Security
Last updated 7 September 2026
How PasserJack protects your content, where the protection ends, and the controls you can use.
Choose the protection your content needs
The Board keeps everyday content accessible for search, previews and sharing. The service can read Board content. The Vault encrypts saved content under keys protected by your devices and recovery code. Putting something on the Board does not give it Vault protection.
Vault bodies, files and thumbnails use AES-256-GCM encryption. Titles, notes, tags, filenames, item kind, file sizes and activity metadata remain readable by the service. Use labels that do not disclose the sensitive content they describe.
When content reaches the server
Browser vault captures are encrypted before upload. API, agent and some device capture paths send plaintext to the server, which encrypts it to the vault's public key before storing it. If your requirement is that plaintext never reaches the server during capture, use a device-encrypted capture path.
An explicit Unlock for agents window temporarily gives the server a derived read key. The selected duration is 15 minutes, 1 hour or 8 hours. Only authorized credentials with Read my vault permission can use it; reads are recorded in your vault read history. Close the window when the task is done.
A recipient you share with, or an agent you authorize, can keep a copy of content it receives. Expiry, revocation and key rotation restrict future service access; they cannot erase a copy already obtained.
Account and device access
Sign-in uses a verified Google account. API keys and connected applications have scoped permissions, and device credentials can be revoked. Review Devices, API keys and Connected apps in account settings when a device is lost or access is no longer needed.
Trusted vault devices and signed-in sessions are separate. A Google sign-in does not supply the key needed to decrypt your vault. A new device needs approval from a trusted device or your recovery code.
A trusted browser normally keeps its device key in local browser storage. Enabling a passphrase on that device stores the key wrapped under the passphrase and keeps an unlocked key in page memory only. Reloading requires the passphrase again, and this setting requires a connection to unlock. Device encryption does not protect content from malicious software or someone using an already-unlocked device.
Links, QR codes and encrypted sharing
Public links give access to whoever holds them. Specific people and Trusted contacts links also require an allowed signed-in account. The sender can see when a signed-in recipient opens a restricted link. Choose the audience before sharing and revoke links you no longer need.
A one-click Vault link carries decryption information in the complete URL and currently supports text content. Treat that link as a secret. To share encrypted content with another account on an ongoing basis, use Vault sharing permissions. Removing that access queues affected content for key rotation on an unlocked owner device.
QR handoff links are signed, expire after ten minutes and cover one eligible item. Anyone holding a valid handoff link can use it without signing in. The QR format does not add encryption or identify the person scanning it.
Notifications, analysis and local data
Notifications can display Board content snippets or plaintext Vault labels on your device's lock screen. Adjust operating-system notification previews if those labels should remain private.
Eligible Board images may be sent to OpenAI for descriptions and text extraction when image analysis is enabled. Vault images are excluded. Turn analysis off in Settings, then Privacy, to delete existing results and stop queued analysis.
Ordinary offline captures and the local share inbox store plaintext on this device. New browser Vault captures are encrypted before they are saved to the prepared offline queue. Without usable Vault keys, a draft may remain only in the open page and is not a durable save. Older plaintext Vault drafts can remain from previous versions until their verified owner recovers or discards them; they are not silently sent as ordinary content. Encrypted replay rechecks the current account, device and keyset online. Clearing site data or browser storage eviction can remove unsent content and trusted-device keys; keep important originals and your recovery code separately.
Recovery and deletion
Keep your vault recovery code somewhere secure outside PasserJack. It can authorize a replacement device. Support cannot reconstruct lost vault keys, and a database backup does not replace a recovery code.
Deleting content removes its active records and initiates storage cleanup. Copies in downloads, recipient devices or backups may remain, and provider errors can delay object removal. Keep independent copies of important content; PasserJack does not promise recovery of deleted items.
Report a security concern
Contact PasserJack support with a description of the issue, affected page or feature, and steps to reproduce it using your own account. Do not include live access tokens, recovery codes or another person's data.
If you believe your account is exposed, revoke affected devices and connected applications, close any agent unlock window, and secure your Google account. A security report does not itself revoke access.
Need help? Contact PasserJack.