Privacy Policy

ShieldVault Browser Extension

In plain English

ShieldVault watches what you type or paste on certain websites and warns you when it spots something sensitive — like an API key or a heated message — before you send it. The text is analyzed locally on your device and is not transmitted to ShieldVault.

Settings and a log of detection events are saved locally on your computer so the extension remembers them between sessions. That log contains metadata only, such as the website, time, and detection category — not the sensitive text itself.

If you activate a paid Pro subscription, ShieldVault contacts shieldvault.site only to verify your license key. If you choose to upgrade, ShieldVault may open a checkout page hosted by ShieldVault that uses Stripe to process payment.

If that's all you needed to know, you're done. Everything below is the long version with technical details.

What ShieldVault analyzes locally

ShieldVault is built on a "detection without possession" principle. The extension analyzes text you type or paste in real time to detect sensitive content — API keys, credentials, confidential information, and risky messages — before that content is sent anywhere.

ShieldVault inspects text you type or paste into input fields on these websites:

The analysis runs entirely on your device using local pattern matching. The text being analyzed is never transmitted, stored, or shared. After analysis completes, the text is discarded from the extension's working memory.

What is stored locally on your device

ShieldVault uses Chrome's local extension storage (chrome.storage.local) to remember the following information across browser sessions. This information stays on your device and is not sent to ShieldVault:

All of this data can be cleared at any time by uninstalling the extension or by clicking "Clear" inside the extension's activity panel.

What is transmitted off your device

ShieldVault does not transmit the text you type or paste. It does not transmit detected secrets, messages, activity logs, browsing history, or detection-event content.

ShieldVault makes automatic network requests only for license verification.

When you activate a Pro subscription using a license key, the extension sends the license key string to ShieldVault's verification endpoint (https://shieldvault.site/api/license/verify) to confirm that the key is valid.

These license verification requests transmit only the license key. No browsing data, no detected text, no detection events, no usage statistics, and no personally identifying information are transmitted with the request.

If you do not activate Pro, ShieldVault does not perform license verification.

Payment processing

If you choose to upgrade to Pro, you are redirected from the extension to a checkout page hosted by ShieldVault (https://shieldvault.site/api/checkout/quick), which uses Stripe to process payment. The extension itself never sees, handles, or stores your payment card information. Stripe collects payment information directly under Stripe's own privacy policy. After successful payment, you receive a license key, which you then enter into the extension to activate Pro.

What ShieldVault does NOT do

Permissions explained

ShieldVault requests the minimum permissions necessary:

Children's privacy

ShieldVault is not directed at children under 13 and does not knowingly collect personal information from children under 13.

Changes to this policy

If this policy changes, the updated version will be posted at this URL. Material changes — anything that affects what data is handled or how — will be reflected in the version date below.

Contact

Questions about this privacy policy? Email privacy@shieldvault.site