9Secure Privacy Policy

Last Updated: July 11, 2026 Applies to: 9Secure applications for Windows, macOS, Linux, iOS, and Android, and the 9SecureCLI command-line interface (together, the "App").

The Short Version

9Secure is a local-first password manager. We do not collect, store, receive, sell, or share any of your personal data. There are no accounts, no telemetry, no analytics, no advertising, and no servers of ours involved in running the App. Your vault lives on your devices, encrypted, and stays there.

The App makes exactly two kinds of network connections, both described below: local-network sync between your own devices, and optional breach checks against the Have I Been Pwned database.

Who We Are

9Secure is developed by TURBOBOOSTTECHNOLOGIES, based in Ontario, Canada. For anything privacy-related, contact us at legal@turboboost.tech.

Your Vault Data

All passwords, credentials, secure notes, and other data you store in 9Secure ("Vault Data") are stored locally on your devices, encrypted using the quantum-crypto library. Your master password is never stored, never transmitted, and is not known to us. We cannot access, recover, or reset your vault under any circumstances.

We never receive your Vault Data. It is not uploaded to us, backed up by us, or routed through our infrastructure.

Network Connections the App Makes

1. Local device-to-device sync (mDNS)

When you sync vaults between your devices, the App uses local network discovery (mDNS) to find your other devices on the same network and transfers Vault Data directly between them, end-to-end encrypted. This traffic never leaves your local network and never touches a server operated by us. mDNS discovery does broadcast the presence of the App on your local network, which is visible to other devices on that network.

2. Sentinel breach checks (Have I Been Pwned)

The Sentinel feature can check whether stored passwords appear in known data breaches by querying the Have I Been Pwned (HIBP) Pwned Passwords service, operated independently by a third party.

These checks use a k-anonymity protocol: the App computes a one-way cryptographic hash of the password locally and transmits only the first 5 characters of that hash. HIBP returns a list of matching hash suffixes, and the comparison is completed on your device. Your plaintext passwords, full password hashes, email addresses, and Vault Data never leave your device — Sentinel checks passwords only and never queries HIBP's account or email breach data.

As with any internet request, HIBP and its infrastructure provider (Cloudflare) receive your device's IP address and standard connection metadata when a check is performed. We receive nothing. All requests use HIBP's response-padding feature, which pads responses to a uniform size to resist traffic analysis. HIBP's own privacy practices are described in its privacy policy. Breach check results are cached locally inside your encrypted vault.

All other Sentinel analysis — password strength estimation, reuse detection, password age, and insecure-URL checks — happens entirely on your device, with no network activity of any kind.

You can disable Sentinel's breach checks in the App's settings. With breach checks disabled, the App makes no connection to HIBP whatsoever, and all local Sentinel analysis (strength, reuse, age, and insecure-URL checks) continues to work normally.

Pwned Passwords data is used under the Creative Commons Attribution 4.0 license.

That's the complete list

The App does not phone home, does not send crash reports, does not check licenses against a server, and contains no analytics or tracking SDKs.

Purchases

Paid versions of the App are sold exclusively through the Apple App Store and Google Play. Apple and Google process those transactions under their own privacy policies; we never receive your payment card details, billing address, or other payment information. The app stores may provide us with aggregated, non-identifying statistics (such as install counts).

Data We Hold About You

None. Because we operate no accounts and no servers for the App, we hold no personal data about you. This means:

  • Access / deletion / correction requests: there is nothing for us to produce, delete, or correct. Your data is on your devices, under your control. Uninstalling the App and deleting your vault files removes everything.
  • Data breaches: there is no server-side data of yours to breach.
  • Data sharing and sale: we have nothing to share or sell, and we wouldn't anyway.

Children

9Secure is not directed at children, and since we collect no data, we knowingly collect no data from children.

Legal Basis and Jurisdiction

We are a Canadian company subject to the Personal Information Protection and Electronic Documents Act (PIPEDA). Because the App collects no personal information, our obligations under PIPEDA, the GDPR, and similar laws are correspondingly minimal — but if you believe we hold personal information about you, or have any privacy concern, contact us at legal@turboboost.tech and we will respond.

Website

This policy covers the App. The 9secure.io website is a static site; its hosting provider may record standard server logs (such as IP addresses and requested pages) for operational purposes.

Future Features and Changes to This Policy

We are developing optional connectivity features, including a hosted relay for syncing devices across networks, and later an optional encrypted cloud backup with user accounts. Before any such feature launches, this policy will be updated to describe exactly what data is processed (for example, connection metadata handled by a relay), where it is stored, for how long, and under which safeguards. Material changes will be announced in the App and reflected in the "Last Updated" date above.

Contact

TURBOBOOSTTECHNOLOGIES legal@turboboost.tech Ontario, Canada