Privacy policy

Effective October 3, 2026 · Developer: Zeng Deyang

Your notebook

Titles, accounts, passwords, notes and folders are encrypted on your device using AES-256-GCM before they are synced to your private iCloud database. PassBy has no developer-operated password server, advertising or analytics SDK.

Tenon Account

Tenon manages sign-in methods, verification and account settings. PassBy receives your verified Tenon identifier, display name and platform role to establish a separate session lasting at most 1 minute. These details and the product session are held temporarily in our authentication service memory. Provider passwords and recovery keys are not received by this service. On iPhone, the current product session is kept in the device-only Keychain so it survives closing the app. It is not synced to iCloud, and is removed on sign-out. It expires within 1 minute; expired credentials are cleared when the app next opens or becomes active. Face ID is still required to open the notebook. The role does not grant access to notebook contents. Routine security and request metadata may be retained by the hosting and central account services. Signing out of PassBy ends its session; manage your central account at Tenon Account.

Apple storage and Face ID

Your system iCloud account identifies the notebook. PassBy does not receive your Apple password or facial data. Apple may share identity information with Tenon when you choose Apple as a central sign-in method; this is separate from notebook storage authorization. Face ID is handled by iOS; PassBy receives authentication results, never your facial data.

Keys and recovery

The local encryption key is protected by the device Keychain and current Face ID enrollment. Your recovery key is never uploaded. Save it outside PassBy. Without a working device key or your recovery key, your notebook cannot be decrypted by the developer.

Clipboard and drafts

In the iPhone app, copied values stay on this device and expire after 60 seconds. The app you paste into can read them. Unfinished entries are saved as encrypted local drafts and are not synced to iCloud.

Web access

The web app connects directly to Apple CloudKit for your private notebook. Your recovery key is used by WebCrypto in the browser and is not sent to our hosting server or Apple. Notebook data is decrypted in page memory; The recovery phrase, notebook contents and unfinished edits are not saved to browser storage. Authorizing a browser saves a non-exportable decryption key locally, scoped to your Tenon identity and Apple storage account. Remove it with “Forget this browser” in Settings. This browser storage is not protected by iPhone Face ID. The browser stores only your optional “keep Apple signed in” preference. If you enable it on a trusted computer, Apple’s SDK also persists an authentication token; signing out through “Change Apple Account” clears that token. An authorized browser can open the notebook during a valid Tenon session; a new browser still needs initial authorization with the recovery key. Switching tabs, leaving the window or 5 minutes of inactivity locks the notebook and removes its contents from the interface. Browsers cannot provide the iPhone app’s Face ID, screenshot protection or clipboard expiry. Use a trusted computer. Our web host receives routine page requests and service metadata such as IP addresses; it does not receive notebook contents or recovery keys.

Retention and deletion

Delete entries and folders inside PassBy and allow iCloud sync to finish to apply those deletions to your notebook. Removing the app deletes its local files, but does not delete the iCloud notebook. Apple manages iCloud storage and service metadata under its own privacy policy.

Support and your choices

You can contact support@tenonai.cn for technical or privacy questions. Any details you voluntarily send are used to answer your request. Never send passwords, recovery keys, Apple verification codes or device passcodes.

Apple privacy policy

简体中文

生效日期:2026 年 10 月 3 日 · 开发者:Zeng Deyang

你的密码本

标题、账户、密码、备注及文件夹在设备上使用 AES-256-GCM 加密后,再同步至你的 iCloud 私有数据库。PassBy 不使用开发者运营的密码服务器、广告或统计 SDK。

Tenon 账号

Tenon 统一处理登录方式、验证与账号设置。PassBy 接收已验证的 Tenon 用户标识、称呼和平台角色,建立最长 1 分钟的独立会话。这些信息和产品会话临时保存在认证服务内存中;该服务不接收提供商密码或恢复密钥。iPhone 将当前产品会话保存在仅本机使用的钥匙串中,关闭应用后可恢复,不同步至 iCloud;主动退出会移除,会话最长 1 分钟;过期凭据在下次打开或返回应用时清除。打开密码本仍需 Face ID。平台角色不授予密码本内容访问权。网页主机及中央账号服务可能保存常规安全与请求信息。退出 PassBy 会结束其会话;中央账号可在 Tenon 账号中心管理。

Apple 存储与 Face ID

密码本通过系统 iCloud 账号识别。PassBy 不获取你的 Apple 密码。若选择 Apple 作为中央登录方式,Apple 可向 Tenon 提供身份信息;这与密码本存储授权分别处理。Face ID 由 iOS 处理,应用只接收验证结果,不接收面部数据。

密钥与恢复

本机加密密钥受设备钥匙串和当前 Face ID 登记保护。恢复密钥不会上传,请在 PassBy 之外保存。若设备密钥失效且恢复密钥丢失,开发者无法解密密码本。

剪贴板与草稿

iPhone 应用中,复制的内容仅保留在本机,60 秒后过期。接收粘贴的应用可以读取内容。未完成的条目以加密草稿保存在本机,不同步至 iCloud。

网页版访问

网页版直接连接 Apple CloudKit 中你的私有密码本。恢复密钥由浏览器的 WebCrypto 使用,不会发送至我们的网页服务器或 Apple。密码本只在页面内存中解密;恢复密钥原文、条目及未保存的编辑不会写入浏览器存储。授权浏览器后,本地保存不可导出的解密密钥,按 Tenon 身份与 Apple 存储账号隔离;可在设置中选择“撤销这台浏览器的授权”。浏览器密钥存储不受 iPhone Face ID 保护。浏览器仅保存“保持 Apple 登录”的可选偏好。若在可信电脑启用该选项,Apple SDK 还会保存身份验证令牌;通过“更换 Apple 账号”退出会清除此令牌。已授权的浏览器可在 Tenon 登录有效时直接打开;新浏览器仍需首次用恢复密钥授权。切换标签页、离开窗口或 5 分钟无操作时自动锁定,并从界面移除内容。浏览器无法提供 iPhone 应用的 Face ID、截图保护或剪贴板过期能力,请使用可信的电脑。网页服务器会接收常规页面请求及 IP 地址等服务信息,不接收密码本内容或恢复密钥。

保存与删除

在 PassBy 中删除条目和文件夹后,请等待 iCloud 同步完成,使删除同步至密码本。卸载应用会删除本机文件,不会删除 iCloud 密码本。Apple 按其隐私政策管理 iCloud 存储及服务元数据。

支持与你的选择

如有技术或隐私问题,可联系 support@tenonai.cn。你主动提供的信息仅用于处理支持请求。请勿发送密码、恢复密钥、Apple 验证码或设备密码。