Repass

Privacy Policy

Repass reads your email to find the accounts you have, and changes their passwords for you. This page says exactly what that involves, what leaves your device, and who else sees any of it.

Effective 13 August 2026

What we collect

Your Google account identity. When you sign in with Google we receive your email address and a Google account identifier. We use them to know whose vault is whose.

Email metadata and subject lines. To work out where you have accounts, Repass reads the sender address and subject line of messages in your mailbox.

The body of a verification email, in two narrow cases. When Repass has just triggered a password reset, it reads that message to extract the link or code. And when you are signing in somewhere yourself and click "Fill the code from your email", it reads the most recent verification message from that site. The second only ever happens on your click — Repass does not read your mail because a code box appeared on a page — and the search is bounded to the minutes around your request, so an older code cannot be found or filled.

Encrypted vault contents. Your passwords, usernames and the sites they belong to are encrypted on your own device before they reach us. We receive and store ciphertext.

Page structure during a reset. While a reset runs, Repass reads the page it is working on: the address, the title, a short excerpt of visible text, the labels of buttons and links, and which form fields exist and what kind they are.

Operational records. Job status, timestamps, error messages and per-day usage counts, so resets can be retried and abuse can be limited.

What we do not collect

We do not collect your master password. It never leaves your device and we could not accept it if you sent it: the vault key is derived from it locally.

We do not collect your browsing history. The Chrome extension counts how often you visit sites you already have an account with, so it can put the ones you use most at the top of your own list. Those counts stay in the browser and are never transmitted. The optional browser-history permission, if you grant it, is read once on your machine and handed straight back.

We do not read, send, delete or alter your mail beyond what is described above, and we never send email from your address.

Gmail access, stated precisely

Repass currently requests the gmail.modify scope. Read-only access is all the product needs and all it uses, but Google grants scopes against a project's approved list, and read-only is not on ours yet. The broader scope is a constraint we are working to remove, not a capability we exercise: nothing in Repass sends, deletes, or alters anything in your mailbox.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide and improve the features you can see in Repass; it is not transferred to others except as necessary to provide those features, for security, or to comply with law; it is never used for advertising; and no human reads it except with your explicit consent, for security purposes, or where required by law.

Where your passwords live, and why we cannot read them

Every password Repass generates is encrypted on your device with a key derived from your master password. What reaches our servers is a sealed blob. We do not hold the key, we cannot derive it, and we cannot decrypt your vault.

This is not a policy choice we could reverse for you. If you lose both your master password and your recovery phrase, your vault cannot be recovered by us, by a support request, or by a court order. That is the trade the design makes deliberately.

Who else receives your data

Anthropic. Repass uses Anthropic's Claude models to decide which senders indicate a real account, which message is the reset email you are waiting for, and what to do next on a page. This means the following is sent to Anthropic: email sender addresses and subject lines; the sender, subject and extracted links of a reset email; and the address, title, a text excerpt and visible button labels of pages a reset runs on.

Links and verification codes are masked before they are sent: a reset token is replaced with bullet characters and the model selects a link by position rather than by reading it. Your passwords, your master password, live reset tokens and verification codes are never sent to Anthropic.

Google Cloud. Our servers, database and authentication run on Google Cloud and Firebase.

Google's favicon service. To show a site's logo beside each account, Repass requests it from Google. That request reveals to Google which domain it is for, and therefore which sites appear in your list. If you would rather that did not happen, tell us and we will prioritise proxying it ourselves.

We do not sell your data, and we do not share it for advertising.

Every company that touches your data

We use a small number of providers to run Repass. This is all of them:

Google Cloud Platform / Firebase — Hosting, database, authentication. Receives: Encrypted vault blobs, account list, Google account identity, operational records. Processed in United States.

Anthropic — The models that decide which senders are accounts, which message is the reset email, and what to do next on a page. Receives: Sender addresses and subject lines; reset-email sender, subject and masked links; page address, title, text excerpt and button labels. Processed in United States.

Google (favicon service) — Site logos shown beside each account. Receives: The domain of each account in your list, revealed by the request itself. Processed in United States.

All of them process data in the United States. If you are in the UK or the EEA, that means your data is transferred there, under the providers' standard contractual clauses.

Cookies and what is stored in your browser

Repass sets no advertising or analytics cookies, and we run no third-party trackers. The site and the extension store things locally that they need in order to work: your signed-in session, your encrypted vault cache, your generator settings, and the visit counts that order your own list. Clearing your browser data clears all of it.

Security

Your vault is encrypted on your device before it is transmitted, and everything travels over TLS. Access to production systems is limited to people who need it. Nobody at Repass can read a vault, so the worst case for a breach of our database is the disclosure of which domains you hold accounts with — not the credentials themselves.

If we discover a breach affecting your personal data, we will tell you and the relevant regulator without undue delay, and within 72 hours where the law requires it. Report a vulnerability to privacy@joinrepass.com and we will not take legal action against good-faith research.

How long we keep it

Your encrypted vault and account list are kept while your account exists. Operational records are kept for up to 90 days. Deleting your account deletes your vault, your account list and your stored Google token; we cannot recover them afterwards.

You can revoke Repass's access to your Google account at any time at myaccount.google.com/permissions, independently of anything on our side.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to certain processing. Write to privacy@joinrepass.com and we will respond within 30 days. We will not make you jump through hoops for it, and we will not charge you.

Note the practical limit: we can delete your encrypted vault, but we cannot produce its plaintext contents for an access request, because we cannot read it.

Deleting everything

Disconnect Gmail, in Account settings, stops us reading your mail, deletes your account list and revokes our stored Google token. Passwords already changed stay changed — export your vault first, or you will lose the only copy of credentials you can no longer guess.

For complete erasure, including your encrypted vault, write to privacy@joinrepass.com and we will do it within 30 days. A one-click full delete is not built yet; until it is, we do it by hand rather than claim a button that does not exist.

If you are in California

You have the right to know what personal information we collect and why, to request its deletion, to request a copy, and not to be discriminated against for exercising any of that. Everything above answers the first; privacy@joinrepass.com handles the rest. We have never sold or shared personal information, as California defines those terms, and we do not intend to.

Children

Repass is not intended for anyone under 16 and we do not knowingly collect their data.

Changes

If we change this policy in a way that materially affects what we do with your data, we will tell you before it takes effect. The effective date is at the top.

Contact

Write to privacy@joinrepass.com. A person reads it.