Keyward: Password Manager

Contains ads
Content rating
Everyone
0+
Downloads
Content rating
Everyone
Learn more
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image

About this app

Keyward keeps your passwords in an encrypted file on your phone. There is no account to create, no vault to sync, and no server holding a copy — so there is no server that can be breached.

WHAT YOU GET

• Logins, cards, secure notes and identities in one encrypted vault
• Unlock with your master password or your fingerprint
• A password generator that tells you the real entropy of what it made
• Built-in two-factor codes, so your login and its 2FA live together
• Android autofill for apps and websites
• A health check that finds reused, weak and breached passwords
• Encrypted backups, and CSV import from your current manager

HOW THE ENCRYPTION WORKS

Your master password is stretched with PBKDF2-HMAC-SHA256 into a key that wraps a second, randomly generated key. That second key encrypts the vault with AES-256-GCM.

The iteration count is measured on your own device when you first set up, then stored in the file header. It tracks your hardware instead of a number someone picked years ago on a laptop.

Because the two keys are separate, changing your master password rewrites sixty bytes instead of re-encrypting everything you own.

BIOMETRICS THAT ARE ACTUALLY CRYPTOGRAPHY

Turning on fingerprint unlock does not store your master password somewhere and hand it back. Your fingerprint releases a key held in the phone's secure hardware, and that key unwraps a second copy of the vault key. The key cannot be exported, and there is nothing on disk for a rooted device to lift.

AUTOFILL THAT WILL NOT FILL A FAKE

Keyward matches on the registrable domain, never on substrings. A page at
paypal-secure-login.com is offered nothing. Neither is www.paypal.com.evil.ru.
That is the whole point of putting a password manager between you and a login box, and it is where a surprising number of them are careless.

THE HEALTH CHECK FINDS WHAT OTHERS MISS

As well as weak and reused passwords, Keyward finds near-duplicates —
Summer2023! sitting next to Summer2024!. Credential-stuffing tools mutate known passwords in exactly that way, and almost no free manager looks for it.

WHAT USES THE NETWORK, PRECISELY

Two things, and nothing else.

The breach check is off until you switch it on. When it is on, it sends five
characters of a hash. Not your password, not your username, no account, no
identifier. The service cannot tell which password was asked about or whether there was a match.

The banner at the top of the main screens is an ad, served by Google. It
receives the usual advertising data — an advertising ID, your device model, and approximate location from your IP address. It has no access to your vault: the vault is encrypted and the ad runs in its own view. In the EEA and the UK you will be asked what Google may use before any ad loads, and you can change that answer later in Settings.

Your passwords, usernames, notes and card numbers are never sent anywhere.
There is no analytics and no crash reporting.

BEFORE YOU START

There is no password reset, because there is no account to reset it from. If
you forget your master password the vault is gone and nobody can recover it — not us, not Google. Keyward makes you tick a box acknowledging this before it will create a vault. Make an encrypted backup and keep it somewhere safe.

Requires Android 8.0 or later.
Offline password vault. AES-256, biometric unlock, no account, no sync.
Updated on
Aug 30, 2026

Data safety

Safety starts with understanding how developers collect and share your data. Data privacy and security practices may vary based on your use, region, and age. The developer provided this information and may update it over time.
  • No data shared with third parties
    Learn more about how developers declare sharing
  • No data collected
    Learn more about how developers declare collection