Skip to content

Instantly share code, notes, and snippets.

@flrngel
Created June 22, 2026 00:28
Show Gist options
  • Select an option

  • Save flrngel/dccc1dc8bd6393ec6f53c7370ec87ebe to your computer and use it in GitHub Desktop.

Select an option

Save flrngel/dccc1dc8bd6393ec6f53c7370ec87ebe to your computer and use it in GitHub Desktop.
PassBasket Privacy Policy

PassBasket Privacy Policy

Last updated: June 22, 2026

What PassBasket Does

PassBasket is a local-first household credential vault. The browser extension and iOS app help users save, search, fill, share, restore, and sync encrypted vault data.

Data Stored In The Vault

Users may choose to save login titles, website URLs, usernames, email addresses, passwords, one-time passcode details, secure notes, vault labels, family sharing metadata, and recovery information. Vault contents are encrypted on the user's device before sync.

How Browser Permissions Are Used

The extension reads the active tab URL and page login fields to match and fill credentials on sites the user visits. It uses storage for encrypted vault data and settings, alarms for local lock and sync retry tasks, favicon access to show recognizable site icons, and Chrome privacy controls to reduce duplicate browser password prompts.

Sync And Server Data

When sync is enabled, the server stores encrypted vault envelopes, sync identifiers, token hashes, billing state, and operational metadata needed to run the service. The server is designed not to receive plaintext vault JSON or the user's local unlock password.

Payments

Paid sync uses Stripe Checkout and billing tools. Stripe may process billing email, payment status, subscription identifiers, and payment details under Stripe's own policies. PassBasket does not store full payment card numbers.

Sharing And Sale

PassBasket does not sell user data. PassBasket does not use vault data for advertising, creditworthiness, lending, or unrelated purposes. Data is transferred only as needed to provide sync, billing, security, legal compliance, or a user-requested support path.

Remote Code

The Chrome extension package includes its JavaScript and WebAssembly resources. It does not load or execute remote JavaScript or WebAssembly.

Retention And Deletion

Local vault data remains on the user's devices until removed by the user or browser. Synced encrypted data and billing metadata are retained while the service is active and may be removed when a user deletes or stops using sync, subject to security, backup, accounting, and legal retention needs.

Contact

For privacy or support requests, contact the PassBasket developer through the support channel listed in the App Store or Chrome Web Store listing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment