Bastique is built around a simple principle: your secrets stay yours. The app has no advertising, behavioral tracking, or marketing analytics. Bastique is designed so that your sensitive vault contents remain encrypted and under your control.
1. Data We Do Not Access
Bastique does not have access to your master password, recovery key, encryption keys, or the unencrypted contents of your vault. Passwords, payment card details, documents, notes, and attachments are encrypted locally on your device before any optional synchronization or sharing occurs.
Bastique does not use advertising SDKs, behavioral tracking, or third-party marketing analytics.
2. Limited Technical Data Processing
When you choose to use optional online features, limited technical data may be transmitted and processed only to provide those features:
- Encrypted synchronization: encrypted vault snapshots, encrypted attachments, synchronization identifiers, and delivery status may be processed by the Bastique relay when relay delivery is used.
- Secure sharing: encrypted temporary packages, short codes, expiration information, and retrieval status may be processed until the package is retrieved or expires.
- Subscription verification: Apple, Google, or Microsoft may provide transaction identifiers, product identifiers, purchase status, renewal status, and related purchase information so Bastique can verify access to subscription features.
- Security and infrastructure: hosting providers may temporarily process IP addresses, request timestamps, and technical logs for security, abuse prevention, and reliability.
- Optional breach checking: when initiated by you, Bastique sends only the first five characters of a locally generated SHA-1 password hash to the Have I Been Pwned range API. The full hash and the password itself are never transmitted.
- Optional AI-assisted duplicate review (macOS and Windows desktop builds only): when explicitly initiated and confirmed by you, Cloudflare Workers AI receives a minimized, pseudonymized relationship map containing public service domains or provider identifiers, random per-analysis record and relationship identifiers, and field-presence indicators or bounded counts. Usernames, email addresses, passwords, password hashes, TOTP secrets, recovery codes, notes, attachments, and full URLs are never included. The feature is not included in Android, iOS, or Linux Snap builds.
All synchronization and sharing payloads are end-to-end encrypted before leaving your device. Nearby devices may exchange encrypted sync data directly when they can reach each other locally; when the relay is used, it processes ciphertext only and cannot read the contents.
Optional AI-review metadata is separate from encrypted synchronization and sharing payloads. It is generated for a single requested analysis, is not written to Bastique relay storage, and can only produce recommendations. Bastique validates recommendations against the current local records and requires your confirmation before applying changes.
3. Where Your Data Lives
Your primary vault database is stored only on your local device, protected by strong authenticated AES-256-GCM encryption and Argon2id key derivation using your master password. Without the required key, the stored data cannot be read.
When synchronization is enabled, end-to-end encrypted snapshots and encrypted attachment data may be transmitted to and temporarily retained by the Bastique relay. The relay receives ciphertext only and does not have the keys required to decrypt it.
Your master password and recovery key are never transmitted to the Bastique relay.
4. Legal Bases for Processing
Depending on the feature and applicable law, Bastique processes limited technical data on the following legal bases:
- Performance of a contract, when processing is necessary to provide synchronization, secure sharing, purchase restoration, or subscription access requested by you.
- Legitimate interests, when necessary to protect the relay, prevent abuse or fraud, and maintain service reliability.
- Consent, when you voluntarily initiate an optional breach check or another optional feature that requires it.
- Compliance with legal obligations, where financial or transaction records must be retained by law.
You may withdraw consent for optional processing at any time without affecting processing that occurred before withdrawal.
5. Third-Party Service Providers
Bastique may use the following service providers:
- Cloudflare: encrypted relay hosting, network delivery, security and abuse prevention, and optional Workers AI inference on the minimized pseudonymized metadata described above.
- Apple: App Store purchases, subscriptions, transaction processing, and entitlement verification.
- Google: Google Play purchases, subscriptions, transaction processing, and entitlement verification.
- Microsoft: Microsoft Store purchases, subscriptions, transaction processing, and entitlement verification.
- Have I Been Pwned: optional password breach checking through the k-anonymity range API.
These providers process information under their own privacy terms and only as required to provide the relevant service.
The Linux Snap edition does not connect to the Bastique relay and does not perform store subscription verification or cloud AI duplicate review. Its direct nearby-device features remain on the local network. An optional breach check contacts the Have I Been Pwned k-anonymity API only when initiated by you.
6. International Data Transfers
Bastique is operated from Ukraine. Some service providers may process limited technical information outside your country of residence. Where required by applicable data protection law, appropriate contractual, organizational, or legal safeguards are used for these transfers.
7. Data Retention and Deletion
Local vault data remains on your device until you delete it or remove the application.
You can erase local vault entries at any time from Bastique Settings by choosing Clear vault memory and selecting which categories to remove. Bastique first overwrites the selected records with random data and then deletes them, so the cleared entries cannot be recovered from this device.
One-time sharing packages are deleted immediately after successful retrieval or automatically expire after 10 minutes, whichever occurs first.
Encrypted synchronization data is retained on the relay only while required to provide synchronization. Sync snapshots, encrypted attachment blobs, and the sync manifest automatically expire after 15 days without activity.
You can also remove server-side synchronization data immediately from Bastique Settings by choosing Delete sync data. This deletes the encrypted relay data for your sync group and turns sync off on that device; local vault entries and attachments are not deleted. You may still contact us at the address below for privacy and deletion requests.
Limited subscription verification information and security logs may be retained only as long as necessary to verify access, prevent fraud, maintain service security, and comply with applicable legal obligations.
Bastique does not store optional AI-review request bodies or model recommendations in relay KV storage and does not log their contents. Cloudflare processes the minimized request transiently to provide Workers AI inference and states that Workers AI customer content is not used to train models or improve Cloudflare or third-party services without explicit consent.
8. Data Deletion Requests
Bastique has no user accounts, so there is no account to close. Your vault lives on your own device and is removed by deleting the entries, clearing the vault, or uninstalling the app. The steps below cover the limited server-side data described in section 2.
In the app (immediate):
- Delete sync data — removes the encrypted synchronization data for your sync group from the relay and turns synchronization off on that device. Your local vault is not affected.
- Clear vault memory — overwrites the selected local entries with random data and then deletes them from the device.
By request:
To request deletion of server-side data associated with Bastique, email bastique@eventumdigital.com with the subject “Data Deletion Request”. Because Bastique does not maintain user accounts, please include whatever identifying information you have — for example a subscription or transaction identifier, or synchronization-related information shown in the app — so the relevant records can be located. Where this is technically possible, we will identify and delete the corresponding server-side data and confirm by email.
What may remain: subscription verification records and security logs may be retained where necessary for fraud prevention, service security, or compliance with legal obligations, and are removed once those purposes no longer apply. Encrypted synchronization data and one-time sharing packages also expire on their own as described in section 7, even if no request is made.
9. Your Privacy Rights
Depending on your location, you may have the right to request access to, correction of, deletion of, restriction of, or portability of personal data associated with you, and to object to certain processing. You may also withdraw consent where processing relies on consent.
Because Bastique does not maintain user accounts and cannot decrypt vault contents, some requests may be technically limited to server-side metadata or information that can be associated with a transaction or support request.
You may also lodge a complaint with the competent data protection authority in your country of residence.
10. Your Control
You can delete entries, clear your vault, export encrypted backups, or remove the app at any time. Removing Bastique from your device deletes its local encrypted storage. Secure deletion of temporary decrypted files is performed on a best-effort basis within the limits of the device's storage and file system.
11. Contact and Legal Operator
Bastique is developed and operated by Valeriia Lypovska, Individual Entrepreneur, trading as Eventum Digital Agency.
For privacy-related inquiries, data deletion requests, or other questions, contact us at bastique@eventumdigital.com.