Privacy policy
ninjabiba is a privacy-first password manager. This notice describes what the web app, Chrome extension, and iOS app send to ninjabiba.com. It is product documentation, not legal advice.
What we store
- Account email and a hashed account password for sign-in.
- An encrypted vault backup. The server stores ciphertext only so your other devices can sync. Your master password and vault encryption keys are derived on your device and are not sent to the server.
- Optional authenticator (TOTP) secrets, encrypted at rest on the server.
- Session tokens so you can stay signed in until you sign out or the session expires.
What stays on your device
- Master password, derived keys, and decrypted vault items stay in memory until you lock, sign out, or the auto-lock timeout fires. The Chrome extension may keep an opaque encrypted backup locally; it never stores the master password or decrypted items on disk.
- The Chrome extension fills a login only after you choose a matching account. It does not inject passwords on page load.
iOS app
- The iOS app uses the same account and encrypted vault sync as the web app: the server receives your account email, hashed account password, session tokens, and vault ciphertext only.
- On device, the app may store session material in the Keychain, optionally wrap your master password for biometric unlock (Face ID / Touch ID), and publish an autofill credential index so iOS Password AutoFill can offer matching logins. The autofill extension does not hold a plaintext copy of your vault.
- We do not include advertising or tracking SDKs in the iOS app.
Retention
We keep your account, hashed account password, encrypted vault backup, and MFA material for as long as the account exists. Refresh sessions last until you sign out, the token expires, or the session is revoked. After you delete your account, that server-side data is removed immediately (see below). Device-local data is cleared when you delete the account from the app or uninstall it.
Account deletion
In the iOS app, open Settings → Delete account, confirm, and enter your account password (plus an authenticator code if MFA is enabled). That authenticated request permanently deletes your user record, encrypted vault backup, sessions, and MFA secrets. You can export a LastPass-compatible CSV from Settings before deleting if you want a local copy of vault contents. Deletion is immediate; we do not keep a recoverable copy of deleted accounts.
Chrome Web Store data categories
Using the Chrome Web Store category names, ninjabiba collects or processes: personally identifiable information (account email); authentication information (account password hash, session tokens, and encrypted vault contents); website content (login-form field kinds such as type, name, id, and autocomplete — not typed passwords); and web history limited to the current page hostname so a matching login can be offered. We do not collect health information, payment-card data, personal communications, or location.
Chrome Web Store User Data Policy
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. User data is used only to provide this password manager: account sign-in, encrypted vault sync, login-form detection, explicit autofill, and optional save. We do not sell user data, use it for advertising, or transfer it to data brokers.
What we do not do
- We do not sell your data or run advertising SDKs in the app or extension.
- We do not require this policy page to be viewed while signed in.
Contact
Questions about privacy or account deletion: [email protected].
Last updated 17 September 2026.