Privacy Policy
Last updated: June 9, 2026
ConfPass ("we", "our", "us") is a zero-knowledge password manager. This policy explains what data the ConfPass desktop app and the ConfPass browser extension collect, how it is used, and your rights. We designed ConfPass so that we are technically unable to read your passwords.
In short: Your vault is encrypted on your device before it ever leaves it. We never see your master password or your plaintext passwords. We do not sell, rent, or share your data, and we do not use it for advertising, profiling, or any purpose unrelated to running ConfPass.
1. What we collect
- Account information: Your username and email address when you register.
- Encrypted vault data: Your passwords and vault entries, encrypted on your device with AES-256-GCM before transmission. We store only the ciphertext and cannot decrypt it.
- Usage metadata: Timestamps of vault sync operations, session tokens, and IP address information used for security (rate limiting, suspicious-login detection).
- Device identifiers: A hashed hardware ID used to bind sessions and detect unauthorized access. It is not linked to your real-world identity.
2. What we do NOT collect
- Your master password — it never leaves your device.
- Plaintext vault contents — everything is encrypted client-side.
- Your browsing history, the list of sites you visit, or the content of pages you view.
- Any data for advertising, marketing profiles, or sale to third parties.
3. How we use your data
- To provide, sync, and maintain the ConfPass service.
- To send email verification and security alerts (such as data-breach notifications).
- To detect and prevent unauthorized access to your account.
4. The browser extension
The ConfPass browser extension exists for a single purpose: to detect login and payment form fields on the page you are viewing and to fill them with credentials you have chosen from your ConfPass vault. Here is exactly how it handles data:
- Page access: The extension reads the structure of input fields on the current page (field names, types, and form layout) only to identify where a username, password, or card field is so it can offer to fill it. It does not read, collect, or transmit the content you type or the pages you browse.
- Where credentials come from: When you choose to autofill, the extension retrieves the relevant entry from the local ConfPass desktop app over an authenticated
localhostconnection, or from your encrypted account atpass.conftag.pro. Credentials are used only to fill the field you selected. - Local settings: Your per-site preferences (for example, sites or fields you asked ConfPass to ignore) are stored locally in your browser and are never sent to us.
- No external transmission: The extension communicates only with the local desktop app and
pass.conftag.pro. It does not send page content, form data, or browsing activity to any third party. - Domain matching: Autofill is offered only when the entry's website matches the page you are on, to protect you against look-alike phishing sites.
5. Limited use & no sale of data
ConfPass's use of information received from the browser extension adheres to the Chrome Web Store User Data Policy and the equivalent Mozilla Add-on policies, including their Limited Use requirements. Specifically:
- We do not sell or rent your personal or vault data to anyone.
- We do not transfer your data to third parties except as needed to operate the service (for example, hosting), or when legally required.
- We do not use your data for advertising, profiling, or creditworthiness/lending purposes.
- We do not allow humans to read your encrypted vault data; it is technically inaccessible to us.
6. Data storage and security
Encrypted vault data is stored on servers located in the European Union. We use AES-256-GCM encryption with keys derived by Argon2id, TLS for transport, hashed and rotating authentication tokens, and operating-system-level protection (DPAPI) for secrets stored on your device. Access to production systems is strictly limited.
7. Data retention
Your data is retained for as long as your account exists. You may delete your account at any time from the app settings, which permanently erases all associated data within 30 days.
8. Third-party services
ConfPass uses HaveIBeenPwned (HIBP) to check whether a password has appeared in a known breach. Password hashes are sent only as k-anonymity prefix queries — the first five characters of a SHA-1 hash — so your full password is never transmitted. No analytics, tracking, or advertising services are used.
9. Your rights
You have the right to access, correct, export, or delete your personal data at any time. To exercise these rights, contact us at emre.conf@gmail.com.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated in the app.
11. Contact
For any privacy questions or requests, email emre.conf@gmail.com.