Privacy Policy
ShieldVault Browser Extension. Last updated: June 23, 2026.
In plain English
ShieldVault helps prevent accidental sharing of sensitive information on supported websites. It checks text you type or paste locally on your device and warns you before you submit content that appears risky, such as API keys, credentials, private data, or certain behavioral/tone risks.
The text being checked does not leave your device as part of ShieldVault's detection process.
ShieldVault stores settings and limited event metadata locally so the extension can keep working across browser sessions. If you use Pro features, ShieldVault may contact ShieldVault-operated services to activate or validate a license key, or to start checkout if you choose to upgrade.
What ShieldVault analyzes locally
ShieldVault is built on a "detection without possession" principle. The extension analyzes text you type or paste in supported fields in real time to detect potentially sensitive content and warn you before that content is submitted.
Examples of the kinds of content ShieldVault may check for include:
- API keys and secrets
- Auth tokens
- Passwords
- Seed and recovery phrases
- Credit card numbers
- Phone numbers
- Bank account information
- Personal information patterns
- Client or customer data markers
- Large pastes
- Certain behavioral or tone-based warning patterns
This analysis runs locally in your browser using pattern matching and extension logic. ShieldVault does not transmit the text being analyzed as part of this detection process.
After analysis, ShieldVault does not store the original typed or pasted text as part of its local activity history.
Supported websites
ShieldVault currently runs on supported pages including:
- AI chat platforms: ChatGPT, Claude, Gemini, Perplexity, Microsoft Copilot, Google AI Studio, OpenRouter, Poe, and Grok
- Code and development: GitHub, GitHub Gist, GitLab, Bitbucket, Replit, CodeSandbox, and StackBlitz
- Work tools: Slack, Discord, Linear, Jira / Confluence (Atlassian), Notion, and Google Docs
- Email: Gmail and Outlook.com
- Social and community: LinkedIn, Reddit, Twitter / X
Support may change over time as the extension is updated.
What ShieldVault stores locally on your device
ShieldVault uses browser extension storage (chrome.storage.local) on your device to store data needed for the extension to function. Depending on how you use the extension, this may include:
- Your ShieldVault settings and enabled/disabled preferences
- Whether the extension is turned on or off
- Recent blocked-event metadata (website domain, timestamp, detector labels/categories, event class)
- Badge/count information used by the extension UI
- Limited local state related to Pro preview or Pro activation
- Your Pro license key and Pro status, if you activate Pro
- Limited local allow-list or bypass state used to support extension behavior on specific sites
ShieldVault's local event history is designed to store metadata only, not the actual text you typed or pasted.
What ShieldVault sends off your device
ShieldVault does not send the text you type or paste for secret-detection or behavioral-detection analysis. ShieldVault also does not send your local activity history, detected secret contents, or typed message contents as part of its normal protection workflow.
ShieldVault may send limited data to ShieldVault-operated services in the following cases:
1. Pro license activation or validation
If you enter a Pro license key, ShieldVault may send that key to a ShieldVault-operated endpoint so the extension can activate or validate your Pro status. This is used only to determine whether the license is valid. ShieldVault does not send your typed chat text or local activity-history contents with that request.
2. Checkout initiation
If you choose to upgrade to Pro, ShieldVault may contact ShieldVault-operated services to load payment-related configuration and create a checkout session, then open a checkout page in a new tab or window. These requests are for payment flow setup only. The extension itself does not send your typed or pasted protected text as part of checkout.
Payment processing
If you choose to purchase Pro, checkout is handled through a ShieldVault-hosted payment flow that uses Stripe for payment processing.
The extension does not collect or store your full payment card details inside the extension. Payment information is handled by Stripe or Stripe-hosted checkout flows under Stripe's own terms and privacy practices.
After a successful purchase, you may receive a license key that can be entered into ShieldVault to activate Pro.
What ShieldVault does not do
- Send your typed or pasted text for its local detection workflow
- Store the full contents of detected secrets in its local activity history
- Sell your personal information
- Share your data with advertising networks or data brokers
- Use your typed secret-detection content for ad targeting
- Track you across websites for advertising purposes
- Require a ShieldVault account to use the extension's core local protection features
Permissions explained
storage
Used to save settings, local extension state, and limited metadata on your device so the extension can work across sessions.
tabs
Used to open extension pages (such as the onboarding page on first install) in a new tab, and to determine the current tab context for extension UI features.
activeTab
Used to access the currently active tab when you interact with the extension, such as opening the popup.
Host access (content scripts)
ShieldVault injects local detection logic into supported websites so it can inspect text in relevant input areas and provide warnings before risky content is submitted. The extension does not transmit your typed or pasted text as part of this process.
Host access (shieldvault.site)
ShieldVault requests access to shieldvault.site for extension-connected features such as Pro license activation, validation, or checkout setup. These requests do not include your typed or pasted protected text.
Data retention
Most extension data described in this policy is stored locally in your browser environment until it is overwritten, cleared by browser or extension behavior, or removed when the extension is uninstalled.
If you activate Pro, license-related information may remain stored locally until it is cleared, replaced, or removed.
Children's privacy
ShieldVault is not directed to children under 13, and ShieldVault is not intended to knowingly collect personal information from children under 13 through the extension.
Changes to this policy
This policy may be updated from time to time. If it changes, the updated version will be posted at this URL with a revised "Last updated" date.
Contact
Questions or deletion requests: support@shieldvault.site