Palladin Privacy Policy
Polish version: Polityka Prywatności — the Polish version is legally binding; this English version is provided for convenience.
1. Controller
Patryk Roguszewski IT Solutions — the business name of Patryk Roguszewski, a sole trader registered in Poland’s Central Register and Information on Economic Activity (CEIDG), Tax ID (NIP) 8241804773, REGON 366380826 — is the controller of personal data (“we”, “Palladin”). Service address: ul. Szkolna 11G/1, 05-091 Ząbki, Poland. Contact — including all data-protection matters: patryk.roguszewski@palladin.io, tel. +48 517 777 441.
Where an organization (a B2B customer) enters data concerning its employees or systems into the Service, we act as a processor under a data processing agreement (Art. 28 GDPR), and that organization is the controller.
2. Two categories of data: Account Data and Vault Data
Palladin is built on a zero-knowledge architecture: the contents of your Entries are encrypted on your device before they reach our servers.
| Account Data (visible to us) | Vault Data (invisible to us) | |
|---|---|---|
| What it covers | e-mail, display name, language, organization, salt and authentication verifier derived client-side from the Master Password, Plan and subscription status, Entry metadata (name, description, icon, type, domain, timestamps), the audit log, public keys and wrapped private keys | Entry contents: usernames, passwords, API keys, notes, URLs, TOTP secrets, scripts, fields marked as concealed |
| How it is stored | in plaintext or encrypted server-side | solely as ciphertext (XSalsa20-Poly1305); keys derived from your Master Password (Argon2id) exist only on your device |
| Can we access it | yes — to the extent necessary to provide the Service | no — we do not know your Master Password, Recovery Key or encryption keys, and we are unable to decrypt Entry contents |
Encrypted Vault Data remains personal data under the GDPR (pseudonymisation); client-side encryption is our security measure under Art. 32 GDPR.
3. What we process, why, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Account creation, authentication and providing the Service | e-mail, name, language, organization, salt and authentication verifier; wrapped cryptographic keys; encrypted Entries and their metadata | Art. 6(1)(b) GDPR (contract) |
| Plan, subscription and billing administration | Plan, subscription status, customer and transaction identifier at the operator, billing country and currency; billing data supplied to the operator | Art. 6(1)(b) and (c) GDPR (contract and tax/accounting obligations) |
| Security, accountability, abuse prevention | audit log (who, what, when — including Entry names, Agent name and stated reason), IP address and hostname of an Agent’s last connection | Art. 6(1)(f) GDPR (legitimate interest: service security and accountability of secret access) |
| Notifications about events requiring a decision | push token, device platform and device name or browser-client identifier, event category, opaque notification identifier, and notification title and body; depending on the event, the message may contain an Agent name, the name of the person taking the action, an Entry name or a Vault name — never Entry contents, passwords, keys or other secrets | Art. 6(1)(b) GDPR |
| Transactional and legal e-mail delivery | e-mail address, display name, notification content, delivery/bounce/complaint events | Art. 6(1)(b), (c) and (f) GDPR (contract, legal obligation, delivery security and effectiveness) |
| Product analytics | app usage events (user identifier, event type, technical properties — never Entry contents, never secrets) | consent (Art. 6(1)(a) GDPR) — see the Cookie Policy |
| Complaints and requests | correspondence, account data | Art. 6(1)(b) and (c) GDPR |
| Handling notices concerning illegal content, appeals and DSA obligations | notifier contact details, notice contents and attachments, statement of reasons, correspondence | Art. 6(1)(c) GDPR (legal obligation) and Art. 6(1)(f) GDPR (defence of claims and Service security) |
Providing Account Data (the e-mail address and data required for authentication) is voluntary but is a condition of concluding and performing the agreement — without it we cannot create an account or provide the Service. Providing data required by the payment operator is a condition of purchasing a paid Plan. Analytics consent is entirely voluntary and refusing it does not limit your use of the Service.
The Service is intended solely for persons aged 18 or over. We do not knowingly create accounts for minors.
We do not profile users, make automated decisions producing legal effects, or sell data.
4. Data visible to AI Agents
By deliberate product design, AI Agents enrolled in your organization can see — without approved Access — the public metadata of Entries: name, description, domain, and fields the Entry owner has explicitly marked as agent-visible. This lets Agents locate the right Entry and request Access. Entry contents are never visible without approved Access; they are delivered one Entry at a time, encrypted to the specific Agent’s key. Do not put personal data or secrets into Entry names or descriptions.
If you use the get mode (returning a secret into the Agent’s context), the secret may be transmitted to the LLM provider your Agent runs on — Terms of Service §6 describe your responsibility for that choice.
5. Data recipients and processors
We use a short list of providers — the full, current list and their roles are set out in the “Data Recipients and Processors” document. Google/Firebase, Amazon Web Services EMEA SARL, PostHog and RevenueCat process data on our behalf. Paddle, Apple and Google act as independent controllers in relation to web payments, the App Store and Google Play respectively, under the terms of their own services. None of these providers receives Entry contents in plaintext — server-side processing is limited to ciphertext and Entry contents are never placed in file storage as plaintext.
Data may also be disclosed to competent authorities where the law requires — within the scope of the request and after verifying its basis. Due to the zero-knowledge architecture, we are unable to hand over Entry contents in plaintext.
Amazon SES (Amazon Web Services, EU region — Ireland) handles transactional e-mail: e-mail address verification, security alerts, account notifications and legal delivery. Send data includes the e-mail address, display name, notification content, and delivery, bounce and complaint events. The channel is not used for marketing without a separate legal basis.
Firebase Cloud Messaging processes the device token and payload required to deliver a notification on the web, Android and iOS. For Apple devices, the message is subsequently delivered through Apple Push Notification service (APNs). The payload contains the event category, an opaque notification identifier, and the notification title and body. Depending on the event, the title or body may contain an Agent name, the name of the person taking the action, an Entry name or a Vault name. The payload does not contain Entry contents, passwords, keys or other secrets. Notification content may be visible on the lock screen according to the device settings.
The Paddle entity identified at checkout — Paddle.com Market Limited for most buyers outside North America, Paddle.com Inc. for US buyers, or Paddle.com (Canada) Ltd. for Canadian buyers — acts as the seller to the buyer and Merchant of Record for web payments and as an independent controller of billing data. Apple App Store and Google Play act as sellers or platform operators for mobile purchases and as independent controllers. RevenueCat synchronizes subscription entitlements across channels as our processor. These entities do not receive Entry contents or encryption keys.
6. Transfers outside the EEA
The infrastructure storing data runs in AWS eu-west-1 (Ireland, EU), and PostHog uses EU Cloud. RevenueCat operates in the USA; Google, Apple, Paddle, PostHog and AWS may engage group entities or further providers outside the EEA. Depending on the flow, transfers rely on an adequacy decision (including the EU–US Data Privacy Framework) and/or Standard Contractual Clauses (SCC), with supplementary measures (encryption in transit and at rest). Per-provider details are in “Data Recipients and Processors”.
Information on the mechanism applicable to a particular transfer, a copy of the applicable SCCs and a summary of the transfer impact assessment may be obtained at patryk.roguszewski@palladin.io. Documents may be redacted or limited as necessary to protect other persons’ data, trade secrets and system security.
7. Retention
| Data | Period |
|---|---|
| Account Data and Vault Data | until account deletion; after deletion, data is erased promptly, no later than within 30 days (backups: up to 90 days) |
| Audit log | Free Plan: 30 days; paid Plans: for the period stated in the Price List or agreement, no longer than the agreement term, and afterwards only until claims become time-barred or a legal obligation has been fulfilled |
| Push tokens and payloads | token until logout, deregistration, expiry or account deletion; the payload is provided to the delivery providers solely for delivery and may be temporarily retained under FCM/APNs rules |
| Subscription and billing data | for the subscription term and then for the period required by tax, accounting and limitation laws |
| E-mail delivery events | 90 days after the event, unless longer storage is necessary to investigate an incident or defend a claim |
| E-mail suppression list | until delivery capability is reconfirmed or the account is deleted, whichever occurs first; longer only where required for security or by law |
| Analytics events | no longer than 24 months after collection; withdrawal stops further consent-based collection and use, and erasure requests are handled under Article 17 GDPR |
| Complaint correspondence | until claims are time-barred |
8. Your rights
You have the right to: access and obtain a copy of your data, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent at any time (without affecting prior lawful processing).
Send requests to patryk.roguszewski@palladin.io. We respond within one month. You can delete your account and its data directly in the application or by submitting an e-mail request.
Technical limits of zero-knowledge. We cannot “recover” or disclose the contents of your Entries in plaintext — even at your request — because we do not know them. The only way to obtain a copy of Entry contents is to export them from an unlocked Vault on your device.
You have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO) (ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl) or your local supervisory authority.
9. Security
Our measures include: on-device encryption of Entry contents (Argon2id, X25519, XSalsa20-Poly1305 — libsodium), TLS in transit, Agent API keys stored only as SHA-256 digests, an append-only audit log, and a strict no-secrets rule for telemetry and logs. Architecture details: Palladin security documentation.
10. Cookies and similar technologies
The use of cookies, localStorage and analytics is described in the Cookie Policy.
11. Changes to this policy
We will announce material changes in the Service or by e-mail. The change history is available in the public legal changelog.