Back to Product

NeuroAI Vault — Privacy Policy

Effective Date: July 2026
Last Updated: July 2026
(Pre-Release Version)

NeuroAI Digital (“we,” “us,” or “our”) develops NeuroAI Vault, a client-side encrypted password manager. NeuroAI Vault is currently available as a web application and a browser extension for Chrome, Brave, and Edge.

Because we believe that privacy is a fundamental human right, our software is designed so that we never host, store, see, or transmit your master password, your encryption keys, or your decrypted credentials. Your vault data is encrypted on your device before it ever leaves it. You retain full ownership and control over your digital identity.

This Privacy Policy explains what information NeuroAI Vault handles and how it operates in its current pre-release phase. We are committed to a strict Zero-Data Collection model.


1. Zero-Knowledge Architecture & Encryption

All data stored within your vault is subject to strict, browser-native client-side encryption before it is stored locally or transmitted to your personal cloud storage.

  • Client-Side Encryption: Plaintext credentials (passwords, credit cards, secure notes, identities) are encrypted on your local device using standard AES-GCM-256 cryptography.
  • Key Derivation: The encryption key is derived locally using PBKDF2-HMAC-SHA256 with a minimum KDF iteration floor of 600,000 iterations and a unique, cryptographically random 32-byte salt.
  • Volatile Memory Storage: Plaintext credentials and derived keys exist solely in your device’s volatile memory (RAM) while the vault is unlocked. They are never written to disk in decrypted form and are wiped completely from memory upon auto-locking or closing the application.
  • No Master Password Storage: We never store, transmit, or receive your Master Password. We have no way to reset your password or access your data.

2. Bring-Your-Own-Storage (BYOS) & Cloud Sync

NeuroAI Vault does not host databases or central servers.

  • User-Owned Storage: Your encrypted vault file is stored directly on your personal cloud storage account (Google Drive or Microsoft OneDrive) in a hidden, app-specific application folder (appDataFolder for Google Drive, special/approot for Microsoft OneDrive).
  • Direct REST API Calls: Your client device makes direct, authenticated REST API calls to Google or Microsoft. We do not proxy, intercept, or monitor these requests.
  • Metadata Protection: Your chosen cloud provider acts as a simple storage repository. They only see an opaque, encrypted binary file and cannot read the contents of your vault.

3. Web Application Privacy Declarations

When using the NeuroAI Vault Web App (vault.neuroai.digital):

  • No Server Communication: The application does not communicate with any servers owned by NeuroAI Digital. All network requests go directly from your browser to Google or Microsoft APIs.
  • IndexedDB Caching: The encrypted vault is cached locally in your browser’s IndexedDB for offline access. No plaintext data is ever saved to local storage.
  • Session Tokens: OAuth access and refresh tokens used to communicate with Google Drive or OneDrive are stored solely in volatile sessionStorage (cleared on tab close) to prevent persistent exposure.

4. Browser Extension Privacy Declarations & Permissions

The browser extension (Chrome, Edge, Brave) requests specific web permissions strictly to provide essential autofill and credential-management features:

  • activeTab and scripting: Used to inject secure autofill overlays directly into login, credit card, and identity checkout forms on the active tab. The extension does not read or inspect your web pages unless you click the autofill popup or interact with a login form.
  • host_permissions (https://*/*): Required to support automated save-password and update-password prompts when submitting forms on secure HTTPS sites. The content script automatically blocks execution on unencrypted HTTP pages for your safety.
  • storage: Used to securely store the local, encrypted vault cache and your extension configurations (e.g., auto-lock timeouts).
  • identity: Used to handle the secure OAuth login flow to connect your Google or Microsoft account.
  • alarms: Used to implement the background idle timer which triggers auto-lock, purging KEK and DEK encryption keys from service worker memory after a period of inactivity.

5. Security & Privacy-Preserving Integrations

  • Have I Been Pwned (Breach Check): To monitor if your passwords have been exposed in third-party breaches, the application integrates with the Have I Been Pwned API using a k-anonymity model. The client hashes your password locally using SHA-1 and sends only the first 5 characters of the hash to the API. Your actual password and the remaining 35 characters of the hash are never sent, ensuring your passwords are never exposed to external services.

6. Personal Information & Telemetry

6.1 Vault Data — Not Collected by Us

All data stored within your vault (passwords, credit card details, secure notes, personal identities) is encrypted on your device before being stored in your personal cloud storage (Google Drive or Microsoft OneDrive). NeuroAI Digital does not receive, store, or have access to any of this data.

6.2 Zero Personal Data Collection

During this pre-release phase, we do not require users to register an account with us, nor do we collect subscriber emails or process payments. We collect zero personal data from users of the Service.

6.3 Application Telemetry — Not Collected

  • No Analytics: There are no trackers, third-party advertising SDKs, cookies, or telemetry libraries in the NeuroAI Vault application or browser extension.
  • No Diagnostics: We do not collect logs, crash reports, or diagnostic data from the application.
  • No Behavioral Tracking: We do not monitor how you use the application.

7. Your Rights (GDPR)

If you are located in the European Union or European Economic Area, you have rights under the GDPR regarding personal data. However, because NeuroAI Digital operates under a zero-data collection model and does not collect, process, or store any personal data regarding users of the Service, there is currently no personal data for us to provide access to, rectify, or erase.

If our data practices change in the future (e.g., when introducing paid subscriptions), we will update this Privacy Policy and provide mechanisms for you to exercise your full GDPR rights. You always retain the right to lodge a complaint with the competent supervisory authority in your federal state or country.


8. Policy Changes & Contact

We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. Any updates will be reflected on this page with an updated effective date. Continued use of NeuroAI Vault after an update constitutes acceptance of the revised policy.

For privacy inquiries, data subject requests, or questions about this policy, please contact us at:

NeuroAI Digital
Website: https://neuroai.digital/contact