Otter Vault privacy policy

Last updated: September 14, 2026

Otter Vault is a browser extension that helps you save passwords and API keys to an encrypted vault on your own device. This policy explains what the extension handles and what it does not do.

The short version

What the extension handles

Credentials you choose to save. When you click Keep it safe, the extension saves the password or API key you approved, together with a label (the page title), the username field's value on login forms, the website's origin (for example https://example.com), and the time it was saved. All of this is encrypted with AES-256-GCM before it is written to your browser's local extension storage.

Your vault passphrase. Your passphrase is used only to derive encryption keys on your device. It is never stored or transmitted. We cannot recover it for you: if you forget it, the vault cannot be decrypted.

Page content, in the moment. To offer help, the extension looks at the web pages you visit: it notices password and API-key fields, and text that looks like a newly generated API key. This inspection happens locally in your browser. Page content is not recorded, stored, or sent anywhere unless you explicitly save a credential.

Unlocked session. While the vault is unlocked, a key needed to use it is kept in the browser's in-memory session storage, which is cleared when the browser closes. The vault locks automatically after the auto-lock time you choose (5, 15, or 30 minutes).

What the extension does not do

Your control

Chrome Web Store user data policy

The use of information received by Otter Vault adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Changes and contact

If this policy changes, the updated version will be published at this address with a new date. Questions: krishna091718@gmail.com.