Last updated: June 26, 2026
This Privacy Policy describes how Cerberus Password Manager (hereinafter, "the Application") handles user information and data. Cerberus is a high-security password manager designed under a "local-first" philosophy.
1. Data Collection and Use (Local-First Storage)
Cerberus does not collect, store, monitor, or share any personal information, credentials, passwords, or browsing data on external servers owned by us.
All information you enter into the Application (usernames, passwords, URLs, notes, and categories) is stored exclusively in your mobile device's internal storage, within a local database strongly encrypted end-to-end using the AES-256 protocol (SQLCipher). Decryption of this data takes place strictly at runtime on your own hardware, and only after validating your Master Password or your operating system's biometric credentials.
2. App Permissions and Third Parties
To provide its advanced security features, the Application requires the following native permissions, each of which runs in a fully isolated manner:
Biometric Authentication ("local_auth"): Used exclusively to verify the user's identity on the device (fingerprint or facial recognition) in order to unlock the local vault. We have no access to your biometric data, which is securely managed by your operating system's hardware.
Internet Access: Required only for two specific functions explicitly requested by the user:
Downloading and locally caching website logos (favicons) directly from the service's official domain, with no intermediaries or telemetry logging.
The optional backup flow.
In-App Purchase Validation: Network access is strictly necessary to securely and anonymously connect to the app store's official billing services (Google Play Billing API). This process is carried out locally on the device to verify payment status or activate purchased Premium features, without collecting or storing any banking data on the developer's servers.
3. Synchronization and Backups (Google Drive API)
The Application offers an optional cloud backup feature using the official Google Drive API:
Use of a restricted scope (appDataFolder): Cerberus interacts solely and exclusively with Google Drive's restricted application data folder (drive.appdata). The Application does not request, collect, or have access to any other file, document, photo, or personal folder stored in the user's Google Drive account.
Efficient, Automated Synchronization: Once the user enables and signs in to this feature for the first time, the Application automates backups by securely uploading the encrypted file to Google Drive whenever a change or update is detected in the local vault. The user can also manually force an upload or download at any time from the settings menu.
State-of-the-Art Security and Encryption: All information exported or backed up outside the local vault is processed under the strictest information security standards. For optional cloud backups (Google Drive), the Application transfers the database file protected using SQLCipher's native encryption (AES-256 and PBKDF2 with 600,000 iterations). For manual exports to local files (such as the .cjson format), an independent layer of protection is applied using the AES-256-GCM protocol with key derivation via Argon2id. Under no circumstances does Cerberus's developer have intermediary servers, interception channels, or the technical capability to access, read, or decrypt your data.
Cerberus's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Data Security
To protect your visual privacy and prevent passive information leaks, the Application implements the operating system's native security flag (FLAG_SECURE). This strictly prohibits screenshots and screen recordings within the app, and completely hides the interface content in your device's recent apps (multitasking) menu. Additionally, Android's automatic system backup has been disabled (allowBackup="false") to prevent uncontrolled backups by the operating system.
5. Changes to this Privacy Policy
We reserve the right to update this Privacy Policy in future versions of the Application to reflect technical improvements or changes. Any substantial change will be communicated transparently within the Cerberus interface itself.
6. Contact
If you have questions about Cerberus's local operation and privacy practices, you can contact us at: cerberus.keypass@gmail.com