VaultWatch Privacy Policy
VaultWatch does not collect your data. It does not send your extensions, cookies, browsing or page content to the developer or to anyone else. Everything it checks is processed and stored on your own device.
What VaultWatch looks at
VaultWatch protects your accounts from session theft. To do that, it handles the following information. All of it stays in your browser.
- Your installed extensions. Names, versions, permissions and how each was installed, so it can rate their risk and tell you when a new one appears or an update adds access.
- Login cookie details, only if you allow cookie access. Cookie names, the site they belong to, and whether they are marked Secure or HttpOnly, so it can find weak login cookies. Cookie values are never stored, shown or sent anywhere.
- Cookie timing, only if you allow cookie access. When a website sends a cookie, VaultWatch keeps the cookie's name and the time in memory for about 30 seconds, then discards it. This lets it tell whether a cookie came from a website or was inserted by something on your computer.
- Sign-in page checks, only if you turn on Page Shield. On pages with a visible password box, it reads the page title, main headings, site name and the address the form sends to, and compares them with the site you are on. It never reads what you type. Page text and form contents are not kept.
- The site you are on, when you click the VaultWatch icon, so you can turn on Site Lockdown for it.
What VaultWatch stores
VaultWatch saves the following in your browser's local extension storage: the latest extension scan, your alerts (including the website address each alert is about), sites you have muted or ignored, extensions you marked as trusted, sites you locked down, your on/off choices and, if you set one, a threat feed address. This data is not synced and is deleted if you uninstall VaultWatch. You can clear your alerts at any time from the Alerts tab.
Network use
By default VaultWatch does not contact any server. There are two situations where you may see it or the browser make a connection:
- Optional threat feed. If you enter a feed address, VaultWatch downloads a list of known harmful extensions and its signature from that address, and checks the signature before using it. It sends nothing about you or your extensions. As with any web request, the server you chose can see your IP address and the time of the request. The feed is data only and is never run as code.
- Security pages. When you choose "Clear and open security page", VaultWatch opens the website's own account or security page in a new tab. That is a normal visit to that website.
Sharing and use of data
- We do not sell or transfer user data to anyone.
- We do not use data for advertising, profiling, analytics, or any purpose unrelated to VaultWatch's single purpose of protecting you from session theft and account takeover.
- We do not use or transfer data to judge creditworthiness or for lending.
- No person reads your data, because it never leaves your device.
The use of information received from Chrome APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Why VaultWatch asks for its permissions
| Permission | Used for |
|---|---|
| management | Listing your extensions to rate them, and turning one off or removing it when you click. |
| storage | Saving the local data described above. |
| alarms | Re-checking extensions every 30 minutes and refreshing the optional feed every 6 hours. |
| notifications | Alerting you to high-risk findings. |
| scripting | Running the Page Shield check, only after you turn it on. |
| activeTab | Knowing which site you are on when you open VaultWatch. |
| declarativeNetRequest | Site Lockdown: limiting scripts on a site you choose to those from that site itself. |
| cookies (optional) | Checking login cookie settings, and clearing cookies when you click "Sign out and clear". |
| webRequest (optional) | Watching, without changing anything, whether a cookie was sent by the website. |
| All-site access (optional) | Running Page Shield, cookie checks and Site Lockdown on the sites you choose. |
Optional permissions are requested only when you use the feature that needs them.
Children
VaultWatch is a general security tool and is not directed at children under 13. It does not knowingly collect information from anyone.
Changes to this policy
If VaultWatch's data practices change, this page will be updated and the effective date above will change. If a change needs new permissions, Chrome will ask you to approve them.
Contact
Questions about this policy or VaultWatch: ammiller1151@gmail.com