Français · English

Privacy Policy

Applies to the PasseMots service, the web application and the browser extension (Chrome, Edge, Firefox). Version of 7 August 2026.

In one paragraph. PasseMots is a zero-knowledge secrets manager: your vault is encrypted and decrypted inside your browser, with a key derived from your master password, which we never receive. The server only holds encrypted data it cannot read, plus the minimum needed to run your account: your email address, your organisation and a few dates. Nothing is sold, nothing is used for advertising, and the extension contains no tracker.

1. Data controller

PasseMots is published and operated by E2PZ, reachable at contact@e2pz.app. Send any request about your data to that address.

2. Data we collect

We collect only the following. This list is exhaustive.

2.1 Account data

DataSourceWhy
Email addressYou, on sign-up or when accepting an invitationIdentify your account, send you service emails
First and last name (optional)YouShow you under a readable name to other members of your organisation
Organisation, role, statusYour administratorDetermine what you can access
Last login date, failed login attemptsGeneratedAccount security, abuse detection

2.2 Authentication data and keys

Your master password is never sent to us. Your browser derives two distinct values from it locally (Argon2id): an authentication proof, which the server stores hashed again, and an encryption key that never leaves your device. The server therefore holds: that hashed proof, the derivation parameters, your public key, and your private keys already encrypted by your browser. None of these values can recover your master password or read your vault.

2.3 Your vault contents

Credentials, passwords, notes, files and anything you share are stored end-to-end encrypted. The server handles them as opaque blobs: it knows neither their content, nor the names you give them, nor the sites they relate to. It does know unavoidable technical metadata: how many items exist, their type (password, note, file), their size, their creation and modification dates, and which members a share was created for.

2.4 Technical data

2.5 Data the extension keeps on your device

This data is never sent to our servers. It stays in your browser's local storage, and uninstalling the extension erases it.

3. How we use this data

We perform no profiling, no automated decision-making, no advertising, and your data trains no model.

4. Where and how long we store it

5. Who we share it with

We do not sell, rent or trade any data. We pass data to a third party only in these cases:

RecipientData passedReason
Mailjet (Sinch, France)Recipient email address and message contentDeliver invitation and share-notification emails. These messages never contain a secret or a key.
Members of your organisationWhat you explicitly share with them, plus your name and email addressMake internal sharing possible. You decide on every share.
The recipient of an external linkThe content you chose to shareThe link itself carries the decryption key; we cannot read that content.
A legally competent authorityAccount data, and encrypted data onlyA legal order we are bound to comply with.

The browser extension communicates with no third party. Its only network destination is https://passemots.e2pz.app, your account's API. It embeds no tracker, no ad network and no analytics. Our public marketing pages use analytics we host ourselves, without cookies and without any personal identifier; it covers neither the application nor the extension.

6. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, object and port your data. In practice:

7. Security

A direct consequence of zero-knowledge: if you lose your master password, we cannot reset it or recover your vault. That is the price of guaranteeing that nobody but you can read your data.

8. Browser extension: permissions and limited use

In accordance with the Chrome Web Store Limited Use policy: data collected by the extension is used solely to provide the user-facing feature; it is not sold, not transferred to third parties, not used for advertising, not used for creditworthiness or lending purposes, and no human reads it, except with your explicit consent, to comply with the law, or where necessary for security.

9. Children

The service is intended for professional use and is not directed at people under 16. We do not knowingly collect their data.

10. Changes

Any substantial change to this policy is published on this page with an updated version date and signalled to the administrators of the organisations concerned.