MyPwdTool is a password manager built around one simple idea: your data should never be readable by anyone but you — not MyPwdTool, not a cloud provider, not anyone.
Free (excl. device sync), no account
The vault, browser extensions, AutoFill, password health checks, breach checks, TOTP two-factor codes, passkey metadata storage, and encrypted backups all work fully offline and cost nothing — no feature limits, no time limit, no account or sign-up of any kind, on any platform.
Multi-device sync (optional, still no account)
The only paid feature is multi-device synchronization, an affordable yearly subscription ($2.99/y reference price) that keeps your passwords in sync across macOS, iOS, Windows, and Android — without a central cloud database. Devices talk directly to each other through a relay server whose only job is to pass encrypted messages along; it has no concept of a "vault," a "password," or a "user account," and could never read your data even if it were compromised. Joining a sync group someone else already created is free — the subscription only gates creating a new group or inviting further devices. One subscription, bought on any one platform, covers every device in the group.
Security
Every sensitive field — password, username, note, card number, TOTP secret — is independently encrypted with AES-256-GCM. Your master password is used once, locally, to derive a key via PBKDF2-HMAC-SHA256 with 400,000 iterations; it is never stored and never leaves your device. If you forget it, nobody — including us — can recover your vault. Unlock with Face ID, Touch ID, Windows Hello, or your fingerprint between master-password prompts, on your own schedule.
Cross-platform, feature-complete
macOS, iOS, Windows, and Android all get the same feature set — not a crippled "desktop-only" or "mobile-only" tier. Browser extensions are available for Chrome, Edge, and Firefox on macOS and Windows, plus a native Safari extension on macOS and iOS, and a system-level AutoFill provider on iOS, macOS, and Android.
What's inside
• Encrypted vault for passwords, passkey metadata, TOTP codes, and payment cards
• Multiple independent vaults (e.g. personal + work)
• Browser extensions (Safari, Chrome, Edge, Firefox) and system AutoFill
• Password health audit: weak, reused, and old passwords flagged on-device
• Breach check against Have I Been Pwned, using k-anonymity so your password never leaves your device
• Encrypted local backups and CSV import/export
• A full local activity log, with per-vault "hasn't synced in a while" reminders
No tracking
No analytics, no advertising, no third-party SDKs for tracking, no account system, no server-side storage of your vault or its contents. The relay's source code is planned to be published for independent review.
Made in France.
No comments or reviews, maybe you want to be first?