Privacy Policy
VaultCove is an offline-first password manager published by AJ Coder Digital Store. This policy explains what data VaultCove handles, what remains local, what limited licensing data is transmitted, and which service providers are involved.
1. VaultCove's purpose
VaultCove's single purpose is to securely store and manage user-selected authentication credentials and related private vault information, and to provide user-directed secure login assistance on websites.
2. Data handled locally in the encrypted vault
Depending on what you choose to save, VaultCove may locally process:
- names, usernames, email addresses, postal addresses, identity information and other personally identifiable information;
- passwords, credentials, TOTP/authenticator secrets and authentication-related information;
- payment-card and bank-account information;
- Secure Notes, folders, tags, favorites and other user-created vault records;
- website URLs and the limited website/form content needed to identify supported login fields and perform a user-requested Secure Login;
- local security-health information derived from saved passwords, such as weak or reused-password status.
These vault contents are stored in Chrome extension-local storage in encrypted form. Decrypted vault data is processed locally while the vault is unlocked. VaultCove does not operate a developer-hosted cloud password vault and does not upload the contents of your encrypted vault to AJ Coder Digital Store, Payhip, or the VaultCove licensing service.
3. Website access and Secure Login
VaultCove uses temporary active-tab access and, when you explicitly grant it, optional website permissions to detect supported login forms and perform password-manager functions. Website URLs and form information used for these functions are processed for the current user-facing operation. VaultCove does not create or sell a browsing-history profile and does not send your browsing history to the licensing service.
4. Licensing and device-management data
When you activate or manage a VaultCove license, the extension communicates over HTTPS with the VaultCove licensing service hosted with Google Apps Script. The licensing workflow may process:
- the email address associated with the license purchase;
- the license key transiently for verification and a keyed/hash representation for server-side lookup;
- a random VaultCove installation identifier and device recovery/refresh-token representations;
- device label, platform, application version, license type/status and device status;
- activation, first-seen, last-seen and related licensing timestamps;
- one-time verification challenges and verification-code hashes.
The licensing service uses Google Apps Script, Google Sheets and Google email-sending infrastructure to verify activation, maintain the device-slot ledger, issue signed license leases and send one-time verification codes. The raw contents of the password vault are not included in licensing requests or verification emails.
5. Payhip
For purchased licenses, the licensing service contacts Payhip to verify that a submitted license key is valid for the VaultCove product and to confirm the buyer email/status returned by Payhip. Payhip already processes purchase information under Payhip's own terms and privacy policy. VaultCove does not send your password-vault contents to Payhip.
6. Backups and downloads
When you create an encrypted VaultCove backup, the backup is generated for you and saved as a local file using Chrome's download functionality. VaultCove does not automatically upload that backup to AJ Coder Digital Store. You are responsible for securely retaining the backup and its required secret.
7. Notifications
VaultCove may display local Chrome notifications for user-facing events such as trial status, password-change review or new-login review. Notifications are designed not to reveal saved passwords, TOTP secrets or other vault secrets.
8. Support and external links
The Support area can open your email application or user-initiated links to AJ Coder Digital Store, Payhip or PayPal. VaultCove does not automatically attach or transmit your vault, passwords, backup secrets or TOTP secrets to support messages. Information you intentionally send through email or third-party websites is governed by your choices and the relevant provider's privacy terms.
9. Data VaultCove does not use for advertising or credit decisions
- VaultCove does not sell user data.
- VaultCove does not use vault data for advertising, retargeting or interest-based advertising.
- VaultCove does not use or transfer user data for purposes unrelated to its password-management and necessary licensing/security functions.
- VaultCove does not use user data to determine creditworthiness or for lending purposes.
- VaultCove does not provide analytics or telemetry based on the contents of your vault.
10. Security
VaultCove is designed to protect vault data at rest using authenticated encryption. Licensing communication uses HTTPS, and signed license leases are verified by the extension. No security measure can guarantee absolute security, so users should also protect their Chrome profile, operating-system account, master password and encrypted backup secrets.
11. Retention and deletion
Local vault data remains in the Chrome extension's local storage until you delete it or Chrome removes the extension's local data. Removing the extension can permanently remove that local vault, so create and safely store an encrypted backup first if you want to preserve it.
Licensing records are retained as needed to provide license activation, device management, fraud/abuse prevention and related security functions. One-time verification codes expire after a short period; the service stores verification hashes rather than plaintext codes. You may contact the publisher to request correction or deletion of licensing information, subject to security, legal and operational requirements. Deleting licensing records may prevent continued activation or device management for that license.
12. Service providers
VaultCove's limited online licensing functions rely on Google services (including Apps Script, Sheets and email delivery) and Payhip for purchase/license verification. User-initiated support/payment links may open Payhip or PayPal. These providers process information according to their respective privacy policies and terms.
13. Changes to this policy
If VaultCove's data-handling practices materially change, this policy and applicable in-product/store disclosures will be updated before or when the changed handling is introduced, as required.
14. Contact
Publisher: AJ Coder Digital Store
Email: leveriza.aj08@gmail.com
Store: payhip.com/AJCoderDigitalStore
For your security, never email your master password, saved passwords, private keys, TOTP secrets, backup secrets, or complete vault files unless you fully understand and explicitly choose to disclose specific information for support.