Legal
Last updated September 28, 2026
Montara Pass is zero-knowledge, and this policy is written the same way: plainly. It covers what we collect, what we can never see, and the rights you have.
Montara Pass is built so that your vault is encrypted on your device and can only be decrypted there. Your master password never reaches our servers, and the data we do hold about your account is limited to what is needed to run the Service.
This policy explains what we collect, what we can never see, and the choices you have. The short version: we collect the minimum, we sell nothing, and your vault content is invisible to everyone — including us.
We keep this list short, because keeping it short is the point:
Your vault is encrypted on your device with XChaCha20 using a key derived from your master password. That key is never transmitted, stored, or reconstructable by us.
Practically, this means we cannot see your passwords, passkeys, secure notes, attachments, or vault metadata such as item titles and URLs. If our servers were compromised, an attacker would obtain only encrypted blobs — not your data.
For users in the EU, UK, and Switzerland, we process account and billing data to perform our contract with you (Art. 6(1)(b) GDPR), technical and security data under our legitimate interests in operating a secure service (Art. 6(1)(f)), and optional communications only with your consent (Art. 6(1)(a)), which you can withdraw at any time.
When you delete your account, your account data is removed within 30 days, and it is purged from encrypted backups within 90 days. Your encrypted vault data becomes permanently unrecoverable — by design, there is no copy we can restore.
We keep the minimum data required for tax and fraud-prevention obligations for as long as the law requires, then delete it.
Wherever you live, you can access, correct, export, or delete your personal data from your account settings. If you are in the EU, UK, or California, you additionally have the rights to object to processing, restrict processing, and opt out of any “sale” or “sharing” of personal information — which, for Montara Pass, is moot: we never sell or share personal information for advertising.
To exercise a right or file a complaint, contact privacy@montarapass.com. We respond within 30 days.
Our infrastructure is hosted in the United States and the European Union. Where data is transferred out of the EU or UK, we rely on the European Commission’s Standard Contractual Clauses and equivalent safeguards, and we encrypt data in transit and at rest.
Montara Pass is not intended for children under 16, and we do not knowingly collect their personal data. Families plan administrators are responsible for any supervised vaults they create for younger family members.
If we make a material change to this policy, we will notify you by email or in-app notice at least 30 days before it takes effect, and we will update the date above.
Questions about privacy can be sent to privacy@montarapass.com, or by mail to Montara Labs, Inc., 550 Kearny Street, Suite 400, San Francisco, CA 94108.