The short version
QtPass is free software, released under the GNU General Public License, version 3 or later (GPL-3.0-or-later). Copyright belongs to IJHack and the contributors; the source files and the commit history name the individual authors. You can read it, change it, redistribute it, and sell it, as long as whatever you redistribute stays under the same license and keeps the source available.
The pieces
The GPL covers the application. This website is a different kind of thing (prose, screenshots, a typeface someone drew by hand), so it is licensed piece by piece instead of as one blob:
- Pages and scripts: GPL-3.0-or-later, same as the app, copyright IJHack.
- HTML content itself (the words you're reading): CC BY 4.0, copyright IJHack. Quote us, translate us, put it on a poster; just say where it came from.
- The logo: based on Heart-padlock by AnonMoos, CC0 1.0 (public domain).
- Screenshots: pictures of QtPass itself, CC0 1.0: use them in an article, a store listing or a wiki without asking.
- The typeface: this page is set in Lato, designed by Łukasz Dziedzic and released under the SIL Open Font License 1.1.
- Platform logos: Tux, the Windows and Apple logos and the BSD logos belong to their owners. They are shown only to say that QtPass runs on those systems.
- One specific exception: the OpenBSD puffer fish on the downloads page is CC BY 1.0, credited to art.gnux.info via Wikimedia Commons.
How we keep track
None of the above is just written down and hoped for. Both branches of
the repository, the application's main and this website's
gh-pages, carry a machine-readable
REUSE / SPDX manifest, and a CI
job runs on every push that fails if a file's license cannot be
determined (for the website, the generated API documentation
excepted). The REUSE badge in the footer shows the live result for the
application's repository: click it rather than take our word for it.
Third-party software
QtPass is a GUI for
pass, built on
Qt, and optionally calls out to
gpg and
git. None of those are ours to
relicense: each is developed separately, under its own license (Qt is
LGPLv3/GPLv3 depending on the module; pass,
gpg and git are GPL). QtPass links against
and shells out to them; it doesn't absorb them.
The fun part
A password manager spends a lot of its design energy proving that what it says about your data is actually true, not just asserted; this site's security page goes into surprising depth on that. Licensing gets the same treatment, just for lower stakes: the REUSE badge in the footer is not decoration, it is a check that every file in the application's repository is licensed as it claims to be. So in a small way, the page you are reading right now is held to the same standard as the vault it's advertising.
And if you've read this far: yes, this page itself is CC BY 4.0. Take it, adapt it for your own project's licensing page, tell people where you got it. That's the whole point of the license.