Privacy Policy

Your sensitive information deserves clear boundaries.

Passwordic is designed to help individuals and organizations manage credentials and sensitive records while keeping personal accounts, company workspaces, and platform administration separated. This policy explains the information Passwordic processes, why it is needed, and the security controls used to protect the service.

1. Scope

This Privacy Policy applies to the Passwordic website, Passwordic application, Personal accounts, Business workspaces, authentication and security functions, and related support interactions. Passwordic is a WizSpeed product.

2. Information you provide

Depending on how you use Passwordic, we may process information such as your name, email address, account type, company or workspace information, profile information, security preferences, and information you intentionally add to Passwordic. The product includes functionality for storing and managing password-vault entries and may also support sensitive records such as security keys, credit-card records, documents, medical records, subscriptions, and related account information.

You decide what information you place in your Passwordic workspace. Do not send passwords, MFA recovery codes, private keys, or other authentication secrets to Passwordic support through ordinary email.

3. Authentication and security information

To authenticate users and protect accounts, Passwordic may process login timestamps, IP addresses, browser or user-agent information, failed-login attempts, account-lock status, MFA configuration state, recovery activity, and authentication/security events. This information is used for authentication, abuse prevention, troubleshooting, account recovery, auditing, and security monitoring.

4. Personal and Business account boundaries

Passwordic separates Personal accounts from Business workspaces. Business users operate inside a company tenant, and administrative actions are scoped to that tenant. Tenant administrators can manage authorized users in their own organization, including roles, account status, recovery or unlock actions, and company security policies. A company administrator does not receive platform-wide administrative authority simply by being an administrator of its workspace.

Credential sharing is also bounded by account context: Business sharing is restricted to authorized users in the same active tenant, while Personal sharing is kept within the Personal account context. These boundaries are intended to reduce accidental cross-organization exposure.

5. How we use information

We process information to provide and maintain Passwordic; authenticate users; operate vault, sharing, workspace, and administrative functionality; enforce permissions and security policies; detect and investigate suspicious activity; recover or protect accounts; provide support; diagnose reliability issues; improve the service; communicate service-related information; and comply with applicable legal obligations.

6. Security architecture and safeguards

Passwordic uses layered application controls intended to protect accounts and reduce unauthorized access. Current controls include account-scope separation, tenant isolation, role-based access controls, MFA capabilities, company-level MFA enforcement, configurable failed-login lockouts, authentication auditing, server-side authorization checks, controlled account recovery, and restrictions on sharing across security boundaries.

Passwordic also maintains a distinct platform-administration scope separate from Personal and Business users. Administrative privileges are not intended to be inferred merely from a selected login portal; the service determines access from the authenticated account's actual scope and permissions.

Security is a continuous process. We work to maintain reasonable technical and organizational safeguards appropriate to the service, but no online service, encryption method, hosting environment, or security control can guarantee absolute security or prevent every possible compromise.

7. Passwords and authentication secrets

Your Passwordic account password is used for authentication and should never be disclosed to unauthorized persons. Passwordic may support MFA and recovery mechanisms to strengthen account access. Users are responsible for safeguarding recovery information and devices used to authenticate. Where Passwordic stores information that you intentionally place in a vault, access is governed by authenticated sessions and applicable authorization controls.

8. Business administrators

If your account belongs to a Business workspace, authorized administrators for that organization may manage workspace membership and security-related account settings and may have access to company-scoped information according to their assigned role. Your organization is responsible for deciding who receives administrative privileges and for using those privileges appropriately.

9. Service providers and infrastructure

Passwordic may use third-party infrastructure, hosting, authentication, email, monitoring, payment, or other operational providers where needed to deliver the service. Those providers may process limited information on our behalf according to the service being provided. Passwordic does not authorize service providers to use customer information for unrelated purposes merely because they support our infrastructure.

10. Social and third-party authentication

If you choose an available third-party sign-in method, the relevant provider may send Passwordic account-identification information needed to authenticate you. The provider's own privacy practices also apply to information it processes. Passwordic does not require you to disclose your third-party account password to Passwordic when using standards-based provider authentication.

11. Billing information

Business plans may require billing information when paid billing is activated. Payment information may be processed by a payment provider rather than stored directly by Passwordic. The specific payment provider's privacy and security terms apply to information submitted directly to that provider.

12. Cookies and sessions

Passwordic may use cookies, session identifiers, and similar technologies that are necessary for authentication, account security, preferences, and reliable operation of the website and application. Security-related cookies and sessions help maintain authenticated state and reduce unauthorized access.

13. Data retention

We retain information for as long as reasonably necessary to provide the service, maintain account and security records, meet legitimate operational needs, resolve disputes, enforce agreements, and satisfy applicable legal requirements. Retention periods can vary by data type. Security and audit records may be retained differently from active account content.

14. Account deletion and privacy requests

Subject to applicable law, users may contact us regarding access, correction, deletion, or other privacy questions concerning their information. Business users should understand that some company-workspace information may also be controlled or retained by their organization. Certain records may be retained when reasonably necessary for security, fraud prevention, legal compliance, dispute resolution, or enforcement of agreements.

15. Children

Passwordic is not intended for children to create accounts independently where parental or guardian consent is required by applicable law. Organizations using Passwordic are responsible for ensuring that their authorized users meet applicable eligibility requirements.

16. International processing

Passwordic and its service providers may process information in locations different from where a user resides. Where applicable, we take reasonable steps to handle information consistently with this policy and applicable data-protection requirements.

17. Future features

Passwordic's public roadmap may describe planned capabilities such as single sign-on, SAML or OIDC integrations, SCIM provisioning, directory integrations, APIs, webhooks, and additional enterprise controls. Roadmap features are not treated as current functionality until they are actually released. This policy will be updated when new functionality materially changes how information is processed.

18. Changes to this policy

We may update this Privacy Policy as Passwordic changes. Material updates will be reflected by revising the effective date and, when appropriate, providing additional notice through the service.

19. Contact

Privacy and data-handling questions can be sent to info@passwordic.com.

Security transparency: Passwordic describes security controls as safeguards, not guarantees. No legitimate online service can promise that a system is impossible to compromise.