Privacy Policy
Short version: E-Vault is zero-knowledge. Your passwords are encrypted on your device before they ever reach our servers. We cannot read your passwords — ever. We collect only the minimum data required to operate the service.
1. Who we are
E-Vault Password Manager is developed and operated by EMIAC Tech. If you have any questions about this policy, contact us at support@emiactech.com.
2. What data we collect
Account data
- Your email address (used for login and team invitations).
- Your name or display name (optional, used within your organization).
- Encrypted vault data — your credentials, folders, and sharing keys — stored as ciphertext. We cannot decrypt this data.
Extension data (Chrome / Edge)
- The extension reads form fields on web pages only when you actively autofill or save a credential. It does not scan, log, or transmit the contents of pages you visit.
- The extension stores your encrypted vault locally (via Chrome's
storage.local) to work offline and reduce server round-trips. This data is the same encrypted ciphertext stored on our servers. - No browsing history, page content, or keystrokes are collected or transmitted.
Usage data
- Basic server logs (IP address, request path, timestamp) retained for up to 30 days for security and debugging. We do not use these for advertising or analytics.
- We do not use third-party analytics, tracking pixels, or advertising cookies.
3. How your data is encrypted
- Your master password is processed locally using PBKDF2-SHA256 (310,000 iterations) to derive an encryption key. The master password itself is never transmitted.
- Every credential is encrypted with AES-256-GCM before leaving your device.
- Team sharing uses RSA-OAEP 2048-bit asymmetric encryption — each recipient gets a copy wrapped to their public key.
- Our servers store only ciphertext. We have no technical ability to read your passwords.
4. How we use your data
- To provide, maintain, and improve the E-Vault service.
- To send account-related emails (invitations, password reset). We do not send marketing emails without your consent.
- To ensure security and prevent abuse.
5. Data sharing
We do not sell, rent, or share your personal data with third parties for marketing purposes. We may share data only in the following limited circumstances:
- Service providers: We use a hosted PostgreSQL database to store encrypted vault data. The provider has no access to encryption keys.
- Legal requirement: If required by law, court order, or to protect the rights and safety of our users.
6. Data retention
- Your vault data is retained as long as your account is active.
- When you delete your account, all your encrypted data is permanently deleted within 30 days.
- Server logs are deleted after 30 days.
7. Your rights
You may at any time:
- Export or delete your vault data from within the app.
- Request deletion of your account and all associated data by emailing support@emiactech.com.
- Ask what personal data we hold about you.
8. Chrome extension — host permission
The E-Vault extension requests access to http://*/* and https://*/* (all websites). This permission is required so the extension can:
- Detect login forms and offer to save or autofill credentials on any site you visit.
- Inject the autofill UI into pages when you click "Fill" in the popup.
The extension does not read, record, or transmit the general content of pages you visit. It only interacts with username and password input fields when you explicitly trigger autofill or when it detects a form submission to offer saving.
9. Children's privacy
E-Vault is intended for organizational and professional use. We do not knowingly collect data from children under 13.
10. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of E-Vault after changes constitutes acceptance of the updated policy.
11. Contact
Questions or requests regarding this privacy policy:
support@emiactech.com
EMIAC Tech