NoirLock is a zero-knowledge, local-first vault for passwords, passkeys, TOTP codes, secure notes, seed phrases, and API tokens. NoirLock does not require an account, and there are no NoirLock servers of any kind. StakhivLabs cannot access, view, or decrypt the contents of any user's vault.
All vault records are encrypted on the user's device before they are ever written to disk or synced. Encryption keys are derived from the user's master password and an independent Secret Key that only the user holds, and are stored in the device's system Keychain — never in plain files, and never transmitted to StakhivLabs.
If a user enables sync, only already-encrypted data leaves the device, and it is sent solely to that user's own private iCloud account via Apple's CloudKit. This data is never routed through, or accessible to, StakhivLabs. iCloud storage of this synced data is governed by Apple's own privacy policy.
Where Face ID or Touch ID is used to unlock the vault, authentication is performed entirely by Apple's Secure Enclave on the user's device. NoirLock never receives, collects, stores, or transmits any biometric data.
NoirLock contains no analytics, no third-party tracking, and no advertising SDKs. No usage data, vault metadata, or personal information is collected or shared with any third party.
Because NoirLock cannot decrypt vault contents, it cannot recover or delete data on a user's behalf. Users can permanently remove their data at any time by deleting records within the app, disabling iCloud sync, or uninstalling the app and removing its data from iCloud in their device's iCloud settings.
NoirLock is not directed at children under 13, and StakhivLabs does not knowingly collect personal information from children.