Privacy

Privacy Policy for Aegis

Aegis is built around user-owned key control and encrypted credential storage. This policy summarizes what data flows through extension and web experiences, how it is protected, and which disclosures are published for Chrome Web Store compliance.

User-owned keysEncrypted vault recordsLimited metadata collection
Core Sections

Data We Process

Aegis processes encrypted vault payloads, account/session identifiers, and operational metadata needed for security controls and service reliability.

  • Credential contents are encrypted before persistence and sync.
  • Session and policy metadata support lock state, sender trust, and anomaly controls.
  • Crash and error telemetry is scoped to service diagnostics and abuse prevention.

Chrome Web Store Data Categories

For Chrome Web Store privacy disclosure, Aegis may process the following categories when users save, sync, and fill credentials.

  • Authentication information: passwords, credentials, and related lock/factor data.
  • Personally identifiable information: account identifiers such as usernames or email values saved in credential entries.
  • Website content: login-form field values and related host context used for save-on-submit and guarded autofill.

What We Do Not Sell

Aegis does not sell personal information or plaintext credentials. Credential plaintext is intended to remain accessible only within user-controlled decrypt contexts.

  • No ad-tech resale of vault or account data.
  • No plaintext credential ingestion from third-party services.
  • No cross-site behavioral profiling based on autofill events.

Retention and Deletion

Retention is limited to operational needs such as account continuity, audit workflows, and abuse mitigation. Users can remove vault content and account state through product controls.

  • Encrypted vault items remain until user deletion or account closure.
  • Operational logs follow environment-specific retention windows.
  • Deletion requests can be submitted through support channels.

Chrome Web Store User Data Policy

The use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including Limited Use requirements.

  • User data is used only for password-manager functionality and account security operations.
  • User data is not used for unrelated profiling, advertising, or credit/lending decisions.
  • Data transfer to third parties is limited to approved use cases required to provide the service.

Security and Contact

Questions about data handling, breach response, or security disclosures can be sent through the Aegis support channel.

  • General privacy and account support: support@a3gis.me
  • Security disclosure and incident response: support@a3gis.me
  • Policy updates are published with release and legal notices.