VaultPassword Privacy Policy

This Privacy Policy describes how VaultPassword ("we", "our", or "the extension") collects, uses, and protects the information gathered when you use our password management extension. By using VaultPassword, you agree to the collection and use of information in accordance with this policy.

Information We Collect

VaultPassword collects information that you directly provide when using the extension. This includes, but is not limited to:

Additionally, to improve our services, VaultPassword collects anonymous usage statistics such as device type, operating system and which features are used. This information cannot be linked back to your account or to the contents of your vault. See Usage Analytics below for the full detail of what is and is not collected, and how to opt out.

Use of Information

The information collected is used to:

Security of Your Information

The security of your information is of the utmost importance to us. We implement industry-standard security measures to protect the data collected by the extension, including end-to-end encryption for stored credentials and secure transmission protocols (HTTPS/TLS) for all data in transit. Your master password is never stored on our servers — only a secure hash is used for authentication.

Data Retention

We retain your personal data for as long as your account is active or as needed to provide you with our services. You may request deletion of your data at any time. Upon account deletion, all stored credentials, personal information, and associated data are permanently removed from our servers within 7 business days.

Information Disclosure

VaultPassword does not sell, rent, or share your personal information with third parties, except in the following circumstances:

Usage Analytics

To understand how VaultPassword is used and where it can be improved, our browser extension and mobile application send anonymous usage events to Umami, an open-source analytics platform that we host ourselves on our own infrastructure. Your data is never sent to Google Analytics or to any other third-party advertising or analytics provider.

What we collect:

What we never collect through analytics:

Analytics events carry no cookies and no persistent identifier. Because no identifier is sent, we cannot reconstruct the activity of an individual user from this data; it is only ever read in aggregate.

Opting out. Usage analytics are enabled by default and can be disabled at any time. In the browser extension, go to Options → About and turn off Anonymous stats; in the mobile application, open the Account tab and turn off Anonymous stats. Once disabled, no further events are sent from that installation. This setting is independent of the data processing strictly necessary to operate the service.

Cookies and Tracking

VaultPassword does not use tracking cookies for advertising or profiling purposes. We may use session cookies strictly necessary for authentication and secure access to your account. Our usage analytics, described above, do not use cookies at all.

Third-Party Services

Our extension may integrate with third-party services to enhance functionality. These third parties have their own privacy policies and we encourage you to review them. We are not responsible for the privacy practices of these external services.

Breach check (haveibeenpwned.com)

Our public breach check page at /breach-check sends the email address you type to Have I Been Pwned so it can be looked up against known data breaches. The lookup runs on our server so that our API key is not exposed; the address is not written to our database, our logs, or our analytics. The result is cached for a limited time under a keyed hash of the address, never the address itself. Using that page does not create an account and does not require one.

Inside the extension and the app, the password breach check is a different mechanism: it uses the k-anonymity range API, which means only the first five characters of a SHA-1 hash ever leave your device. Your passwords are never sent anywhere.

Advertising measurement

When you arrive at our site by clicking a paid advertisement, the landing page loads a measurement script from our advertising network so that the network can tell that its click reached us. This happens only for visits that arrive with an advertising click identifier in the URL; visits from search engines, from our apps, or typed directly do not load it at all.

Separately, we keep our own count of landing-page visits and breach checks on our server. Those records contain the traffic source, the campaign name, the device type and the language — and deliberately no email address, no IP address, no browser fingerprint and no advertising click identifier. They cannot be traced back to a person, and they exist only to tell us whether an advertising campaign is worth its cost.

Children's Privacy

VaultPassword is not intended for use by children under the age of 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately so we can take appropriate action.

Changes to This Privacy Policy

We reserve the right to update this Privacy Policy to reflect changes in our information collection and protection practices, or to comply with new legal requirements. We will notify you of significant changes through the extension or via email. Continued use of VaultPassword after such changes constitutes your acceptance of the updated policy.

Your Rights

Depending on your jurisdiction, you may have the right to:

To exercise any of these rights, please contact us using the details below.

Contact

If you have any questions about this Privacy Policy or the handling of your data, please contact us at [email protected].

Acceptance of Terms

By using our extension, you agree to this Privacy Policy. If you do not agree with this policy, please do not use the VaultPassword extension.