This policy is for the Android app Data Guardian
(package com.mekanix.passman), published by ToolsForTheMasses.
Last updated: 18 August 2026.
Contact: cezar.lucan@gmail.com. Account and data deletion: Data Guardian account deletion.
Data Guardian is a password manager. Your vault (logins, notes, and similar items) is stored on the phone in an encrypted database. A PIN and optional biometrics lock the app locally. They are not an online account.
Cloud Backup and Time Capsule are optional. You can use the app without signing in and without sending data off the device.
Unless you use Cloud Backup or Time Capsule, this stays on the phone:
We do not have access to the contents of a locked vault. Photos taken with the camera (if you use that feature) are stored in the local vault, not sent to us.
If you sign in with Google for Cloud Backup and/or Time Capsule, the following may leave the device. None of this is required to use the local vault.
The Google account id from Sign-In (the sub value) is stored on the
Time Capsule server so we can recognise the same Google account on another phone.
A device identifier (Android ID, or a generated id if Android ID is unavailable) is sent to the Time Capsule server. The first phone for a Google account becomes the canonical device id. A later phone signed in with the same Google account keeps that original id and inherits existing capsules.
PassmanBkps).INSTRUCTIONS.txt file (including the capsule password) are uploaded to your Drive (for example under PassmanTimeCapsule). File ids are stored on the Time Capsule server.
The live Database Key for the open vault is not uploaded. The capsule uses a
separate password written only into INSTRUCTIONS.txt until share time.
App functionality and account management only: optional Google sign-in, Drive backup, and Time Capsule (including identifying the owner across devices).
Vaults on the device use encrypted database storage. Google Drive transfers use HTTPS. If you point Time Capsule at an HTTP server URL, metadata sent to that server (email, user id, device id, file ids, recipient list) is not encrypted in transit. Use HTTPS for that server if you need encryption in transit.
You are responsible for Database Keys, PIN, capsule passwords, and who you name as Time Capsule recipients.
Data Guardian is not directed at children under 13. We do not knowingly collect data from children.
You can:
PassmanTimeCapsule and PassmanBkpsUninstalling the app does not by itself delete Drive files or Time Capsule server records.
If this policy changes in a material way, we will update the date above. Continued use of Cloud Backup or Time Capsule after an update means you accept the revised policy for those features.