What we keep,
where, and why.
One page. No legalese. If anything here is unclear, email us at founders@vaultbix.com and we'll fix the wording.
What we collect
For the free Chrome extension: nothing. No account, no telemetry, no analytics. The extension runs entirely in your browser.
For the marketing site (vaultbix.com): a privacy-first analytics tool (Plausible) that records anonymous page views. No cookies, no fingerprinting, no IP logging.
If you email founders@vaultbix.com: we keep your email and the contents of your message. Standard email.
Where data lives
All detection happens locally in your browser. Your prompts never reach our servers because we don’t have detection servers.
The optional team tier (in design) syncs incident metadata to a backend. We only sync SHA-256 hashes of detected patterns, never the raw secret values. You can audit this in the open-source repo.
Why
A tool that protects secrets has to be auditable. If we sent your prompts anywhere, you should not trust us. So we don’t.
Terms
VaultBix is provided as-is, under the MIT license for the open-source extension. We make a best effort to detect leaks but make no guarantees. You are still responsible for your own secret hygiene.
Don’t use VaultBix to do anything illegal. That’s about it.
last updated · 2026-05-08