Privacy policy for IronVault — Secure Autofill
IronVault — Secure Autofill by Saket
IronVault Browser Extension — Privacy Policy
This policy describes what the IronVault browser extension ("IronVault — Secure Autofill") accesses, stores, and transmits. Form detection and autofill happen locally. Information you explicitly save is encrypted on your device before the encrypted vault syncs with the IronVault API; vault plaintext and your master password never leave your device.
Full policy: https://www.ironvault.app/privacy/extension
Effective date: August 9, 2026
The IronVault extension is an autofill companion to your IronVault account. Vault contents, including passwords, TOTP secrets, credit cards, identities, notes, and passkeys on supported browsers, are protected with end-to-end encryption using AES-256-GCM and a key derived locally from your master password with PBKDF2. Encryption and decryption happen only on your device after you unlock. Your master password and derived encryption keys are never transmitted, and IronVault cannot read your vault contents.
- Web pages you visit (content scripts): reads relevant form fields locally to detect supported login, TOTP, card, and identity forms; offers matching vault items only when you focus a supported field; and fills a selection you request. If you choose Save, Update, or Quick Note, the submitted values, selected passage, and source URL become a vault record on your device and are included only inside an encrypted vault blob sent to the IronVault API. They are never sent in plaintext or to a third party.
- storage: keeps the encrypted vault cache, preferences, and local session state. Decrypted material is limited to extension session storage and is cleared when the extension locks or the browser session ends.
- activeTab / tabs: identifies the active page and correct frame for user-requested matching and fill actions.
- contextMenus: lets you explicitly capture selected text as a Quick Note or another supported vault record.
- notifications: shows important session or autofill notices on supported browsers.
- alarms: enforces the session timeout and local auto-lock.
- clipboardWrite: copies a password or one-time code only when you request it.
- downloads: detects a password CSV you explicitly exported from the browser for import into your unlocked vault, then removes the temporary download or history entry where the browser supports that cleanup.
- Host permissions: privileged network access is limited to www.ironvault.app and ironvault.app for authentication and encrypted vault sync.
The extension communicates only with the IronVault API over TLS. Account sign-in sends your email address and an account-password hash, or a short-lived pairing code. Vault sync sends an encrypted vault blob that may contain credentials, saved URLs, selected text, cards, identities, and other records, but IronVault does not receive the plaintext or encryption key.
Browser and operating-system details may be used to label connected browser sessions and provide your security activity history. In Firefox, the technical and interaction data permission is optional. If you decline it, IronVault uses a generic browser-session label and suppresses optional activity metadata without disabling encrypted vault sync.
The extension contains no advertising trackers, product analytics, remote executable code, or requests to third-party services.
IronVault stores your account email address, a salted cryptographic hash of your account password, encrypted vault blobs, account and entitlement records, and the limited session/security metadata described above. The account password itself, master password, derived keys, and vault plaintext are not stored. We do not sell personal data, use it for advertising, or build a cross-site browsing profile.
Matching saved items, generating passwords or one-time codes, and filling forms are performed on your device. Values you type on a third-party website are never transmitted to IronVault in plaintext. Only information you explicitly choose to save or update can enter the encrypted vault blob used for sync.
Encrypted vault data is retained while your account is active so it can sync across your devices. You can delete your account and its data at any time; see how to delete your IronVault account (https://www.ironvault.app/delete-account). Account deletion removes the account record and encrypted vault data from our servers, subject to limited legal or security retention described in the general policy.
If these practices change, we will update this page and effective date. Material changes will be highlighted in the app or extension.
Questions about this policy or your data: support@ironvault.app (mailto:support@ironvault.app). The general IronVault Privacy Policy (https://www.ironvault.app/privacy) covers the web and mobile apps.