bitwarden / bitwarden/ios

[PM-32551] Several "Data Linked to You" collected - Bitwarden Password Manager

Open
#2,366 6 comments 0 reactions 0 assignees View on GitHub
app:password-manager bug
Dominant language
Swift
Stars
684
Forks
154
Avg merge
3d 22h
Merged PRs (30d)
24

Description

### Steps To Reproduce

1. Go to the [release on the App Store](https://apps.apple.com/us/app/bitwarden-password-manager/id1137397744)
2. Scroll down to the "App Privacy" section

### Expected Result

No "Data Linked to You" should be collected.
Note that this is common practice in many other password managers, such as [NordPass: Password Manager](https://apps.apple.com/us/app/nordpass-password-manager/id1486322860) and [Proton Pass - Password Manager](https://apps.apple.com/us/app/proton-pass-password-manager/id6443490629).

If any "Data Not Linked to You" is strictly required for the correct operation of the app's core functionality, the specific data collected should be clearly reported in your Privacy Policy.

### Actual Result

- "Contact Info" and "Identifiers" are collected as **Data Linked to You**
- "Contact Info" and "Diagnostics" are collected as **Data Not Linked to You**

### Screenshots or Videos

Image

### Additional Context

I believe this is a bug, not only because no data linked to a user’s identity should ever be collected, but also because requesting unnecessary permissions for an application constitutes a programming error and violates the principle of least privilege.

### Build Version

2026.2.0

### What server are you connecting to?

N/A

### Self-host Server Version

_No response_

### Environment Details

_No response_

### Issue Tracking Info

- [x] I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the iOS App Store App Privacy declarations and identifying what produces the reported Contact Info, Identifiers, and Diagnostics entries. Confirm which collection is required for core functionality and compare the result with Bitwarden's Privacy Policy; done means the declarations accurately reflect the app's actual data practices.

Written by the indexing model from the issue text.

Assessment

Tech stack
ios, swift
Domain
mobile, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.