is never stored). This data lives in the app’s folder on the device, encrypted with AES-256. The encryption key is kept in the iOS Keychain or Android Keystore, on this device only.
Autofill
If you turn on autofill, a copy of your password records that are not in the trash is handed only to the autofill service on this device. On Android the copy sits in the app’s non-backed-up folder, with the passwords encrypted by a Keystore key that requires device-lock verification. On iOS the copy is kept only in the app group keychain on this device; the system is told only the domain and username, never the password. To fill a form, the service reads the structure and name of the app or site you are signing in to, on the device; this information is neither stored nor sent anywhere. Turning autofill off deletes the copy.
Installed apps
On Android, when you link a record to an app, the names and icons of installed apps are read on the device only while you have the picker open, so the list can be shown. The chosen app’s package name and a digest of its signing certificate are stored with the record so that autofill goes to the right app. This list is never sent anywhere.
Clipboard and screen
Copied passwords are flagged as sensitive and cleared from the clipboard after the time you choose in Settings (with “Clear” set to never, they stay). On iOS, copied passwords are not shared with your other devices. On Android, screenshots and screen recording are blocked, and the content is hidden in the app switcher.
Backups and export
You create backups and choose where they are saved or with whom they are shared. Password-protected backups are encrypted with Argon2id + AES-256-GCM; if you forget the password the backup cannot be opened, not by you and not by us. If you choose an unencrypted export, the file is plain text and anyone who opens it can read your records. Temporary export files are deleted from the device after sharing.
Device backups
On Android, app data is excluded from device and cloud backups. On iOS, the encrypted vault file may be included in a device backup, but because the key that opens it stays on this device only, it cannot be opened on another device. To move your vault to a new device, make a KutunaCo backup.
Recovery copies
If the vault cannot be read at launch, the files are not deleted; the copies set aside remain on the device and can be exported, shared or deleted from Settings › Data Management › Set-aside Vault Copies.
Deleting your data
Settings › Data Management › Delete All Data removes your vault, settings, the autofill copy, recovery copies and temporary files, and creates a new encryption key at the next launch. Deleting the app also removes the vault files on the device. Because nothing is kept on a server, there is no other copy to delete.
Children
KutunaCo is not directed at children and does not collect personal data from anyone.
Changes
If this policy changes, the current text ships with the new version of the app and the date above is updated.
This website (kutuna.co)
This website uses no analytics, advertising or tracking tools and loads no third-party scripts. The only cookie is kk_lang, written when you press the language switch so that your choice is remembered; it expires after one year and is never transmitted to anyone. If you press the theme switch, your choice is kept only in your browser’s local storage (kk_theme) and is never sent to a server. The infrastructure hosting the site (Google Firebase Hosting) may keep standard server logs (IP address, time, requested page) for security and debugging; we do not access these logs or use them for any other purpose. The password generator on this page runs entirely in your browser; nothing it produces is sent or stored.
Contact
Questions: support@kiplix.com
Controller: [legal entity]