arrow_back Home

Privacy Policy

Last updated: March 13, 2026

Lockstep Security ("Lockstep," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. By using Lockstep Security's website, web application, browser extension, or mobile application (collectively, the "Service"), you agree to the practices described below.

1. Data We Collect

When you create and use a Lockstep Security account, we may collect the following information:

1.1 Account Information

  • Email address — used for account identification, login, email verification, password reset, and email-based two-factor authentication (2FA).

1.2 Encrypted Vault Data

  • Vault entries — usernames, passwords, URLs, notes, and other credentials are encrypted client-side using AES-256-GCM before being transmitted to our servers. The server stores only ciphertext and can never decrypt your data.
  • Folder names — folder names used for organizing vault entries are also encrypted client-side.

1.3 Authentication Data

  • Authentication verifiers — bcrypt-hashed authentication keys derived from your master password. Your actual master password is never transmitted to or stored on our servers.
  • 2FA credentials — TOTP secrets (encrypted), backup codes (hashed), and verification status flags for email-based 2FA.

1.4 Device & Session Data

  • Device identifiers — opaque UUIDs generated by your client applications for device management and trusted-device recognition.
  • Session tokens — short-lived JWTs and rotating refresh tokens used for authentication.

1.5 Security & Operational Data

  • Security event metadata — login timestamps, IP-based rate-limiting counters, and 2FA event records. This data is collected solely for abuse prevention and security enforcement.
  • Subscription data — your subscription tier and billing status, managed through Stripe. We do not store credit card numbers or full payment details on our servers.

2. Data We Never Collect

Lockstep Security is built on a zero-knowledge architecture. We do not collect:

  • Your master password
  • Your encryption key or vault key in plaintext
  • Plaintext vault contents (usernames, passwords, URLs, notes)
  • Browsing history, page content, or keystrokes
  • Analytics, telemetry, or crash-report data
  • Location data, device sensor data, or advertising identifiers
  • Contact lists, photos, files, or any data unrelated to the Service

3. How We Use Your Data

We use the data we collect exclusively to provide and secure the Service:

  • Account management — to create, authenticate, and manage your account.
  • Vault synchronization — to store and sync your encrypted vault data across your authorized devices.
  • Two-factor authentication — to send verification codes via email when you enable 2FA.
  • Security enforcement — to enforce rate limits, detect abuse, and protect against unauthorized access.
  • Subscription management — to manage your free or premium tier and process billing through Stripe.
  • Service communications — to send essential transactional messages such as email verification codes, 2FA codes, and critical account notifications.

4. No Third-Party Sharing

We do not sell, rent, trade, or share your personal information with any third parties. This includes, without limitation:

  • We do not share your data with advertisers or ad networks.
  • We do not share your data with analytics providers.
  • We do not share your data with data brokers.
  • We do not share your data with any marketing services or partners.
  • We do not use advertising SDKs, tracking pixels, or third-party analytics tools.

The only third-party service that receives any account-related data is Stripe, our payment processor, which receives only the minimum information necessary to process subscription payments (email address and payment details you provide directly to Stripe). Stripe's use of your data is governed by Stripe's Privacy Policy.

5. No Marketing Use

Your information will never be used for marketing purposes. We do not send promotional emails, newsletters, or advertising of any kind. The only messages you will receive from Lockstep Security are essential transactional messages directly related to operating your account (e.g., verification codes, critical security alerts).

6. Encryption

All vault data is encrypted client-side using AES-256-GCM before being transmitted to our servers. Your master password is never sent to our servers — instead, we derive separate authentication and encryption keys locally on your device using PBKDF2 with 600,000 iterations. The server stores only encrypted blobs and bcrypt-hashed authentication verifiers. Even in the event of a complete server breach, your vault data remains encrypted and cryptographically inaccessible.

7. Data Retention

Your encrypted vault data is stored for as long as your account is active. When you delete your account, all associated data — including encrypted vault entries, folder structures, device records, and account information — is permanently and irreversibly destroyed.

Security event audit logs (login timestamps, rate-limiting counters) may be retained for a limited period after account deletion for fraud prevention and legal compliance purposes.

8. Your Rights

  • Access — You can view your account information at any time from Account Settings.
  • Export — You can export your encrypted vault data from Account Settings.
  • Deletion — You can delete your account and all associated data from Account Settings or via our Account Deletion page.
  • 2FA opt-out — You can disable any 2FA method at any time from Account Settings.
  • Data requests — Contact us at tomjhartnett99@gmail.com for any data-related requests.

9. Children's Privacy

Lockstep Security is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will delete that information promptly.

10. Free and Premium Tiers

Free and premium tiers differ in feature access (entry limits, device limits, web vault access), not in privacy or security protections. Both tiers use the same zero-knowledge encryption model, the same data handling practices, and the same privacy commitments described in this policy.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify users through the Service. Continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact

For privacy-related inquiries, contact us at:

  • Email: tomjhartnett99@gmail.com
  • Support page: lockstep.security/support