1. Introduction
Worthy Tech LLC ("Worthy Tech," "we," "us," or "our") develops WorthyID, an offline-first password manager, and operates this marketing website. WorthyID is a product of Worthy Tech LLC, a Wyoming-based company.
This Privacy Policy explains our data practices for the WorthyID application and this website. It is designed to meet platform requirements for Apple, Google, and Microsoft app stores, and to comply with applicable privacy laws including the CCPA/CPRA and GDPR where applicable.
2. WorthyID Application
2.1 Data Stored Locally (Encrypted)
WorthyID stores all vault data locally on your device in an encrypted SQLite database (vault.db). This includes:
- Login credentials, credit cards, secure notes, identities, and other item types
- Encrypted record blobs (AES-256-GCM) — no plaintext titles or usernames on disk
- File attachments you add to items — encrypted inside the item blob; decrypted only on-demand to a local cache folder when you open or share them, never transmitted
- KDF parameters, wrapped vault keys, and quick-unlock protector metadata
- App settings in
settings.jsonbeside the vault
Worthy Tech has no access to this data. It never leaves your device except through actions you explicitly initiate (backup export or optional cloud sync).
2.2 Optional Cloud Sync (.widsync)
If you enable cloud sync, WorthyID writes an encrypted .widsync file to a folder you choose (e.g., Dropbox, Google Drive, OneDrive, iCloud). This file contains only ciphertext and cryptographic metadata. Worthy Tech does not host, access, or control this file — it resides entirely in your own cloud storage account.
2.3 Biometric and Quick-Unlock Data
Biometric unlock (Face ID, Touch ID, Windows Hello, Android BiometricPrompt) is processed entirely on your device by your operating system. PIN, swipe pattern, and passkey secrets are stored in platform secure storage (e.g., DPAPI on Windows) and never transmitted to Worthy Tech.
2.4 What the App Does Not Collect
- No accounts or user registration within the app
- No network calls to Worthy Tech servers by default
- No analytics, telemetry, crash reporting SDKs, or advertising
- No third-party data sharing of any kind
2.5 Browser Extension
The optional Chrome/Edge/Brave browser extension communicates with WorthyID via a local native-messaging host on your machine. Credentials are exchanged only between the extension and the local app — not over the internet to Worthy Tech.
2.6 Optional Device Access — Contacts, SMS, and Camera
WorthyID can import data from your device only when you explicitly choose to, and only after you grant the corresponding operating-system permission. These features are opt-in and the app works fully without them.
- Contacts (
READ_CONTACTS): When you open contact import and grant permission, WorthyID reads your address book so you can pick which contacts to save as encrypted Contact items. Only the contacts you select are stored. - SMS messages (
READ_SMS, Android only): When you open Text Messages import and grant permission, WorthyID reads SMS threads so you can pick which conversations to archive as encrypted Text Thread items. Only the threads and messages you select are stored. iOS does not expose message history to apps, so this feature is Android-only. - Camera (
CAMERA): Used solely to scan TOTP/2FA QR codes when you initiate a scan. No images are stored or transmitted.
3. This Website
3.1 Launch Notification Signups
If you sign up for launch notifications on this website, we collect your email address, signup date, and source page. We use this solely to notify you about WorthyID availability. You may unsubscribe at any time by contacting us.
3.2 Website Logs
Our web hosting infrastructure may log standard request data (IP address, browser type, pages visited) for security and operational purposes. This does not include any WorthyID application data.
4. Data Deletion
App data: You may delete all vault data at any time from Settings → Delete All Data, which requires your master password and wipes the local vault, settings, and unlock methods. The optional .widsync file in your cloud folder is not automatically deleted.
Website signups: Submit a deletion request via our contact form with subject "WorthyID — Delete My Email."
5. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, or port personal information we hold about you (limited to website signup data). California residents may submit a "Privacy Request" via our contact form. We do not sell personal information.
6. Children's Privacy
WorthyID is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children.
7. App Store Privacy Disclosures
For store privacy nutrition labels and data safety forms:
- Data collected by the app: None transmitted to the developer
- Data stored on device: Encrypted vault contents (user-controlled, not accessible to Worthy Tech)
- Device permissions requested: Contacts and SMS (Android) for opt-in local import; Camera for TOTP QR scanning; Biometrics for unlock — all processed on-device, none transmitted
- Data linked to you: None (no accounts)
- Tracking: None
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised "Last updated" date.
9. Contact Us
- Worthy Tech LLC (WorthyID)
- Wyoming, United States
- Contact: worthytech.net/contact
- Privacy requests: subject line "WorthyID Privacy Request"