English
Summary: Aperture Vault is a local-only password manager. It has no developer-operated server, analytics, advertising, telemetry, cloud sync, or third-party network SDK, and it does not send your vault data to the developer or independent third-party infrastructure.
1. Scope
This policy describes how the Aperture Vault browser extension processes information. Aperture Vault’s single purpose is to store sign-in credentials locally in encrypted form in the current browser profile and, after a user action or per-origin authorization, manage, review, and fill credentials on exactly matched sites.
2. Data processed
Aperture Vault processes only data needed for its user-facing password-management features, including:
- site name, exact origin (scheme, hostname, and port), and an optional path prefix;
- username, password, and notes;
- locally generated passwords with their creation times and exact origins, and replaced credential passwords with their timestamps;
- last-used timestamp and use count stored in the encrypted vault;
- language, theme, auto-lock policy, and origins where the user separately enabled candidate detection or post-submit save prompts;
- the master password while the user enters it on a secure extension page; and
- the current page title, origin and path, login-form structure, labels, and field metadata needed locally to identify sign-in fields for an explicit read or fill, or for an enabled trusted-submit prompt.
When the user selects “Read and save current login,” the extension examines the current page and sign-in form locally, reads the selected username and password, and asks for confirmation in a secure extension window. It does not retain a copy of the page or the full form.
The user can explicitly generate a password in the manager or beside a recognized HTTPS registration/password-change field. Generation uses local browser cryptographic randomness and writes encrypted recovery before displaying, copying or explicitly filling the new and confirmation fields. It never submits the website form or determines whether the site accepted a password. A webpage generation context (origin/path, title, username, tab/frame/document and field-binding identifiers, and expiry) is held in trusted extension session storage for at most ten minutes without the generated password, and cleared on lock, replacement or related window/tab closure. A save review opened after generation uses the ten-minute manual-review lifetime below.
The user may separately enable post-submit save or update prompts for one exact HTTPS origin. This feature operates only while that origin’s optional permission remains granted and the vault is unlocked. After a trusted click or Enter action leads to a native form submission, the extension reads the username and password once only if the form action remains on the same HTTPS origin, the form has one login-password field and a high-confidence account field, and the flow does not appear to be registration, password change, one-time-code, or payment entry. Confirmation is still required before any save or update.
Pending review data is held temporarily in the browser’s memory-backed storage.session. It can include the proposed username and password, page title, source origin and path (without query parameters or fragments), operational identifiers and timestamps needed to connect and expire the review, the suggested save/update mode, and one or more existing candidate identifiers. An explicit manual capture is retained for at most 10 minutes; an enabled trusted-submit prompt is retained for at most 2 minutes. Pending data is cleared on confirmation, cancellation, expiry, lock, vault replacement, or closure of the related tab or review window. The extension does not continuously monitor input, serialize the full form, or silently save or overwrite a credential. The master password is processed only while entered to derive or unlock the encryption key; it is never stored, transmitted, injected into, or shared with the current website.
3. Local storage and security
- The credential vault—including saved site records, credentials, notes, and their usage metadata—is encrypted with AES-256-GCM before it is written to browser local storage.
- Generated-password recovery and replaced-password history are encrypted inside the same vault, never written to unencrypted preferences, indexed for search, or sent to other websites.
- The master password is never stored. A key is derived using PBKDF2-HMAC-SHA-256, a random salt, and 600,000 iterations.
- The raw unlocked key is kept only in browser memory-backed session storage and is removed on lock, timeout, or browser-session end.
- The in-memory search index exists only on an unlocked extension page and is cleared on lock.
- Non-sensitive preferences and operational settings—including language, theme, auto-lock policy, and per-origin feature enablement—are stored separately in browser local storage and are not part of the encrypted credential vault or its encrypted backup.
- Exported JSON backups remain encrypted and protected by the master password.
- If the user chooses Copy, the selected plaintext password is written to the operating-system clipboard. The extension does not automatically clear the clipboard; later retention is controlled by the operating system and user environment.
4. Network transfer and third parties
Aperture Vault contains no developer-operated remote server, analytics, advertising, telemetry, cloud sync, or third-party network SDK. It does not send credentials, site information, search queries, usage records, or vault contents to the developer, advertising or analytics services, cloud services, or independent third-party infrastructure. It does not sell user data or use it for advertising, creditworthiness, lending, or an unrelated purpose, and it does not expose vault data to human review.
Data leaves the extension only through a user-directed local action: filling the selected username and password into sign-in fields on the current exactly matched site, copying a selected password to the operating-system clipboard, or downloading an encrypted local backup. If the user submits a filled form, that chosen site’s own privacy policy governs its processing of the submitted data.
5. Browser permissions
storage: stores the encrypted vault, non-sensitive settings, and memory-backed session state.alarms: triggers the selected local idle lock and clears expired pending reviews even when no Vault page is open; it makes no network request.activeTab: accesses the current tab after the user clicks the extension or invokes its shortcut.scripting: injects the isolated sign-in candidate, form-reading, and fill interface on demand.- Optional website access: requested only after the user enables candidate detection or separately enables post-submit save prompts for an exact HTTPS origin. Even if the browser grants host-level access, the extension validates the exact scheme, hostname, and effective port.
The extension does not download, execute, or reference remote code. All executable code is included in the Manifest V3 store package.
6. Retention, control, and deletion
Data remains in the user’s browser profile until the user deletes a credential, imports another backup, clears extension data, or uninstalls the extension. The user can view, edit, or delete individual credentials; export an encrypted backup; turn off per-site features; revoke website access that is no longer required; lock the session; or uninstall the extension to clear extension data.
Generated recovery retains at most the newest 20 records for 30 days. Expired records cannot be accessed and are removed from the encrypted payload on the next unlocked vault read or write. Each credential retains its ten most recent replaced passwords; the user can clear this history, and deleting the credential also deletes its history. Restoring a password changes only the local record, not the website password. Exported backups are encrypted historical snapshots; deleting or expiring records inside the extension does not modify those files. Users manage and remove their backup files separately.
7. Chrome Web Store Limited Use
Aperture Vault’s use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide or improve the extension’s user-facing local password-management features. Except for the user-directed fill, clipboard, and encrypted-export actions described above, it is not transferred outside the extension. It is never transferred for advertising, creditworthiness, lending, or unrelated purposes and is not exposed to human review.
8. Changes to this policy
If the extension’s data practices change, this page will be updated before or when the relevant extension update is released. The effective date and applicable version shown above identify the current policy.
9. Contact
For privacy or support questions, open an issue in the public privacy-policy issue tracker. Do not include passwords, master passwords, backup files, or other secrets in a public issue.