About PassPony

One developer, a family of small privacy tools. PassPony is part of a line of independent apps built on the same principle: the cryptography that protects you should be something you can read, and your data should never leave your device.

Why it exists

The pass password store is a quietly excellent idea — one encrypted file per secret, organized in folders, versioned with git, readable by tools that have existed for decades. Its age-based cousin, passage, brings the same idea to modern, simple cryptography. What both have lacked is a good phone client that stays faithful to the format instead of trapping your data in yet another proprietary vault.

PassPony is that client. It doesn't invent an account, a server, or a format. It reads and writes exactly what the command-line tools do — verified, byte for byte, by an automated test suite that checks everything the app writes against the real pass, passage, gpg, and age binaries.

The approach

  • Your keys, your device. Encryption and decryption happen on-device with keys you control. Nothing is uploaded anywhere.
  • Open where it counts. The cryptographic cores — the age implementation and the OpenPGP engine — are open and auditable. That is the part that matters for trust.
  • No lock-in. Because the on-disk format is the standard one, your store opens in any other pass/passage client, on any platform, forever. If PassPony vanished tomorrow, your data would be exactly as usable as before.
  • Honest about limits. Entry names and folder structure are metadata visible to your git host. PassPony says so plainly rather than pretending otherwise.

Who's behind it

PassPony is built and maintained by a solo independent developer under the NorseHorse name, alongside a small family of related privacy and encryption tools. No venture funding, no growth team, no data business — just software that does one thing carefully.

Get in touch

NorseHorse@norsehor.se · Security & disclosure · PGP key