Security & recovery

How Vaultless handles
your passwords and mail.

Your Master Key stays on your device. Email and online recovery use servers. Here’s what each part does and what you need to back up.

Why “Vaultless”?

Passwords are created
on your device.

Vaultless uses your Master Key and the saved settings for an account to create its password locally. With the matching Key and complete saved settings, it can reproduce that generated password.

Saved logins are also stored encrypted on your device so they’re ready when you need them. “Vaultless” doesn’t mean there is nothing to store or back up.

The Key alone is not a complete backup. Account details and the settings used to create each password matter, too. Imported passwords need their saved credential data.

On your device

Password creation and access to saved logins happen locally. Your Master Key and readable passwords aren’t sent to Vaultless servers to create or fill a login.

With online services

Aliases, mail delivery, breach checks, online recovery, and delivery tracking use servers. Account-free means you can start without registering a traditional Vaultless account.

Your Master Key

Keep both parts
of your Master Key.

Your Key phrase and Base password make up the Master Key. Keep both somewhere you can still reach if your phone is lost.

Vaultless cannot recover a forgotten Master Key. Its displayed ID identifies the Key; it does not contain the secret or replace a backup.

A Recovery Phrase belongs to online recovery. It is different from the Key phrase inside your Master Key. Follow the requirements for the recovery method you set up.

When you get a new phone

Set up recovery
while you still have access.

Open Recovery in the app and prepare a method before you need it.

Encrypted backup file

Export a current encrypted backup and keep it outside the phone. You need that file and the matching two-part Master Key to restore it.

Online recovery

Set up and verify the Recovery Phrase in the app. Keep it along with your Master Key, and check that your recovery data is up to date.

Transfer from your old device

If the old device is still available, use the app’s device transfer flow. A transfer plan alone doesn’t help if that device is lost.

An optional recovery sign-in helps locate a linked account. It does not replace your Master Key. Older backup files can have different requirements; the app checks the file before asking for what it needs.

Email privacy

An alias hides your
personal email at signup.

It doesn’t hide every detail you choose to give the website, and it doesn’t make ordinary email end-to-end encrypted.

Vaultless and its mail providers process ordinary messages to deliver them. Optional shared-key mail protects message content with a key shared separately; routing information remains visible.

If you forward mail, a copy also reaches your existing email provider. You can pause forwarding for one alias while continuing to read its messages in Vaultless.

Read the full privacy policy

Breach monitoring

Check for known
email exposure.

With your consent, Vaultless checks addresses through Have I Been Pwned. That service receives the full email address, never your password or Master Key.

Only known breaches can appear in a result. If a check fails, the app says so instead of showing no known exposure.

Vaultless can prepare a replacement alias. You complete the email change on the outside website and follow the app’s retirement instructions so you can keep access during the change.

Check your email on Have I Been Pwned, opens in a new tabUnderstand the possible results

If a service is unavailable

Open saved logins
without a connection.

Saved passwords open on your device. To recreate a generated password, you need its complete account settings and matching Master Key.

New aliases, new mail, breach checks, and online recovery need their services to be available. Local storage cannot deliver new email during a service interruption.

A local encrypted backup gives you a recovery option separate from online recovery. Keep it up to date and keep the required Key available.

If you stop using Vaultless

Plan the move
before deleting anything.

Export an encrypted backup from Recovery. That file is for restoring Vaultless; it isn’t a universal import file for another password manager.

If you move to another service, update each website to an email address you’ll continue to control. Keep the old alias available until the website accepts the change, and verify that you can sign in.

Deleting an alias removes its associated sign-in and mail from Vaultless. Cancelling Pro, pausing forwarding, retiring an address, and permanently deleting it are different actions.

Alias addresses depend on the mail service continuing to operate. An encrypted backup cannot keep an address receiving mail if that service closes.

Get help planning a move