English
Privacy Policy
In short: since version 0.7.0 Y-Secret-Pass has accounts: your vault syncs across your devices through the Y-Secret-Pass server, and companies can share vaults among employees. Encryption still happens only on your device — the server stores ciphertext it cannot read. To run your account the server knows your email and service details (when and from which address you signed in, which devices are connected). No analytics, no advertising, no tracking, and no sharing of your data with anyone for their own purposes. Versions before 0.7.0 made no network requests at all.
What data the extension handles
Only what you put into it: logins and passwords, website addresses, notes, two-factor (TOTP) secrets, payment cards, personal details for forms, documents, custom fields, previous passwords, section names and files you attach to entries. It also uses your master password and, if you set one up, your keyfile — in memory only.
Your account and the Y-Secret-Pass server
The server runs on the developer's own machine at api.y-secret-pass.com (earlier versions of the extension use
ysp-api.nodo-claro.com, the same server). The extension talks to this address only — its security policy (connect-src) makes the browser block any other.
Stored on the server in readable form:
- your account email and the language of its emails;
- when the account was created and whether two-step verification is on;
- your public key (for shared vaults);
- sessions: device name (“Chrome · Windows”), IP address, browser, sign-in and last-use time;
- your account's security log: sign-ins, failed attempts, password and second-factor changes, password resets and address changes — with time and IP address;
- the Recovery Kit as a fact: whether there is one, when it was made and confirmed, and its public number (the kit's fingerprint is made from it);
- requests to change the account's email: the old and the new address, how (with the master password or with the kit), when it was requested, took effect or was cancelled. Kept for 30 days after they end; unfinished ones while the code is valid (15 minutes).
Stored only encrypted or irreversibly transformed:
- the sign-in key — as an Argon2id hash; the key itself is derived from your master password on your device so that the master password cannot be obtained from it;
- your vault — the same encrypted file that is on your device;
- the wrapped vault key and your private key — encrypted with keys the server does not have;
- the two-step verification (TOTP) secret — encrypted with a server key, as the server needs it to check codes; backup codes — hashes only;
- if you made a Recovery Kit — a copy of the vault key encrypted with the key from the kit, and a hash of a check value derived from it. The server never has the kit's key, and without it this copy opens nothing. A new kit replaces the previous one at once;
- codes sent by email and “This was not me” links — hashes only.
Your master password, keyfile, the key from your Recovery Kit and encryption keys are never sent to the server. The Recovery Kit (a PDF) is made inside the extension, with no network request, and is saved only where you download it; your master password never goes into it.
If you forget the master password and have your Recovery Kit, “Reset password” (the code from the email, two-step verification and the key from the kit) sets a new password for the same vault — your data stays, and the kit is replaced with a new one. Without the kit, the reset creates a new, empty vault: the old data cannot be recovered by you or by the developer.
Changing your email. With the master password the address changes right after you confirm a code sent to the new address; the old address gets an email with a “This was not me” link that can bring the address back within 72 hours. Without access to the old mailbox, the address can be changed with the key from the kit after 72 hours; the old address — and, if you are an owner or admin of an organization, its other owners and admins — can cancel it.
Notices. A password reset with the kit and a change of address are reported by email with the time, IP address and browser name. If you are an owner or admin of an organization, its other owners and admins get the same notice and the event is written to the organization's log.
Organizations (business accounts)
If you create or join an organization, the server also stores: the organization's name, employees' names and emails, their roles and offices, names of shared vaults, access rights, and the organization's log (who granted access, invited, blocked and so on, when and from which IP address).
Items in shared vaults are encrypted on employees' devices with the vault's key; the server keeps only ciphertext and a copy of that key wrapped for each employee, which only that employee can open. Administrators see the organization's log and member list, but not your personal vault.
For each member, administrators see only the fact of a Recovery Kit — yes, no or outdated — and its date, never the key. An organization can require a kit from every member.
If the organization has access recovery on, your device encrypts your key for shared vaults with the organization's recovery key. This lets an owner bring back your access to company vaults if you forget your master password; at that moment your key is decrypted on the owner's device. Your personal vault cannot be recovered this way. You see this in the invitation before joining.
Data on your device and how it is protected
- Your vault is kept in your browser's local extension storage on your device, encrypted with AES-256-GCM.
- Website icons next to your entries come from the browser's local favicon cache: the extension makes no network requests for them, and no site or icon service learns which entries you have. An icon is stored encrypted inside your vault, with its entry.
- The encryption key is protected by a key derived from your master password (and keyfile) with Argon2id.
- Your master password, keyfile and keys are never stored — not on disk, not in browser storage, not in the cloud. If you forget the master password, nobody can recover your data, including the developer.
- Files you attach to entries are encrypted the same way and stored only on your device, in the extension's IndexedDB. Their names are kept inside the encrypted vault.
- Previous versions of the vault (snapshots) are kept on your device, encrypted the same way.
- Archived and deleted items stay inside the encrypted vault, on your device and in the synced copy. A deleted item is kept in the trash for 30 days and then erased for good; you can empty the trash or erase an item right away. Until the snapshots are replaced by newer ones, an earlier version of the vault may still contain it.
- The security check (weak, reused and old passwords, missing two-factor, expired cards and documents, addresses without HTTPS) runs on your device and sends nothing anywhere. Passwords are not checked against online breach databases.
- Some service data is stored unencrypted on your device and never leaves it: settings (including interface language, theme, list density, sort order and generator options), the failed-unlock counter, auto-lock timers, the date of your last backup, and the size and date of encrypted attached files. None of it contains your items.
Sync through your Chrome account (without an account)
Sync is off by default and only you can turn it on. When it is on, the extension puts a copy of the
encrypted vault into chrome.storage.sync, and Chrome carries it to your other computers signed
in to the same account. Chrome does the transfer under Google's sync terms; this sync does not go through the Y-Secret-Pass
server. It is meant for a vault without a Y-Secret-Pass account (for example, one created before 0.7.0); with an account, the
vault syncs through the server described above. Your master password, keys and keyfile are never synced, and attached files
are not synced either — only the encrypted list of them. A vault without an account keeps its Recovery Kit copy (the vault key
encrypted with the kit's key) on the device and in this sync copy, so a new computer can be recovered with the kit too.
Without your master password the copy is unreadable ciphertext, to Google and to the developer alike.
Fingerprint or security key unlock
If you enable it, the extension registers a key on your authenticator (fingerprint sensor, device PIN or a security key such as a YubiKey) using the WebAuthn standard. Your fingerprint never reaches the extension — the device checks it. The secret the authenticator returns is used in memory and never stored; only an encrypted copy of the vault key and public parameters stay on disk.
Access to web pages
The extension touches a page only when you click a button in its window: to fill a login or a form, to save a login you have typed (it then reads the username and password from the visible form, and the page title as the suggested entry name, to store them in your vault), or to insert a generated password into a sign-up form. It has no permanent access to any website. Page content is not read, stored or sent anywhere.
Backups and export
A backup is the same encrypted file that is stored on your device, attached files included. To move to another password manager you can export without encryption (Bitwarden JSON or CSV); this requires your master password again, and the file is saved straight to your computer — the extension does not keep or send it. That file contains your passwords in plain text: delete it after importing.
Who else processes data
- Cloudflare — the network in front of the server: the extension's requests pass through it (your address, email at sign-in and sign-up, the sign-in key, ciphertext). Cloudflare receives neither your master password nor your encryption keys.
- Brevo — the email service: it receives your email address and the text of the message (a confirmation code, a password-reset code, an address-change code, an organization invitation, notices of a reset with the Recovery Kit and of an address change — with time, IP address and browser name).
Neither they nor anyone else gets your data for advertising, analytics or any purpose of their own.
What we do not do
-
We do not send your data anywhere except the Y-Secret-Pass server, and that only encrypted, apart from what section 2 lists.
The extension's security policy (
connect-src) makes the browser block every other address. - We do not collect analytics, usage statistics or crash reports.
- We do not sell user data or share it with third parties for their purposes (see section 9 for the services we use).
- We do not use your data for advertising, creditworthiness or any purpose unrelated to managing your passwords.
- We do not load or run remote code. All code ships inside the extension package.
Browser permissions
Each permission is used only to provide the password manager's features on your device.
| Permission | Why it is needed |
|---|---|
storage |
Keep the encrypted vault, settings and the signed-in account's session on your device, and — only if you turn Chrome sync on — an encrypted copy in your Chrome account. |
unlimitedStorage |
Keep encrypted attached files from being evicted by the browser when the disk runs low. |
offscreen |
Hold the key of the unlocked vault in a separate extension document that is destroyed on lock, and clear the clipboard. |
activeTab, scripting |
Fill a saved login or form into the current page, or save the login you typed there — only when you click. |
clipboardWrite |
Copy a password when you click copy, then clear it after a timeout. The extension cannot read your clipboard. |
alarms, idle |
Lock the vault after inactivity or when your screen locks, and clear the clipboard on time. |
favicon |
Show website icons next to saved logins from the browser's local favicon cache. No network requests are made and no browsing data leaves the device. |
How long data is kept and how to delete it
Your account is kept until you delete it: Settings → Account → “Delete account” (with your master password and code again). This removes from the server your account, the vault copy, sessions, the account's security log and your organization memberships; an organization nobody else is in is deleted with it. In logs of organizations where others remain, your actions stay without your name and IP address. The vault on your device stays.
- The security log is kept for one year.
- Server database backups are kept for 14 days on the same machine, closed to others; deleted data leaves them after that.
- A session unused for 30 days stops working and is deleted 30 days later.
- Email change requests are deleted 30 days after they end; the Recovery Kit copy is kept until a new kit replaces it or the account is deleted.
Removing the extension deletes the vault, attached files and settings it stored in your browser (your account stays on the server until you delete it). If you used Chrome sync, first use “Delete the copy from the account” (Settings → Sync). Keep your own backup if you want to keep your passwords.
Changes to this policy
If this policy changes, the updated version will be published on this page with a new effective date.
Contact
Questions about this policy can be sent through the Support tab of Y-Secret-Pass on the Chrome Web Store.