Palladin Privacy Policy

Polish version: Polityka Prywatności — the Polish version is legally binding; this English version is provided for convenience.

1. Controller

Patryk Roguszewski IT Solutions — the business name of Patryk Roguszewski, a sole trader registered in Poland’s Central Register and Information on Economic Activity (CEIDG), Tax ID (NIP) 8241804773, REGON 366380826 — is the controller of personal data (“we”, “Palladin”). Service address: ul. Szkolna 11G/1, 05-091 Ząbki, Poland. Contact — including all data-protection matters: patryk.roguszewski@palladin.io, tel. +48 517 777 441.

Where an organization (a B2B customer) enters data concerning its employees or systems into the Service, we act as a processor under a data processing agreement (Art. 28 GDPR), and that organization is the controller.

2. Two categories of data: Account Data and Vault Data

Palladin is built on a zero-knowledge architecture: the contents of your Entries are encrypted on your device before they reach our servers.

Account Data (visible to us)Vault Data (invisible to us)
What it coverse-mail, display name, language, organization, salt and authentication verifier derived client-side from the Master Password, Plan and subscription status, Entry metadata (name, description, icon, type, domain, timestamps), the audit log, public keys and wrapped private keysEntry contents: usernames, passwords, API keys, notes, URLs, TOTP secrets, scripts, fields marked as concealed
How it is storedin plaintext or encrypted server-sidesolely as ciphertext (XSalsa20-Poly1305); keys derived from your Master Password (Argon2id) exist only on your device
Can we access ityes — to the extent necessary to provide the Serviceno — we do not know your Master Password, Recovery Key or encryption keys, and we are unable to decrypt Entry contents

Encrypted Vault Data remains personal data under the GDPR (pseudonymisation); client-side encryption is our security measure under Art. 32 GDPR.

PurposeDataLegal basis
Account creation, authentication and providing the Servicee-mail, name, language, organization, salt and authentication verifier; wrapped cryptographic keys; encrypted Entries and their metadataArt. 6(1)(b) GDPR (contract)
Plan, subscription and billing administrationPlan, subscription status, customer and transaction identifier at the operator, billing country and currency; billing data supplied to the operatorArt. 6(1)(b) and (c) GDPR (contract and tax/accounting obligations)
Security, accountability, abuse preventionaudit log (who, what, when — including Entry names, Agent name and stated reason), IP address and hostname of an Agent’s last connectionArt. 6(1)(f) GDPR (legitimate interest: service security and accountability of secret access)
Notifications about events requiring a decisionpush token, device platform and device name or browser-client identifier, event category, opaque notification identifier, and notification title and body; depending on the event, the message may contain an Agent name, the name of the person taking the action, an Entry name or a Vault name — never Entry contents, passwords, keys or other secretsArt. 6(1)(b) GDPR
Transactional and legal e-mail deliverye-mail address, display name, notification content, delivery/bounce/complaint eventsArt. 6(1)(b), (c) and (f) GDPR (contract, legal obligation, delivery security and effectiveness)
Product analyticsapp usage events (user identifier, event type, technical properties — never Entry contents, never secrets)consent (Art. 6(1)(a) GDPR) — see the Cookie Policy
Complaints and requestscorrespondence, account dataArt. 6(1)(b) and (c) GDPR
Handling notices concerning illegal content, appeals and DSA obligationsnotifier contact details, notice contents and attachments, statement of reasons, correspondenceArt. 6(1)(c) GDPR (legal obligation) and Art. 6(1)(f) GDPR (defence of claims and Service security)

Providing Account Data (the e-mail address and data required for authentication) is voluntary but is a condition of concluding and performing the agreement — without it we cannot create an account or provide the Service. Providing data required by the payment operator is a condition of purchasing a paid Plan. Analytics consent is entirely voluntary and refusing it does not limit your use of the Service.

The Service is intended solely for persons aged 18 or over. We do not knowingly create accounts for minors.

We do not profile users, make automated decisions producing legal effects, or sell data.

4. Data visible to AI Agents

By deliberate product design, AI Agents enrolled in your organization can see — without approved Access — the public metadata of Entries: name, description, domain, and fields the Entry owner has explicitly marked as agent-visible. This lets Agents locate the right Entry and request Access. Entry contents are never visible without approved Access; they are delivered one Entry at a time, encrypted to the specific Agent’s key. Do not put personal data or secrets into Entry names or descriptions.

If you use the get mode (returning a secret into the Agent’s context), the secret may be transmitted to the LLM provider your Agent runs on — Terms of Service §6 describe your responsibility for that choice.

5. Data recipients and processors

We use a short list of providers — the full, current list and their roles are set out in the “Data Recipients and Processors” document. Google/Firebase, Amazon Web Services EMEA SARL, PostHog and RevenueCat process data on our behalf. Paddle, Apple and Google act as independent controllers in relation to web payments, the App Store and Google Play respectively, under the terms of their own services. None of these providers receives Entry contents in plaintext — server-side processing is limited to ciphertext and Entry contents are never placed in file storage as plaintext.

Data may also be disclosed to competent authorities where the law requires — within the scope of the request and after verifying its basis. Due to the zero-knowledge architecture, we are unable to hand over Entry contents in plaintext.

Amazon SES (Amazon Web Services, EU region — Ireland) handles transactional e-mail: e-mail address verification, security alerts, account notifications and legal delivery. Send data includes the e-mail address, display name, notification content, and delivery, bounce and complaint events. The channel is not used for marketing without a separate legal basis.

Firebase Cloud Messaging processes the device token and payload required to deliver a notification on the web, Android and iOS. For Apple devices, the message is subsequently delivered through Apple Push Notification service (APNs). The payload contains the event category, an opaque notification identifier, and the notification title and body. Depending on the event, the title or body may contain an Agent name, the name of the person taking the action, an Entry name or a Vault name. The payload does not contain Entry contents, passwords, keys or other secrets. Notification content may be visible on the lock screen according to the device settings.

The Paddle entity identified at checkout — Paddle.com Market Limited for most buyers outside North America, Paddle.com Inc. for US buyers, or Paddle.com (Canada) Ltd. for Canadian buyers — acts as the seller to the buyer and Merchant of Record for web payments and as an independent controller of billing data. Apple App Store and Google Play act as sellers or platform operators for mobile purchases and as independent controllers. RevenueCat synchronizes subscription entitlements across channels as our processor. These entities do not receive Entry contents or encryption keys.

6. Transfers outside the EEA

The infrastructure storing data runs in AWS eu-west-1 (Ireland, EU), and PostHog uses EU Cloud. RevenueCat operates in the USA; Google, Apple, Paddle, PostHog and AWS may engage group entities or further providers outside the EEA. Depending on the flow, transfers rely on an adequacy decision (including the EU–US Data Privacy Framework) and/or Standard Contractual Clauses (SCC), with supplementary measures (encryption in transit and at rest). Per-provider details are in “Data Recipients and Processors”.

Information on the mechanism applicable to a particular transfer, a copy of the applicable SCCs and a summary of the transfer impact assessment may be obtained at patryk.roguszewski@palladin.io. Documents may be redacted or limited as necessary to protect other persons’ data, trade secrets and system security.

7. Retention

DataPeriod
Account Data and Vault Datauntil account deletion; after deletion, data is erased promptly, no later than within 30 days (backups: up to 90 days)
Audit logFree Plan: 30 days; paid Plans: for the period stated in the Price List or agreement, no longer than the agreement term, and afterwards only until claims become time-barred or a legal obligation has been fulfilled
Push tokens and payloadstoken until logout, deregistration, expiry or account deletion; the payload is provided to the delivery providers solely for delivery and may be temporarily retained under FCM/APNs rules
Subscription and billing datafor the subscription term and then for the period required by tax, accounting and limitation laws
E-mail delivery events90 days after the event, unless longer storage is necessary to investigate an incident or defend a claim
E-mail suppression listuntil delivery capability is reconfirmed or the account is deleted, whichever occurs first; longer only where required for security or by law
Analytics eventsno longer than 24 months after collection; withdrawal stops further consent-based collection and use, and erasure requests are handled under Article 17 GDPR
Complaint correspondenceuntil claims are time-barred

8. Your rights

You have the right to: access and obtain a copy of your data, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent at any time (without affecting prior lawful processing).

Send requests to patryk.roguszewski@palladin.io. We respond within one month. You can delete your account and its data directly in the application or by submitting an e-mail request.

Technical limits of zero-knowledge. We cannot “recover” or disclose the contents of your Entries in plaintext — even at your request — because we do not know them. The only way to obtain a copy of Entry contents is to export them from an unlocked Vault on your device.

You have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO) (ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl) or your local supervisory authority.

9. Security

Our measures include: on-device encryption of Entry contents (Argon2id, X25519, XSalsa20-Poly1305 — libsodium), TLS in transit, Agent API keys stored only as SHA-256 digests, an append-only audit log, and a strict no-secrets rule for telemetry and logs. Architecture details: Palladin security documentation.

10. Cookies and similar technologies

The use of cookies, localStorage and analytics is described in the Cookie Policy.

11. Changes to this policy

We will announce material changes in the Service or by e-mail. The change history is available in the public legal changelog.