Privacy policy for GalaxyPass
GalaxyPass by GalaxyOrb LLC
Privacy
What GalaxyPass (the web app, and any connected client such as the browser extension) sends to your GalaxyPass server, and what it never sees.
What never leaves your device
Your vault's passwords, notes, API keys, and SSH keys are encrypted on your device before anything is sent anywhere. Your User Root Key — the key that everything else is derived from — is generated on your device, never transmitted in usable form, and never held by the server. GalaxyPass cannot read your vault contents, and neither can anyone who gains access to the server or its database.
What does get sent, and whyYour account identity (email, display name) — from GalaxyOrb SSO, to sign you in.
Encrypted vault item data (ciphertext only) and non-sensitive metadata (item type, favorite flag, timestamps) — so your vault can sync across your devices.
A device-specific public key when you connect a new client (e.g. this browser extension) — used to wrap a copy of your vault key for that device only. The matching private key is generated on that device and never transmitted.
What GalaxyPass does not doNo third-party analytics or advertising trackers.
No selling or sharing of your data with anyone.
No access to page content beyond what you explicitly ask the extension to fill or save.
The browser extension specifically
The extension detects login forms on pages you visit so it can offer to autofill or save a password — this happens entirely locally in your browser. It only contacts your GalaxyPass server when you explicitly connect it, ask it to load your vault items, or save/update an item, and everything it sends is encrypted the same way described above.
https://pass.galaxyorb.cloud/privacy