CogVault

Privacy Policy

This policy explains what CogVault does — and does not — collect when you use our desktop app, mobile app, and browser extension.

Last updated: July 21, 2026

Zero-knowledge promise: we do not store, access, or transmit your master password or unencrypted vault contents. Encryption happens on your device.

Information We Collect

CogVault is local-first. Vault data stays on your devices unless you opt into cloud sync.

How We Use the Information

Security

Encryption and decryption run locally. We use AES-256-GCM with a key derived from your master password via PBKDF2. Because of this model, there is no “forgot password” recovery: if you lose your master password, we cannot restore your vault.

Third-Party Services

Optional sync uses Firebase (Auth and Firestore). Only ciphertext is stored there. The provider cannot read your passwords. The browser extension talks to those same endpoints only when you unlock and sync.

Cookies

CogVault apps and the extension do not use advertising cookies. Any session storage is limited to keeping you signed in to optional sync or remembering local preferences on your device.

Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page, with the “Last updated” date revised. Significant changes may also appear in app release notes.