Privacy policy
Last updated September 27, 2026
ChromePW is a password vault for credentials you enter manually. It uses Chrome's storage APIs to keep and synchronize vault data. The extension does not inspect websites, read browsing history, autofill forms, use analytics or advertising services, or make its own network requests. The developer does not receive your vault data.
Information you enter
For each saved credential, ChromePW handles a website label, a username (which may be an email address), and a password. It also creates vault settings and identifiers needed to encrypt, synchronize, and restore your data.
Passwords are encrypted on your device before storage, using a key derived from your master secret. Website labels and usernames remain readable within the stored records so you can select a credential before unlocking it. Your master secret is used in the extension while you perform a protected action; it is not saved. A decrypted password is shown only when you request it. If you choose Copy password, the plaintext password is placed on your system clipboard.
Where data is stored and shared
- ChromePW stores vault records in
chrome.storage.sync. If Chrome Sync is enabled, Chrome synchronizes those records between browsers signed into the same Google account. This uses Google's Chrome Sync service, not a server operated by the ChromePW developer. - ChromePW keeps a copy of the vault records in
chrome.storage.localon each computer for recovery. Passwords remain encrypted in this copy; website labels and usernames remain readable within it. - When you export a backup, ChromePW creates a JSON file on your device. The file contains encrypted passwords and readable website labels and usernames. You choose where to keep or share that file. Importing a backup adds its records to Chrome Sync.
ChromePW does not sell vault data, use it for advertising, or send it to the developer or other third-party services. Chrome and any destination you choose for an exported backup handle data under their own policies.
Your choices
You can edit or delete credentials, delete other vaults, or reset your vault in ChromePW. Changes to synchronized records can reach your other Chrome browsers. Exported backup files remain wherever you saved them until you delete them yourself. Removing the extension can also remove its Chrome Sync data, so keep a backup file if you need to preserve the vault.
Limited use
ChromePW uses data only to provide its password vault, synchronization, and backup features. Its use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Questions
For privacy questions, open an issue in the ChromePW repository. This policy applies to the ChromePW extension. This page is hosted on Netlify, which may process visits under Netlify's privacy statement.