TL;DR: A password vault is the one place a lock-in is unacceptable, and it is exactly where users are getting locked in. PainHunt's Security cluster reports lifetime licenses revoked by an update, with vault data and attachments stranded behind a fresh paywall. The opportunity is a portability layer for credential vaults — the escape hatch that makes any manager's terms reversible.
The evidence
Password Management is one of the higher-intensity clusters in PainHunt: average score 11.4/15 and intensity 8.4/10, with high-signal posts arriving through Google Play and the App Store — paying users, writing at the moment access breaks.
The complaint is specific and unusually alarming for a security product. Lifetime PRO access is revoked after an app update, forcing users to pay again for features they already owned. Functionality they relied on is locked behind a new paywall with no path back to what they had. One user reports critical password data with attached images that may become inaccessible — a vault turning read-only or worse. And when it breaks, there is no one to call: users report missing or hidden support contact information, no email or phone channel for what is, for them, an emergency.
The requested features are a portability charter written by the burned: guaranteed access that persists across future updates, a transparent migration path for existing data without a forced repurchase, and — tellingly — visible support to reach a human when a vault is on the line.
The through-line is that the most security-critical data a consumer owns is being held hostage by a business-model change, and the user has no leverage.
Why now
Consumer password managers moved to subscriptions, and the transition stranded a generation of lifetime-license buyers. When a vendor re-prices, the vault does not move with the user; it sits inside the app whose terms just changed. That was a nuisance for a note-taking app. For a password vault it is a hostage situation, because the data is both essential and, by design, hard to get out.
The lock-in is also structural to the category. A password manager's stickiness is its whole moat — attachments, TOTP seeds, autofill mappings, and structure that no clean export preserves. Vendors have every incentive to keep the exit rough, and until now no one has made the exit itself the product.
So the data is maximally sensitive, the business models are in flux, and the exit is deliberately narrow — which is the precise condition under which users will pay for a guaranteed way out.
The wedge
Do not build a better password manager. Build the exit that makes every password manager safe to leave.
- A portability layer that performs a complete vault extraction — credentials, TOTP seeds, attachments, folder structure — from the major managers, preserving what native exports drop.
- A migration path between managers that is one action, not a weekend, so a revoked license is an inconvenience rather than a loss.
- A continuous encrypted backup of the vault's contents in a portable, open format, so access is never solely the vendor's to revoke.
Start by being the thing a user runs the day their lifetime license gets pulled — and then the thing cautious users keep running before it ever does.
Risks and honest caveats
- You are handling the most sensitive data there is. A portability tool for password vaults that is itself compromised is a catastrophe. Local-first, zero-knowledge handling is not a feature here; it is the precondition for existing at all.
- Vendors will fight the exit you are selling. Export APIs can be narrowed, formats changed, terms updated to forbid third-party extraction. The product lives on a surface its targets control, and that fragility has to be designed around and disclosed.
- "Trust me with all your passwords to protect your passwords" is a hard sell. The trust bar is higher than for almost any other tool, and it is earned through openness — open formats, auditable handling, local operation — not marketing.
- Willingness to pay spikes at the moment of loss and fades after. People buy when locked out and forget when safe. The durable version is the always-on backup that quietly earns its keep, not the one-time rescue.
How to validate this further
Read the Security threads in the Pain Point Browser and test the escape-hatch framing with the Idea Validator. Related: safe ESP list migration and syncing entitlements across platforms.