PassVaultify
Privacy policy.
This covers the PassVaultify web vault and the PassVaultify extension for Chrome. The short version: your passwords are encrypted on your device, and nobody else can read them, not a sync server and not us.
No analytics and no ads. By default nothing leaves your browser. If you connect a sync server, it receives your vault only in encrypted form, and it's a server you choose: one you run, or one you trust.
What is stored, and where
- Your vault. Logins, notes and tags are encrypted on your device with a key derived from your master password (AES-256-GCM, PBKDF2-SHA256 with 600,000 iterations). The encrypted vault is kept in your browser's storage: IndexedDB for the web vault, and the extension's own local storage for the extension.
- Your master password is never stored or sent anywhere. Nobody can reset it, including us.
- While unlocked, the extension keeps the vault key in Chrome's session storage, which lives in memory, is private to the extension, and is cleared when the vault locks, when your computer locks, or when Chrome closes.
- Preferences are stored unencrypted next to the vault: the vault's name, theme and colour, auto-lock time, whether autofill suggestions and save offers are on, the sites where you chose never to save, and the date of your last backup.
- Backups are files you download yourself. They stay encrypted with your master password.
- Sync settings, if you connect a server: its address and fingerprint, your account email, and session tokens for that server.
If you connect a sync server
Sync is optional and off until you connect a server by its address. The web vault and the extension then talk only to that server, over HTTPS. It receives:
- Your email, as your account name on that server.
- An authentication key derived from your master password, which it stores only as an Argon2id hash. Your master password itself is never sent, and the key it receives can't decrypt anything.
- Your encrypted vault: the vault header (key-derivation settings, the encrypted vault key and its fingerprint) and each item as ciphertext, with its ID, revision, update time and whether it was deleted.
- Each signed-in device's name (such as "Chrome on Windows"), kind and when it was last active.
The server can see how many items your vault holds, roughly their size, and when they change. It can't see titles, usernames, passwords, websites or notes. The server is run by whoever operates it, under their own policies; PassVaultify (the developer) doesn't run one for you and receives nothing. You can disconnect at any time, sign devices out remotely, and delete the account and everything in it.
What the extension can see on web pages
By default, nothing until you ask. Chrome only lets it into a tab when you click it.
- When you open the popup, it reads the address of the current tab to show the logins saved for that site.
- When you choose Fill, it checks the page for sign-in fields and fills them, but only if the page's address matches a site saved with that login.
- If you turn on autofill on websites, Chrome asks you to grant it access to the sites you visit. It then looks for sign-in fields on the pages you open. When you click into one, it shows a menu of the logins saved for that site's address, or a strong password on a sign-up form. The menu is the extension's own frame, which the page can't read. When you submit a sign-in or sign-up form, it reads the username and password from that form, and nothing else on the page, so it can offer to save or update the login. They are held in memory for up to five minutes, then discarded; on a two-step sign-in, the username from the first step is kept for ten minutes. You can turn either feature off, or turn autofill off entirely, at any time, and the access is removed with it.
What is shared
Nothing beyond the encrypted sync described above, and only with the server you connect. PassVaultify does not sell, transfer or share your data with anyone, does not use it for advertising or credit decisions, and has no way to see it. There is no telemetry or crash reporting.
The use of information received through Chrome's extension APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Deleting your data
Remove the vault from the extension's settings, or uninstall the extension; Chrome deletes its storage. In the web vault, use "Delete this vault" in Settings, or clear the site's data in your browser. Any backup files you downloaded are yours to delete. On a sync server, deleting your account removes it with every device session and item.
Contact
Questions or concerns: open an issue at github.com/furmak331/PassVault.