The short version: your vault is encrypted on your device with keys we never receive. We literally cannot read your passwords, notes, or files.
Walilock is a zero-knowledge password manager. That is not a marketing phrase — it is an architectural constraint that shapes this entire policy. Your vault is encrypted on your own device using keys derived from a master password that never leaves your hardware. We store only opaque ciphertext. As a result, we literally cannot read your passwords, secure notes, or attached files, and we cannot hand them to anyone else, because we do not possess the keys to decrypt them.
This document explains, in plain language, what limited information we do collect, why we need it, what we are technically incapable of seeing, and the rights you have over your data. It applies to the Walilock apps, the Walilock website, and the Walilock sync relay, all operated by Richdale Ventures LLC ("Walilock", "we", "us").
We practice data minimization: we collect the least we need to run the service, bill it, and keep it secure. Specifically:
AES-256-GCM). To us this is an opaque blob of random-looking bytes with no decryption key attached. We store and forward it between your devices; we cannot open it.Because encryption and key derivation happen entirely on your device, the following are mathematically out of our reach. This is the whole point of the product:
The trade-off is real and we want you to understand it: because we cannot decrypt your vault, we cannot recover it for you if you forget your master password. Save an emergency kit when you enable sync — it restores access after a lost or wiped device, though it cannot replace a forgotten password. You can read the full mechanics on our Security page.
Our website uses a small number of strictly necessary cookies and browser local-storage entries to keep you signed in, remember your preferences, and secure form submissions. We do not use advertising or cross-site tracking cookies. The Walilock apps use device storage to hold your encrypted vault and settings locally. For the full breakdown and your choices, see our Cookie Policy.
The Walilock browser extension is the one part of Walilock that runs inside your browser, and it is deliberately the least capable part. It has no account, no server, and no network access of its own — it cannot send anything to us, or to anyone else, because it has nowhere to send it to.
It does not hold your vault. When you fill a password or use a passkey, the extension asks the Walilock desktop app for that one value, over a local channel on your own computer. Your vault is opened and decrypted by the desktop app, on your device, and only the single field you are filling comes back. The extension requires the desktop app for exactly this reason: without it, there is nothing for the extension to read.
Two things, neither of them secret, are kept in browser storage:
No password, passkey, or vault content is ever placed in browser storage.
The extension asks for permission to run on all websites. That is a broad permission and it is worth saying plainly why it needs one: a password manager has to fill credentials on whichever sites you have saved credentials for, and those sites are listed only inside your own vault. Restricting the extension to a fixed list would require us to know which sites you hold accounts on — which is precisely what the rest of this policy exists to prevent. The extension reads a page only to find the sign-in fields you asked it to fill. It retains nothing and, having no network access, transmits nothing.
We do not sell your personal data, and we never will. We share data only with a short list of vetted subprocessors that are contractually bound to protect it and use it solely to provide the service on our behalf:
We may also disclose information if legally compelled (for example, a valid court order). If we ever receive such a request, we will provide only what we actually hold — and because your vault is encrypted with keys we don't have, we cannot produce your decrypted secrets no matter who asks. Where permitted by law, we will notify you of requests affecting your account. Finally, if Walilock is involved in a merger or acquisition, any transfer of data will remain subject to this policy or a successor with equivalent protections.
We keep personal data only as long as we need it:
You can delete your account at any time. Today, account deletion is handled by contacting our support team at support@walilock.com (a self-service in-app deletion flow is on our roadmap). On deletion we remove your account record and encrypted vault blobs from active systems and instruct our subprocessors accordingly; residual copies in encrypted backups are purged on our standard backup-rotation cycle.
Depending on where you live — including under the EU/UK GDPR and California's CCPA/CPRA — you have rights over your personal data. Walilock honors these rights for all users, wherever you are:
To exercise any of these, email privacy@walilock.com. We will respond within the timeframe required by applicable law (generally within 30 days). We do not sell or "share" personal information for cross-context behavioral advertising, so there is nothing to opt out of on that front.
Security is the product, so protection is built in rather than bolted on:
AES-256-GCM before they ever leave your device.TLS 1.3 on top of the application-layer end-to-end encryption.Full technical detail — the cryptographic specification and our threat model — lives on the Security page.
Walilock operates globally, and our infrastructure and subprocessors may process data in countries other than your own, including the United States. Where we transfer personal data across borders, we rely on appropriate safeguards such as Standard Contractual Clauses. In practice, the sensitive part of your data — your vault — travels only as ciphertext, so it stays unreadable regardless of which jurisdiction the servers sit in.
Walilock is not directed to children. We do not knowingly collect personal data from anyone under 16 (or under 13 where that is the applicable minimum age). If you believe a child has created an account, contact us at privacy@walilock.com and we will delete it.
We may update this Privacy Policy as the product and the law evolve. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you by email or in-app. Continued use of Walilock after an update means you accept the revised policy. This policy works alongside our Terms of Service.
Questions, requests, or concerns about your privacy? We read every message.
Richdale Ventures LLC
Privacy inquiries: privacy@walilock.com
General & support: support@walilock.com
Or use the form on our Contact page.