Security model

Security

Lock Myself Out is zero-knowledge: your passwords are encrypted in your browser before they reach our servers, and only your Master Password can decrypt them. Here is how it works and what it does — and does not — protect against.

Zero-knowledge encryption

Your passwords are encrypted in your browser with your Master Password before they reach our servers. We never see or store your Master Password, and we cannot decrypt your stored information.

Locks are enforced by the server

An active lock cannot be cancelled, shortened, or revealed early. There is no emergency unlock, support override, or hidden bypass.

Survives refresh, sign-out, and device changes

Refreshing the page, logging out, reopening the app, or switching devices does not end an active lock. The unlock time is stored on the account, not the device.

Protected information is withheld

While a lock is active, the password, username, and private notes cannot be viewed, copied, edited, deleted, or recovered.

Only extensions are allowed

You may extend an active lock to a later time. The previous earlier unlock time cannot be restored.

Outside recovery is out of our control

Lock Myself Out cannot prevent you from using an outside service's own password-reset system. It withholds credentials; it does not disable the service.

Important limitation

Lock Myself Out withholds account credentials. It does not directly disable outside websites, devices, or applications. A determined user may still recover access through the outside service's own password-reset process.