Data kept on your device
The web application and Chromium Extension each keep a separate encrypted vault in IndexedDB. Unlocking makes vault contents and the data-encryption key available locally. See Architecture for where each client runs these operations.
| Data | Location and lifetime |
|---|---|
| Encrypted vault | IndexedDB in the web application's origin or extension storage. Persists across restarts until the vault or its storage is removed. |
| Unlocked web session | Vault contents and active key in page memory, cleared from application state on lock, reload, or tab close. |
| Unlocked extension session | Vault contents, active key, temporary credential drafts, and service session in chrome.storage.session. Cleared on vault lock or when Chrome clears the extension session. |
| Protection phrase | Derived protection-phrase material can persist in local IndexedDB across locks and restarts. It still requires the master password to unlock the vault. |
| Security-key protection | WebAuthn PRF credential metadata stays on the device. The authenticator supplies the additional key material when you unlock. |
| Backup receipt and preferences | A local receipt records backup time and an encrypted-state fingerprint, not the backup itself. Receipts, vault selection, and interface settings can persist across restarts. |
See unlock factors for how the protection phrase and security key are used.
Closing the extension popup does not clear its unlocked session. Chrome clears extension session storage when the extension is disabled, reloaded, or updated, and when the browser restarts.
What leaves the device
Local vault use does not require an Online Services account. Loading the hosted web application still contacts its web host. Self-hosting changes which host receives those requests; custom synchronization uses the servers you configure.
| When | Recipient and data |
|---|---|
| Loading the hosted app | The web host and any HTTPS-terminating proxy receive the requested URL, request headers, IP address, and timing needed to serve the application. |
| Linking or connecting devices | The signaling server receives channel identifiers, presence, and connection-negotiation messages. WebRTC setup information can include IP addresses and ports. |
| Establishing a device connection | STUN receives network-address information. If TURN relays the connection, it sees addresses, timing, and encrypted traffic volume. |
| Synchronizing | The linked device receives encrypted records and decrypts them locally. A TURN relay carries the encrypted exchange when a direct route is unavailable. |
| Using Online Services | The API receives device-authentication messages, identifiers, and the configuration or operation being requested. Vault passwords and plaintext vault contents are not used to authenticate these requests. |
| Uploading or downloading a managed backup | The API handles backup metadata and issues a temporary signed URL. Object storage transfers the encrypted snapshot directly with the client. |
| Opening a flow with CAPTCHA | Cloudflare Turnstile receives browser and challenge information for its bot check. The client sends the resulting token with the protected request, such as registration or recovery. |
| Opening checkout | Stripe and Link handle checkout requests and the payment details entered there. The service receives the resulting subscription and payment status. See Managed Payments. |
HTTPS encrypts request contents between the browser and the server terminating TLS. A passive network observer can see connection addresses, timing, and traffic volume, but not the HTTP path, headers, or body inside that encrypted connection.
The credential list uses built-in icons rather than requesting favicons for saved websites. Clicking a saved website link opens that destination and makes an ordinary browser request to it.
This table describes what each service receives, not what it keeps in logs. See server-log retention below.
Managed backup metadata
Managed backups are encrypted locally before upload. The storage provider receives encrypted bytes. The API tracks snapshot and object identifiers, byte size, SHA-256 checksum, source device, timestamps, and upload or deletion state.
Device and root-device associations determine which snapshots are eligible for recovery. See root-device permissions. The upload does not send the vault password, vault recovery code, additional protection secret, or plaintext vault contents.
Backup pruning and the subscription grace period follow the published retention rules.
Providers, analytics, and logs
Our production infrastructure, STUN/TURN servers, and managed encrypted backup storage are hosted in Europe. If you self-host, your chosen providers and logging settings apply to those services.
We use Cloudflare to proxy hosted traffic and run Turnstile bot checks. Its HTTP Traffic analytics reports on requests and bandwidth handled by Cloudflare's servers. Cloudflare Web Analytics and RUM are not enabled, so their browser analytics script is not loaded. Turnstile uses separate browser code for bot checks.
- Web diagnostic logs
- Held in memory, with up to 500 entries per category. Cleared when the vault locks or the page session ends.
- Extension diagnostic logs
- Stored locally in
chrome.storage.local, capped at 2,000 entries. They survive closing the popup and are separate from the unlocked session. - Our operational/security logs
- Retained for 30 days. These hosted-service logs can include request identifiers, IP addresses, timestamps, outcomes, and diagnostic information.
Diagnostic logs are not uploaded automatically. You can export them to a file and choose whether to share it. Check it for device identifiers, connection details, and errors before sharing. The 30-day retention period applies to our operational/security logs, not third-party provider logs or logs on self-hosted servers.
Deletion and your controls
- Lock the vault
- Clears the active unlocked vault and key from application state. Keeps the encrypted vault, locally retained protection material, and existing backups.
- Delete a local vault
- Removes that installation's local vault. It does not erase copies on linked devices, downloaded files, or managed backups. Clearing the web app's site data removes its local storage as well.
- Pause managed backups
- Stops new uploads. Existing snapshots remain subject to the retention rules.
- Delete managed backups
- Requests deletion of selected stored snapshots within your device's permissions. It does not delete the live local vault or copies already downloaded.
- Delete your Online Services account
- Revokes service sessions and queues managed backup objects for deletion without the subscription grace period. It does not remotely erase local vaults. See service deletion.
Downloaded backups, exported logs, and JSON exports remain wherever you saved or shared them. JSON exports are not encrypted. For backup instructions, see Backups; for privacy requests, see the privacy policy.