Privacy

What Vault and the Vault browser extension collect, why, who else receives it, how long it is kept, and how to ask about it.

Effective 13 September 2026.

Who runs Vault

Vault, at vault.nbergesen.com, and the Vault extension for Microsoft Edge are run by Nicholas Bergesen. The service is hosted in South Korea.

For any question or request about your data, including access, correction, or deletion, email nicholasb.za@gmail.com.

How your secrets are protected

Vault encrypts every secret you store, including passwords, notes, fields, and vault and collection names, with AES-256-GCM. The keys form a hierarchy rooted in a key kept outside the database and outside the application image.

Vault is server-trusted, not zero-knowledge. The service decrypts your secrets when you, your browser extension, or an agent key you created is signed in and allowed to read them, so that it can show or fill them. The operator of the service is therefore technically able to access stored data, and does not do so except to run and secure the service or when you ask.

What Vault collects

Your account

  • Your email address.
  • Your password, stored only as a salted, one-way hash. Vault cannot read it back.
  • Your two-step verification secret, stored encrypted, and your recovery codes, stored only as hashes.
  • If you sign in with Google: your Google account identifier and the email address Google reports. Vault does not keep Google access or refresh tokens.
  • Your preferences, such as theme, session timeout, and password generator settings.

What you store

The vaults, collections, and entries you create, and earlier versions of entries you change or delete, all encrypted as described above.

Sign-in sessions and activity

For each signed-in session, Vault stores the IP address and browser user agent string the session was most recently used from.

For each action recorded in your activity log, such as signing in, revealing a secret, or an extension fill, Vault stores the time, the kind of action, which item it concerned, whether it succeeded, whether it came from the website, the extension, or an agent key, and your IP address and user agent. The activity log never contains the secrets themselves. You can review your own activity on the Activity page, and the operator can see activity records when running and securing the service.

Web server logs

The web server in front of Vault logs each request with your IP address, browser user agent, the time, and the address requested. For the browser extension, the address requested includes the web address of the site being filled. These logs are used only to run and secure the service.

The browser extension

  • A record of each browser you connect: its name, a public key used to prove requests come from it, its status, and when it was connected and last used. Vault also keeps a record of each request to connect a browser, with the same name and public key.
  • When a page you open has a login form, the extension sends that site's web address (for example https://example.com) to your Vault to look for a saved login. It does not send the page's path, content, or anything you type.
  • The username and password it fills are sent from Vault to the extension only at the moment of filling. The extension does not store them, and it never submits forms for you.
  • Which saved login you chose for a site, and the outcome of each fill, kept against a keyed hash of the site's address rather than the address itself. If a site has been paused, Vault keeps that site's address so it knows not to fill there.
  • The extension stores its settings and encrypted sign-in tokens in your browser. It includes no analytics and sends nothing to anyone other than your Vault.

Agent keys

For access keys you create for tools and agents: the key's name, permissions, scope, and when it was created and last used. Vault stores a short identifier shown on the Security page and a hash of the key, never the key itself.

What Vault does not do

  • It does not sell or rent your data, or share it for advertising.
  • It uses no analytics, advertising, tracking cookies, web fonts, or content delivery networks, and its emails contain no tracking images.
  • The extension does not record your browsing history, read the content of the pages you visit, or submit forms.
  • It does not use your data to assess creditworthiness or for lending.

Other services that receive data

  • Google, only if you choose to sign in with Google. Google handles that sign-in and tells Vault your name, profile picture, email address, and Google account identifier. Vault keeps only the identifier and the email address.
  • Cloudflare Turnstile, on the registration and account recovery pages, to tell people from automated abuse. Your browser loads Cloudflare's check, and Vault sends Cloudflare the check's result token and your IP address to verify it.
  • Mailtrap, which delivers Vault's emails: address verification, account recovery, and account deletion messages. It receives your email address and the message.
  • Have I Been Pwned, to warn you about breached passwords. It receives only the first five characters of a password's SHA-1 hash, never the password, when you register or recover your account.

Cookies

Vault uses only the cookies it needs to work: a sign-in cookie that expires within 24 hours and sooner when you are idle, short-lived cookies that carry you between the steps of signing in, and a cookie that protects forms against cross-site request forgery. There are no tracking or advertising cookies.

How long data is kept

  • Your account and what you store: until you delete them or your account. An entry you delete stays in Trash for 30 days before it is removed. Approving an agent's request to delete an entry, or deleting a whole vault, removes those entries immediately.
  • Web server logs: kept by the server's log storage and not yet deleted on a fixed schedule.
  • Sign-in session records, with their IP address and user agent: for as long as your account exists.
  • Earlier versions of an entry: until they are more than 90 days old or more than 25 versions back.
  • Activity log records, with their IP address and user agent: 365 days.
  • Extension sign-in: at most 90 days before the browser must be connected again. Records of individual fill attempts and short-lived access tokens are deleted within a day of expiring. The record of each browser you connected, its sign-in records, the saved login you chose for each site, and any site pauses are kept for as long as your account exists. A record of each request to connect a browser, with the browser's name, is not yet deleted on a fixed schedule and is not removed when your account is deleted.
  • When you delete your account, Vault waits 7 days so you can cancel, then deletes the account and what you stored. Activity log records are kept for the rest of their retention period, after your account and its email address have been deleted. Records of requests to connect a browser also remain, as described above.
  • Encrypted backups of the service are kept for up to about eight weeks, so deleted data can remain in a backup for that long.

Your choices

  • Review your activity on the Activity page.
  • Export your data as a CSV file or an encrypted backup from the Import and export page in settings.
  • Revoke a signed-in session, an agent key, or a connected browser from the Security page.
  • Turn the extension's autofill off from its toolbar button, or disconnect the browser from the extension's settings.
  • Delete your account from the Account page.
  • Ask for a copy, correction, or deletion of your data, or ask anything about this policy, at nicholasb.za@gmail.com.

Changes to this policy

When what Vault collects or shares changes, this page is updated and its effective date changes with it.