Legal
Terms Of Use
Last updated: August 28, 2026 These Terms of Use apply to the use of the ClavisPass website, the ClavisPass app, and the ClavisPass browser extension.
1. Provider
ClavisPass is provided by:
Ricardo Valente de Matos
Email: clavispass@arratel.dev
Website: https://clavispass.arratel.dev/2. Subject Matter
ClavisPass is a password manager for locally managing encrypted vault data. Users can store entries such as passwords, usernames, URLs, 2FA data, recovery codes, cards, documents, notes, attachments, and other information.
ClavisPass also provides features such as import, export, backup, sync, Fast Access, browser extension support, security analysis, and expiry reminders.
3. Availability And Platforms
ClavisPass is developed for different platforms, especially desktop and mobile devices.
There is no entitlement to permanent availability of individual platforms, stores, features, or third-party integrations.
4. Master Password And User Responsibility
The vault is protected by a master password. Users are responsible for choosing a strong master password, keeping it safe, and creating suitable backups.
ClavisPass cannot recover a forgotten master password. Without the master password, encrypted vault data cannot be decrypted.
5. Vault Data, Backups And Sync
Users are responsible for the contents of their vault.
ClavisPass can store data locally or sync it through providers selected by the user. This includes local device storage, local vault files on desktop, Dropbox, Google Drive, and self-hosted ClavisPass Hub instances.
When using third-party providers such as Dropbox or Google Drive, the terms of those providers also apply. When using a self-hosted ClavisPass Hub, the respective operator is responsible for operating and securing that instance.
Users should regularly check whether their data has been saved, synced, and backed up correctly. Before larger changes, imports, or migrations, users are advised to create a backup.
6. Import And Migration
ClavisPass may provide import features for other password managers, browser exports, or file formats.
Imports may be incomplete depending on the source and data quality. Users should review imported data. No guarantee is given that all data, fields, metadata, or attachments from third-party formats are imported completely or without errors.
7. Browser Extension And Autofill
The browser extension can communicate with the local ClavisPass desktop app to find matching entries and fill login data.
Users should use autofill only on trusted websites and should check that the domain and target page are correct before filling login data.
8. Security Analysis
ClavisPass can show warnings or hints about weak, reused, expired, or potentially compromised passwords.
These hints are supportive and do not replace the user's own security assessment. Analysis results may contain false positives or false negatives.
9. No Guarantee Of Absolute Security
ClavisPass is developed with a focus on privacy and security. However, no software system can guarantee absolute security.
Users are responsible for keeping their devices, operating systems, browsers, cloud accounts, and credentials secure.
10. Permitted Use
Users may use ClavisPass only lawfully.
In particular, the following is not permitted:
- use that infringes rights of third parties
- circumvention of security mechanisms
- manipulation, misuse, or disruption of services, stores, sync providers, or ClavisPass Hub instances
- reverse engineering where it is not permitted by law or expressly allowed by an open-source license
11. Open Source And Licenses
Where parts of ClavisPass are published as open source, the respective license terms in the repository or distribution additionally apply to those parts.
These Terms of Use do not replace any open-source license. They govern the use of the provided app, website, and services where applicable.
12. Costs
Where ClavisPass is provided free of charge, using it does not create a payment obligation towards the provider.
13. Third-Party Providers
ClavisPass may interact with third-party providers, for example app stores, cloud storage providers, OAuth providers, hosting services, or security services.
The terms and privacy notices of third-party services apply to those services. The provider of ClavisPass is not responsible for the permanent availability, security, or contractual terms of third-party providers.
14. Updates
ClavisPass may provide updates to improve features, fix bugs, or update security measures.
Users should install updates promptly. Older versions may become incompatible or may no longer be supported.
15. Liability
The provider is liable under statutory provisions for intent and gross negligence as well as for injury to life, body, or health.
In cases of slight negligence, the provider is liable only for breach of essential contractual obligations. In such cases, liability is limited to the typical and foreseeable damage.
Any further liability is excluded to the extent permitted by law.
In particular, the provider assumes no liability for data loss, forgotten master passwords, faulty backups, faulty sync, third-party outages, or insecure user devices, to the extent permitted by law and unless caused culpably by the provider.
16. Ending Use
Users may stop using ClavisPass at any time by uninstalling the app and deleting local data or connected storage locations.
When using third-party providers, users may also need to delete stored data or revoke permissions directly with the respective third-party provider.
17. Changes
These Terms of Use may be updated if features, legal requirements, or technical processes change.
18. Applicable Law
German law applies unless mandatory consumer protection rules provide otherwise.
19. Severability
If individual provisions of these Terms of Use are or become invalid, the validity of the remaining provisions remains unaffected.