Legacy Vault Pro Chrome Extension: Privacy Policy
Last updated: 7 August 2026
This policy explains exactly what user data the Legacy Vault Pro Chrome extension collects, how that data is handled, where it is stored, who it is shared with, and how you can control or delete it. It applies to the extension only. Our full website and web application policy is available at https://legacyvault.pro/privacy-policy.
Company number 17167163 (England and Wales). ICO registration number ZC128606.
Privacy contact: protect@legacyvault.pro
1. Single purpose of the extension
The extension has one purpose: to help a signed-in Legacy Vault Pro user build an inventory of the online accounts they hold, so those accounts are not lost or forgotten by their family and executors. When the extension detects that you appear to be signed in to a website, it adds that website to your own private Legacy Vault Pro inbox for you to review.
2. What user data we collect
- Website activity: the domain name (for example barclays.co.uk) and the page title of top-level pages you visit while the extension is set to Active.
- Website content, read only as login signals: the extension reads parts of the page you are viewing, such as whether a sign-out control or account menu is present, to help identify account websites. This reading happens on your device. Only the resulting score is transmitted and stored. The page content itself is never sent to us, stored, or shared.
- Username or account identifier, where visible: if the page plainly displays the username or email address you are signed in with, that value is captured so you can recognise the account later.
- Authentication information for our own service: the access token that links the extension to your Legacy Vault Pro account, and your Legacy Vault Pro email address, shown in the extension popup so you know which account you are saving to.
What we never collect
- Passwords, PINs, or credentials for any third-party website.
- Form field values, keystrokes, messages, or search queries. Page content is read on your device for login detection only and is never transmitted or retained.
- Third-party website cookies, financial or payment details, or health information.
- Personal communications of any kind.
3. How we handle the data
- Data is used solely to create and de-duplicate entries in your own Legacy Vault Pro inbox and digital account vault.
- Captures are filtered and de-duplicated before they reach your inbox. Entries matching your standing ignore rules or excluded technical domains are discarded.
- We do not use this data for advertising, profiling, credit or lending decisions, market research, or any purpose unrelated to the single purpose above.
- We do not sell or rent user data to anyone, under any circumstances.
- Data is never transferred to another party except as listed in section 5.
4. How and where the data is stored
-
In your browser: your session token, your Active/Inactive preference, and a
short list of recently seen domains (used only to avoid sending duplicates) are stored using
the Chrome
storageAPI. This is removed when you uninstall the extension. - On our servers: accepted captures are stored against your account in our Postgres database, hosted by Supabase on AWS infrastructure in London, United Kingdom.
- Protection: all transmission uses TLS 1.2 or higher. Stored data is encrypted at rest with AES-256, and row-level security ensures no other user can read your records.
- Retention: local duplicate-check data is kept for up to 180 days. Inbox and vault entries are kept while your account remains open, or until you delete them. On account deletion, all associated data is permanently removed within 30 days.
5. How the data is shared
Extension data is transmitted only to Legacy Vault Pro's own backend. We use the following processors, each bound by contract to process data only on our instructions:
- Supabase — database, authentication, and serverless functions hosting.
- Amazon Web Services (London region) — the underlying infrastructure Supabase runs on.
No extension data is shared with advertisers, data brokers, analytics providers, or any other third party. We disclose data otherwise only where required by law.
6. Limited Use disclosure
Our use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically, data collected by the extension is used only to provide and improve the single user-facing feature described in section 1, is not transferred to third parties except as necessary to provide that feature or to comply with applicable law, is never sold, and is never used for advertising, credit, or lending purposes. No humans read this data except with your explicit consent, to resolve a support issue you have raised, or where required by law.
7. Permissions and why we need them
- storage — save your Active/Inactive preference and duplicate-check list.
- tabs / activeTab — read the domain and title of the page you are on.
- alarms — retry a failed send a few minutes later.
- contextMenus — offer the option to exclude a site from capture.
- Host access to all sites — sign-in detection can only work on the site you are actually signing in to, and we cannot know in advance which banks, utilities, or subscription services a given user holds accounts with. Only the domain, page title, and login signals leave the page.
8. Your control and your rights
- Switch the extension to Inactive at any time to stop all capture.
- Ignore a single entry, an entire website, or every site tied to a given username.
- Delete any inbox or vault entry from your Legacy Vault Pro account.
- Uninstall the extension, which removes all locally stored data.
- Under UK GDPR and the Data Protection Act 2018 you may request access, correction, erasure, restriction, objection, or portability by emailing protect@legacyvault.pro. You may also complain to the UK Information Commissioner's Office.
9. Children
The extension is not directed at, and must not be used by, anyone under 18 years of age. We do not knowingly collect data from children.
10. Changes to this policy
We may update this policy. Material changes will be posted on this page with a revised date, and where appropriate we will notify account holders by email.