Bitwarden
Bitwarden's core security is genuinely strong — your passwords are encrypted on your device before upload and Bitwarden cannot read your vault — but the legal protections it extends to you are weak. The company can terminate your account without notice, owes you nothing if your data is lost or breached, and can change its terms simply by continuing your use of the service. Your non-vault account data can be shared with law enforcement, unnamed affiliates, or a future acquirer, and vague language around data retention after cancellation means you cannot be certain when or whether your information is fully gone. Overall, Bitwarden is technically trustworthy for password storage but legally positions itself to avoid almost all accountability toward its users.
Last analyzed
Heads up: this analysis is AI-generated, can be incomplete or wrong, and is not legal advice. Use it as a starting point and read the original document before you agree — see our Terms.
Clause-by-clause breakdown
Every clause we flagged in Bitwarden's agreement, with what it means for you.
Using the service after minor changes means you've agreed to them.
“For non-material modifications, your continued use of the Website constitutes agreement to our revisions of these Terms of Service.”
Quoted verbatim from the agreement What this means: If Bitwarden makes minor changes to the Terms, simply continuing to use the service counts as your agreement — even if you never read the new terms. Only 'material' changes (like price changes) get 30 days' notice. The line between 'material' and 'non-material' is drawn by Bitwarden alone.
What you can do: Periodically check the Terms of Service page for updates, or watch for email notifications about changes that Bitwarden deems material.
Bitwarden can delete your account anytime, without notice or reason.
“Bitwarden has the right to suspend or terminate your access to all or any part of the Website at any time, with or without cause, with or without notice, effective immediately. Bitwarden reserves the right to refuse service to anyone for any reason at any time.”
Quoted verbatim from the agreement What this means: Bitwarden can shut down your account instantly, for any reason or no reason at all, without warning. For a password manager, this is particularly impactful — losing sudden access could lock you out of credentials for all your other accounts.
What you can do: Regularly export your vault data and store it securely offline so you always have a backup if your account is terminated unexpectedly.
Bitwarden owes you nothing if your data is lost or breached.
“You understand and agree that we will not be liable to you or any third party for any loss of profits, use, goodwill, or data, or for any incidental, indirect, special, consequential or exemplary damages, however arising, that result from your use or inability to use the Service; any modification, price change, suspension or discontinuance of the Service; the Service generally or the software or systems that make the Service available; unauthorized access to or alterations of your transmissions or data;”
Quoted verbatim from the agreement What this means: Bitwarden disclaims all liability for data loss, service outages, or even unauthorized access to your data. For a password manager, a breach or outage could have severe downstream consequences across all your accounts, yet you would have no legal recourse against Bitwarden.
What you can do: Maintain offline backups of your vault export and enable two-factor authentication to reduce your exposure if something goes wrong.
You must pay Bitwarden's legal costs if your use causes a claim.
“You agree to indemnify us, defend us, and hold us harmless from and against any and all claims, liabilities, and expenses, including attorneys' fees, arising out of your use of the Website and the Service, including but not limited to your violation of this Agreement”
Quoted verbatim from the agreement What this means: If Bitwarden faces any legal claim related to your use of the service, you must pay their legal costs and any damages — including attorney fees. This is a broad obligation that could be triggered by a wide range of situations.
What you can do: Be aware of this obligation and use the service only in ways clearly permitted by the Terms to avoid triggering this clause.
All legal disputes must be handled in California courts.
“Except to the extent applicable law provides otherwise, this Agreement between you and Bitwarden and any access to or use of the Website or the Service are governed by the federal laws of the United States of America and the laws of the State of California, without regard to conflict of law provisions. You and Bitwarden agree to submit to the exclusive jurisdiction and venue of the courts located in the State of California.”
Quoted verbatim from the agreement What this means: All disputes must be resolved in California courts under California law, regardless of where you live. For international users or those outside California, this means any legal action would require traveling to or hiring lawyers in California.
What you can do: Be aware that if you ever need to take legal action against Bitwarden, it must be done in California — factor this into your decision to use the service.
Bitwarden shares your account data with law enforcement when requested.
“We believe that disclosure is reasonably necessary to comply with any applicable law, regulation, legal process, or lawful government request, including in connection with national security or law enforcement requirements. This may include disclosures: to respond to subpoenas or court orders; to establish or exercise our legal rights or defend against legal claims; or to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our Service Agreement, or as otherwise required by law. In each case, we will make reasonable efforts to verify the validity of the request before disclosing your Personal Information.”
Quoted verbatim from the agreement What this means: Bitwarden will share your personal (administrative) data with governments or law enforcement when legally required. Importantly, because vault data is encrypted and Bitwarden cannot access it, any government request would only yield administrative data like your email address — not your actual passwords.
What you can do: Understand that your email and account metadata could be disclosed to authorities, but your encrypted vault contents remain inaccessible to Bitwarden and therefore cannot be handed over.
Your data transfers to any company that acquires Bitwarden.
“We may also provide your Personal Information to a third party in connection with a merger or acquisition of Bitwarden, either in part or in whole, or the assignment or other transfer of the Site or Service. In such event, such third party will either: Continue to honor the privacy practices described in this Privacy Policy; or If the third party proposes to materially change the privacy practices described in this Privacy Policy involving your Personal Information collected before such merger, acquisition, assignment or other transfer:inform you and get your express affirmative consent to opt-in to the new practices; and/orinform you in some prominent manner enabling you to make a choice about whether to agree to the new practices.”
Quoted verbatim from the agreement What this means: If Bitwarden is sold or merged, your personal data transfers to the new owner. The new owner must either follow the current privacy policy or notify you and get your consent before changing practices — which is a relatively user-protective approach compared to many services.
What you can do: Watch for any acquisition announcements and review any privacy change notifications carefully, as a new owner could seek your consent to different data practices.
Bitwarden keeps your account data for your entire membership duration.
“We retain Administrative Data for as long as you are a customer of Bitwarden and as required by law. If you terminate your relationship with Bitwarden, we will delete your Personal Information in accordance with our data retention policies.”
Quoted verbatim from the agreement What this means: Bitwarden keeps your administrative data (name, email, billing info) for the entire duration of your account, and deletes it when you leave — but the exact retention period after termination is not specified, and 'as required by law' could extend retention indefinitely for some data.
What you can do: After cancelling your account, you can email [email protected] to confirm your personal data has been deleted and request confirmation.
Google Analytics tracks your activity across sites when you visit Bitwarden's website.
“We use data for analytics and measurement to understand how the Site and Bitwarden Service are used. For example, we analyze data about your visits to our Site to do things like optimize product design. We use a variety of tools to do this, including Google Analytics. When you visit the Site using Google Analytics, we and Google may link information about your activity from that site with activity from other sites that use Google Analytics services.”
Quoted verbatim from the agreement What this means: Bitwarden uses Google Analytics on its website, which means Google can track your browsing behavior across multiple sites that use Google Analytics. This tracking applies to the marketing website, not the vault itself.
What you can do: Use the Google Analytics opt-out browser add-on (http://tools.google.com/dlpage/gaoptout) or a privacy-focused browser extension to block this tracking.
Bitwarden can transfer your contract to anyone without your consent.
“Bitwarden may assign or delegate these Terms of Service and/or the Bitwarden Privacy Policy, in whole or in part, to any person or entity at any time with or without your consent. You may not assign or delegate any rights or obligations under the Terms of Service or Privacy Policy without our prior written consent, and any unauthorized assignment and delegation by you is void.”
Quoted verbatim from the agreement What this means: Bitwarden can transfer your contract to any other company or person without asking you. You, however, cannot transfer your account rights to anyone else without Bitwarden's written permission. This is a one-sided arrangement.
What you can do: Monitor any communications from Bitwarden about ownership or operational changes, as these could affect who holds your data and under what terms.
Post-cancellation data retention timelines reference an unpublished internal policy.
“We retain Administrative Data for as long as you are a customer of Bitwarden and as required by law. If you terminate your relationship with Bitwarden, we will delete your Personal Information in accordance with our data retention policies.”
Quoted verbatim from the agreement What this means: Administrative Data — your name, email, phone number, billing info, and account metadata — is kept for the entire duration of your relationship with Bitwarden. The policy references a separate 'data retention policy' for what happens after you leave, but that policy is not provided or linked here, leaving the actual post-termination retention period unclear.
What you can do: Contact [email protected] to request details on their data retention policy and ask for confirmation of deletion after closing your account.
Your data may be shared with undefined 'affiliates and partners.'
“Bitwarden may also share your Personal Information with our affiliates and partners, to facilitate our global operations and in accordance with applicable laws, and our agreements with customers or service providers.”
Quoted verbatim from the agreement What this means: Beyond service providers, Bitwarden can share your personal information with unspecified 'affiliates and partners.' The term 'partners' is broad and not defined in the policy, which means the scope of this sharing is unclear. This is distinct from the tightly restricted sharing with subprocessors described elsewhere.
What you can do: Contact Bitwarden at [email protected] to ask for clarification on which specific partners receive your data and for what purposes.
Bitwarden makes no legal warranty that the service is actually secure.
“Bitwarden provides the Website and the Service "as is" and "as available," without warranty of any kind. Without limiting this, we expressly disclaim all warranties, whether express, implied or statutory, regarding the Website and the Service including without limitation any warranty of merchantability, fitness for a particular purpose, title, security, accuracy and non-infringement.”
Quoted verbatim from the agreement What this means: Bitwarden explicitly disclaims any warranty of 'security' for the service. While standard in software terms, this is notable for a security product — it means Bitwarden makes no legal guarantee that the service will actually keep your data secure.
What you can do: Rely on Bitwarden's technical architecture (zero-knowledge encryption, open-source audits) rather than contractual security guarantees as your primary assurance.
Bitwarden cannot read your vault — it's encrypted before leaving your device.
“Vault Data includes all information stored within accounts to the Bitwarden Service, including but not limited to login credentials, attachments including photos, videos, images and other files, and may include Personal Information. If we host the Bitwarden Service for you, we will host Vault Data. Vault Data is encrypted using secure cryptographic keys under your control. Bitwarden cannot access Vault Data.”
Quoted verbatim from the agreement What this means: Your passwords and stored credentials are encrypted on your device before being sent to Bitwarden's servers, using keys only you control. This means Bitwarden itself is technically unable to read your vault contents — a strong privacy protection that goes beyond what most services offer.
What you can do: Use a strong, unique master password that you never share with anyone, since it controls the encryption keys that protect your vault.
Your data is AES-256 encrypted on your device before upload.
“Your data, including Personal Information, is never sent to the Bitwarden cloud servers without first being encrypted on your local device using AES 256 bit encryption. In addition, Bitwarden encrypts the transmission of that information using secure socket layer technology (SSL).”
Quoted verbatim from the agreement What this means: Bitwarden uses AES-256 encryption locally before transmitting your data, and also encrypts the connection itself with SSL. This double-layer approach means your data is protected both in transit and at rest on their servers.
What you can do: No specific action needed — this protection is automatic. Ensure you keep your Bitwarden app updated to benefit from the latest security improvements.
Deleting your account permanently purges all your data from Bitwarden.
“All information is purged from our databases when you cancel your account. Information cannot be recovered once your account is cancelled.”
Quoted verbatim from the agreement What this means: When you delete your Bitwarden account, all your data is permanently removed from their servers. This is a strong user-protective commitment — your vault and account information cannot be recovered or retained after cancellation.
What you can do: Export your vault before deleting your account, since the deletion is permanent and irreversible.
Bitwarden does not sell your personal data to third parties.
“Sales of Personal Information California residents may opt out of the "sale" of their Personal Information. We do not "sell" your Personal Information as we understand that term to be defined by the California Consumer Privacy Act and its implementing regulations.”
Quoted verbatim from the agreement What this means: Bitwarden explicitly states it does not sell your personal information to third parties. This is a meaningful commitment that protects users from having their data monetized through data brokers or advertisers.
Frequently asked questions
Is Bitwarden's Terms & Conditions agreement fair?
- BeforeYouClick grades Bitwarden C on an A–E scale, where A is the fairest. Its agreement contains 3 critical clauses, 10 warnings and 4 good practices.
What are the biggest problems with Bitwarden's terms?
- The most serious clauses we flagged are: Policy Changes Bind You Without New Consent, Account Can Be Terminated Without Warning and No Liability Even for Data Breaches.
How long does it take to read Bitwarden's terms?
- Bitwarden's agreement takes about 28 minutes to read in full, across 17 clauses we reviewed. The summary on this page covers the same ground in under a minute.
When was Bitwarden's agreement last analyzed?
- We last read Bitwarden's Terms & Conditions on July 4, 2026. Companies change their terms without notice, so check the original document for the current version.
Is this analysis legal advice?
- No. This analysis is AI-generated, can be incomplete or wrong, and is not legal advice. Use it as a starting point and read the original agreement before you agree to it.
More agreements to read
- Mullvad VPNSecurityGrade A
- MurenaSecurityGrade B
- NordVPNSecurityGrade B
- IVPNSecurityGrade C
- DuckDuckGoSecurityGrade C
- ProtonVPNSecurityGrade D