Key Pass — Privacy Policy

Last updated: July 2026

Key Pass ("the extension", "we", "our") is a password manager Chrome extension. This page explains, clearly and completely, how Key Pass handles data.

Summary

Key Pass does not collect, transmit, sell, or share any user data with us or with any third party. There is no account, no server, and no synchronization. Everything Key Pass stores stays encrypted, on your own device, inside your browser's local storage.

What Key Pass stores, and where

When you use Key Pass, the following information is stored locally on your device only, inside your browser's extension storage (chrome.storage.local and chrome.storage.session):

All of the above is encrypted using AES-256-GCM with a key derived from your master password (PBKDF2, 300,000 iterations). None of it ever leaves your device, is sent to any server, or is accessible to us. We have no server that could receive it even if we wanted to.

How Key Pass detects logins and autofills

To offer to save new logins/signups and to fill saved credentials back into a form, Key Pass's content script reads specific form fields (username/email and password) on the page you are currently viewing. This happens only locally, in your browser, to power the extension's core feature. This information is only written into your encrypted local vault when you explicitly choose to save it — it is never transmitted anywhere.

What Key Pass does not do

Backups

If you use the export feature, Key Pass creates a file containing your encrypted vault (still protected by your master password). This file is saved directly to your computer by your browser; it is never uploaded anywhere by the extension.

Changes to this policy

If Key Pass's data practices ever change, this page will be updated accordingly before the change takes effect.

Contact

Questions about this policy can be sent to: hugomlt44@gmail.com