Where and how are passwords stored?
All your data is stored only on your device in encrypted form: passwords, two-factor authentication codes, documents and cards. If you have turned on sync, an encrypted copy is also kept in your own cloud (WebDAV). Your passwords are not on our servers.
The vault is like a safe. It is fully encrypted with the AES-256 algorithm, the standard used by banks and government organizations around the world. Only your master password can open the safe, and we never store the master password anywhere: not on the phone, not in the cloud, not on our side. Even if someone copies the vault file, without the master password they will see only a meaningless set of characters.
Guessing the password by brute force is practically impossible. It is protected by the Argon2id algorithm, which deliberately makes every attempt “heavy” for a computer. You won't notice it, but an attacker would need years.
To avoid typing a long password every time, you can open the app with your fingerprint or a PIN. This uses the device's own secure key storage, and the master password is not stored in this case either.
Important: the master password is the only key to your data. We cannot recover it, so memorize it or write it down and keep it in a safe place.