Last updated: July 2026
Key Pass ("the extension", "we", "our") is a password manager Chrome extension. This page explains, clearly and completely, how Key Pass handles data.
Key Pass does not collect, transmit, sell, or share any user data with us or with any third party. There is no account, no server, and no synchronization. Everything Key Pass stores stays encrypted, on your own device, inside your browser's local storage.
When you use Key Pass, the following information is stored locally on your device only, inside your browser's extension storage (chrome.storage.local and chrome.storage.session):
All of the above is encrypted using AES-256-GCM with a key derived from your master password (PBKDF2, 300,000 iterations). None of it ever leaves your device, is sent to any server, or is accessible to us. We have no server that could receive it even if we wanted to.
To offer to save new logins/signups and to fill saved credentials back into a form, Key Pass's content script reads specific form fields (username/email and password) on the page you are currently viewing. This happens only locally, in your browser, to power the extension's core feature. This information is only written into your encrypted local vault when you explicitly choose to save it — it is never transmitted anywhere.
If you use the export feature, Key Pass creates a file containing your encrypted vault (still protected by your master password). This file is saved directly to your computer by your browser; it is never uploaded anywhere by the extension.
If Key Pass's data practices ever change, this page will be updated accordingly before the change takes effect.
Questions about this policy can be sent to: hugomlt44@gmail.com