Privacy Policy
Last updated: January 30, 2026
Lemonade Password Manager ("we", "our", "the app") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.
1. What We Collect
- Account information: Email address and display name, provided through Google Sign-In authentication.
- Vault data: Passwords, environment variables, and API keys that you store in the app. All vault data is encrypted client-side before being stored.
- Subscription status: Whether your account is on the free or premium plan.
2. What We Do NOT Collect
- We do not collect browsing history.
- We do not collect or log the websites where you use autofill.
- We do not collect your master password or encryption keys.
- We do not sell, share, or transfer personal data to third parties.
- We do not use analytics or tracking tools in the browser extension.
3. Browser Extension
The Lemonade Password Manager browser extension ("Autofill companion") communicates exclusively with Lemonade servers to retrieve your encrypted credentials. The extension:
- Only activates on pages with login forms.
- Does not read or store page content.
- Does not inject ads or trackers.
- Requires authentication with your Lemonade account to function.
4. Data Storage and Security
- All vault data is encrypted using AES-256 before being stored in Google Cloud Firestore.
- Authentication is handled by Firebase Authentication (Google Sign-In).
- We use HTTPS for all communications.
- Firestore security rules enforce that users can only access their own data.
5. Third-Party Services
We use the following third-party services:
- Firebase Authentication: For user sign-in (Firebase Privacy Policy).
- Google Cloud Firestore: For encrypted data storage.
- Firebase Hosting: For serving the web application.
- Polar: For payment processing of premium subscriptions (Polar Privacy Policy).
6. Data Retention and Deletion
Your data is retained as long as your account is active. You can delete your account and all associated data at any time from the app settings. Upon deletion, all vault data is permanently removed from our servers.
7. Your Rights
You have the right to:
- Access all data stored in your account (visible in the app).
- Export your data.
- Delete your account and all associated data.
8. Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated date.
9. Contact
If you have questions about this privacy policy, contact us at maurohabbaby.dev@gmail.com.