Privacy & Data Protection

Privacy Policy

This Privacy Policy explains how the Uzavik Vault browser extension for Chrome handles information, and how the optional Google Drive backup feature of the Uzavik Vault desktop application for Windows handles information (section 18). Other aspects of the desktop application are covered by separate documentation and its own privacy terms.

Effective date: 17 August 2026 · Last updated: 17 August 2026
Policy scope: This Privacy Policy covers the Uzavik Vault browser extension and the optional Google Drive backup feature of the Uzavik Vault desktop application (see section 18). The USB device, website, support services and other products may have separate privacy documentation.

01 Summary

The extension is designed to operate without internet access, user accounts, servers, analytics, advertising, or third-party tracking. It does not collect or transmit personal data to Uzavik Vault or any third party. Information needed for the extension's operation is processed locally on your computer and communicated only with the Uzavik Vault desktop application through Chrome Native Messaging.

Because the extension is intentionally local-only, many GDPR and DPDP Act obligations concerning remote collection, disclosure, international transfers, and retention do not arise for the extension. This policy nevertheless explains the local processing, your rights, and how to contact us.

02 Who is responsible for the processing

For the purposes of applicable data-protection law, Jivatu Technologies is responsible for the browser-extension privacy practices described in this policy.

Company: Jivatu Technologies

Privacy contact: admin@jivatu.tech

If you are in the European Economic Area or United Kingdom and data-protection law applies to your use of the extension, contact us using the address above for privacy requests. If a representative or Data Protection Officer is legally required for a particular processing activity, their details will be provided here.

03 Information the extension collects

The extension does not collect personal data for transmission to us, does not create an online account, and does not send information to our servers. Specifically, the extension does not collect:

usernames, passwords, notes or other vault contents for remote storage;

websites you visit, browsing history or search history;

your name, email address, IP address or device identifiers;

analytics, telemetry, crash reports or usage statistics;

advertising identifiers or tracking information.

The statements above describe the extension's intended and implemented operation. If a future version introduces any collection, the applicable notice and this policy will be updated before or when required by law.

04 Information processed locally on your device

To perform its functions, the extension necessarily handles limited information locally. This processing is initiated by your actions and is not sent over the internet.

The address of the active tab: read only when you click the extension's toolbar icon, to identify the site for which the desktop application should look up saved credentials.

A single credential: when you explicitly choose to fill a login, the desktop application returns the selected username and password to the extension, which passes them to the sign-in fields on the current page and then discards the credential.

Credentials you choose to save: when you select “Save this login” or “Enter manually”, the username, password and any note you provide are sent to the Uzavik Vault desktop application for storage in your vault.

Your vault passphrase: entered by you in the extension popup, passed to the desktop application to unlock the vault, and cleared immediately afterwards.

This local communication uses Chrome Native Messaging with the Uzavik Vault application on the same computer. The extension does not use the internet for this communication.

05 Purposes and legal bases

5.1 India — DPDP Act, 2023

The Digital Personal Data Protection Act, 2023 (DPDP Act) applies to digital personal data processing within its scope. Where the Act applies to processing by Jivatu Technologies, processing will be carried out only for a lawful purpose and on a permitted ground under the Act. The extension's described local-only operation means that the company does not receive the information listed in Section 4.

Where consent is required, the notice accompanying the consent request will identify the personal data and purpose and explain how applicable rights and complaints can be exercised. Consent, where used, will be capable of being withdrawn through a process that is as easy as giving it.

5.2 European Union/EEA — GDPR

Where the GDPR applies, we will process personal data only on an applicable legal basis under Article 6 GDPR. For the extension's local operations, the processing is initiated by the user to provide the requested password-management functionality. Where consent is relied upon, it will be freely given, specific, informed and unambiguous and may be withdrawn at any time.

Where another legal basis is relied upon, the relevant basis and purpose will be communicated as required by Article 13 or 14 GDPR.

06 Data storage and retention

The extension itself is designed not to store credentials or other personal data in extension storage, local storage, session storage, cookies or cache. Credentials are discarded by the extension after the requested operation. The vault is stored by the Uzavik Vault desktop application on your computer and is encrypted and bound to your Uzavik VaultKey USB device.

Because the extension does not maintain a remote copy, there is no extension-side retention period for credentials. Data retained by the desktop application is governed by the desktop application's documentation and privacy terms.

If the extension ever begins retaining personal data, this section will be updated to specify the categories retained, retention periods or criteria used to determine them, and deletion procedures.

07 Sharing, processors and third parties

The extension does not share personal data with third parties and does not use third-party analytics, advertising, tracking, error-reporting services, or externally hosted code.

If Jivatu Technologies later engages a processor to process personal data on its behalf, it will select and contract with processors as required by applicable law, including appropriate confidentiality, security and data-protection obligations.

08 International transfers

The extension does not transmit the information described in this policy to our servers or third parties, and therefore does not conduct an international transfer of that information as part of its normal operation.

If any future processing involves transferring personal data outside the EEA/UK or outside India where applicable transfer restrictions apply, appropriate safeguards and disclosures will be provided as required by applicable law.

09 Chrome permissions

activeTab — provides access to the tab you are viewing when you invoke the extension, so it can identify the site and perform the requested action.

scripting — permits a self-contained function to be injected into the current page on your action to locate or fill sign-in fields. The extension does not use persistent content scripts.

nativeMessaging — permits communication with the Uzavik Vault desktop application, which is the local location of your vault data.

The extension deliberately does not request permission to read or change data on all websites. Permission use is limited to the functions described above.

10 Security

The extension is designed to minimize exposure of credentials. A password is released only in response to your explicit action, for the requested login, and for the immediate fill operation. The extension does not submit a form on your behalf. It can add and update credentials but cannot delete them; deletion and vault management occur in the desktop application.

The local extension-to-desktop-app communication is authenticated and encrypted as implemented by the product. No security measure can guarantee absolute security, but appropriate technical and organizational measures will be maintained as required by applicable law.

11 Your privacy rights

11.1 GDPR rights, where applicable

Subject to applicable legal conditions and exemptions, you may have rights including:

access to your personal data and information about its processing;

rectification of inaccurate or incomplete personal data;

erasure of personal data in specified circumstances;

restriction of processing in specified circumstances;

data portability where the GDPR conditions are met;

objection to certain processing, including direct marketing;

withdrawal of consent where processing is based on consent; and

rights concerning solely automated decision-making and profiling where applicable.

You also have the right to lodge a complaint with a competent EU/EEA supervisory authority where the GDPR applies.

11.2 India — DPDP rights, where applicable

Where the DPDP Act applies, Data Principals have rights provided by the Act, including rights relating to access to information about personal data and processing, correction and erasure, grievance redressal, and nomination, subject to the Act and applicable rules.

Requests and complaints may be submitted to admin@jivatu.tech. We may need to verify the requester's identity before acting on a request, using proportionate measures.

12 Children's privacy

The extension is not directed specifically at children. It does not knowingly collect personal data from children for transmission to us. Where child-specific requirements apply under the DPDP Act, GDPR or other applicable law, we will comply with the applicable requirements, including any required parental or guardian consent and restrictions on tracking or targeted advertising.

13 Automated decision-making

The extension does not use personal data for profiling, creditworthiness assessment, lending decisions, or automated decisions that produce legal or similarly significant effects on individuals.

14 Data breach and incident response

If a personal-data breach occurs in processing for which Jivatu Technologies is responsible, we will assess and handle the incident and make any notifications to individuals, regulators, the Data Protection Board of India, or other authorities that are required by applicable law and within applicable time limits.

15 Changes to this policy

If this policy changes, the revised policy will be posted at the applicable address with a revised “Last updated” date. Material changes will also be communicated through appropriate product or Chrome Web Store notices where required. Where applicable law requires prior notice or consent for a material change in processing, we will provide it.

16 Contact and complaints

Privacy questions, rights requests and complaints can be sent to:

Jivatu Technologies Private Limited
Privacy contact: admin@jivatu.tech

Grievance Officer (Digital Personal Data Protection Act, 2023)
Suryakant Verma
grievance@jivatu.tech

For GDPR-covered processing, you may also complain to your competent supervisory authority. For DPDP-covered processing, you may use the grievance mechanism above and, where permitted by the Act and applicable rules, the Data Protection Board of India.

17 Important product-scope note

This policy covers the Uzavik Vault browser extension and the optional Google Drive backup feature of the Uzavik Vault desktop application. Other aspects of the desktop application, the USB device, the website, support services and any other Jivatu Technologies products may involve different processing and are covered by separate, consistent privacy documentation.

18 Google Drive backup (desktop application)

The Uzavik Vault desktop application offers an optional backup feature that stores encrypted copies of your vault in your own Google Drive. It is switched off by default. Nothing is sent to Google unless you connect a Google account and then explicitly start a backup. If you never use the feature, the desktop application makes no network connection for this purpose.

18.1 What is uploaded

Only a sealed backup file. Your vault is encrypted on your computer, using a key derived from your recovery key, before it is transmitted. Google receives ciphertext. Neither Google nor Jivatu Technologies can read your credentials, notes or other vault contents, and Jivatu Technologies never receives the file at all — the transfer is directly between your computer and Google.

Your master password, your recovery key and your Uzavik VaultKey USB device are never uploaded. Without them the backup file cannot be decrypted by anyone, including us.

18.2 Where it is stored

Backups are placed in a folder named “Uzavik Vault” in the Google Drive of the account you connect. The files are yours, held under your own Google account and subject to Google’s terms and privacy policy. You may inspect, download or delete them yourself at any time.

18.3 What access the application requests

The application requests a single Google permission, drive.file. This grants access only to files the application itself creates. It cannot see, read, list or modify any other file in your Google Drive. Broader Drive permissions are deliberately not requested.

Sign-in happens in your own web browser, using Google’s standard authorisation flow with PKCE. The application never sees your Google password.

18.4 The connection token

After you authorise the connection, Google issues a token that lets the application upload later backups without asking you to sign in again. This token is encrypted with the Windows Data Protection API under your Windows user account and stored in a single local file on your computer. It is never transmitted to Jivatu Technologies and cannot be read by other user accounts on the same machine.

18.5 Retention

Each backup you create is uploaded as a new file. The application keeps the five most recent backups and also always keeps the oldest one, so that a long-standing recovery point is never lost; older intermediate files are deleted from your Drive automatically. You remain free to delete any or all of them yourself.

18.6 Disconnecting and withdrawing consent

Choosing Disconnect in the application revokes the authorisation with Google first, then deletes the local token. If Google cannot be reached at that moment the application tells you so, because the grant would still be listed on your account; you can remove it yourself at myaccount.google.com/permissions.

Disconnecting does not delete backups already in your Drive. Delete those in Google Drive if you want them gone.

18.7 Legal bases and transfers

Where the DPDP Act applies, the processing rests on your consent, given by connecting an account and starting a backup, and withdrawable as described above. Where GDPR applies, the legal basis is consent (Art. 6(1)(a)). Because the destination is your own Google Drive, storage location is determined by Google under your Google account; the content is end-to-end encrypted before it leaves your computer, so the transfer does not expose readable personal data to Google or to any onward recipient.

19 Google API Services Limited Use

Uzavik Vault’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, data obtained through Google Drive access is used solely to store and retrieve backups of your vault that you have initiated. It is not used for advertising, not sold or transferred to third parties, not used to build profiles, and not read by humans except where you have given explicit permission for a specific support request, where required for security purposes such as investigating abuse, or where required by law.