Who we are
Mabits (“we”) runs the password manager at mabits.com, its browser extension, desktop app and Android app. Write to [email protected] about anything on this page.
Privacy policy
Mabits encrypts your vault on your device, so most of what you store is something we could not read if we wanted to. This page lists what we do hold, why, and for how long. Last updated 25 September 2026.
Mabits (“we”) runs the password manager at mabits.com, its browser extension, desktop app and Android app. Write to [email protected] about anything on this page.
Your email address, which is how you sign in. A hash of a value your device derives from your master password, which lets us check a sign-in without learning the password. The settings your device uses to derive keys, your keys in encrypted form, whether you have set up a recovery key, when the account was created, and whether you asked for security alerts by email.
Items, folders, attachments and settings, all encrypted on your device. We cannot see names, usernames, passwords, websites or notes. We can see how many items you have, when they change, and roughly how large an attachment is.
If you use an authenticator app, we store its secret in a form we can use to check your codes, because that is how those codes work. Recovery codes are stored hashed. For a security key we store its public key and a usage counter; its name is encrypted.
What you share stays encrypted, but we can see who shares with whom, the permission given, who belongs to which organization and in which role, and for emergency access, who the contacts are, the waiting period and when access was requested. Your public keys are published so that others can share with you by entering your email address.
A Send is stored encrypted, with its expiry, view limit and view count. The key is in the link you share and never reaches us. It is deleted on its deletion date, at most 31 days after it was made, or sooner if you delete it.
Your master password, the contents of your vault, the websites you keep, your IP address or your browser’s user agent. The network address a request arrives from is held in memory for a short time to limit repeated attempts, and is never written to the database.
Our web server keeps an access log for 14 days: the time, the address requested, the response, and your browser’s user agent. The address requested can include an email address, when you look up someone’s public key to share with them. Because traffic reaches us through Cloudflare, the IP address in that log is Cloudflare’s, not yours. The application logs errors, not requests.
mabits.com is served through Cloudflare, which protects it from attacks and carries its traffic. Cloudflare decrypts each connection before passing it on, so it handles your requests as our server does: your IP address, your email address when you sign in, and your vault as the same encrypted data we store. Cloudflare may process this in any country where it operates.
Email sent to [email protected] is received and stored by Zoho Mail, in the European Union.
mabits.com does not send email at the moment. If security alerts by email are turned on, they will go only to accounts that switch them on, and each one says only that something happened on the account, never what.
The web app keeps your display settings, a random value that identifies this device to your account, and any warnings it has shown you. If you turn on the offline copy, which is off by default on the web, it also keeps your vault in its encrypted form. Your unlocked vault and your session stay in memory and are gone when you lock or close it.
The apps keep an encrypted copy of your vault so it opens without a connection. This is on by default in the extension, the desktop app and on Android, and can be turned off in settings. If you unlock with a PIN or your fingerprint, the apps keep what that needs on the device, never the master password. The Android app is excluded from phone backups.
To fill and save logins, the extension looks at the forms on the pages you visit to find sign-in fields. It offers a saved login only on the site it belongs to, and what it reads is not sent anywhere unless you choose to save a login.
Only to mabits.com, and only your encrypted vault, your sign-in and the requests above. It runs no code from anywhere else, and contains no analytics or advertising.
Data the extension handles is used only to provide its single purpose: storing, filling and generating your passwords and passkeys. It is not sold, not used for advertising, not used to decide creditworthiness or for lending, and not transferred to anyone except as this page describes.
You can delete your account from the app’s settings. It removes your vault, devices, sign-in methods, Sends, shares and security events. Items you added to an organization stay with that organization. Deleted data can remain in the database’s storage until it is overwritten.
You can export your whole vault from the app at any time, and delete your account from it. You can also write to [email protected] to ask for a copy of what we hold about you, to correct it, to delete it, or to object to how we use it. If you are unhappy with our answer, you can complain to your data protection authority.
To provide the service you signed up for; for our legitimate interest in keeping accounts and the service secure, which is what the logs, security events and failed-sign-in counts are for; and with your consent, for security alerts by email.
Mabits is not directed at children under 16.
When this policy changes, the date at the top changes with it. How the encryption works is described on the security page.