Privacy Policy
Effective August 22, 2026 · Updated for Google Drive backup and payment references
PocketProfile keeps reusable information private. We do not sell data, run advertising, or use analytics or tracking SDKs.
Information PocketProfile handles
You choose what to save. This may include profiles, names, addresses, contact and identity details, dates, passport information, company information, custom fields, group membership, encrypted document files, and recovery settings. After you explicitly enable save suggestions for the current page, the extension temporarily checks safe visible controls and offers individual values only when a strong identifier matches the selected profile.
If cloud sync is enabled, the service receives the account email, authentication data, and already-encrypted vault. Account passwords are one-way hashed. Email addresses are encrypted at rest and indexed with a keyed hash. The vault master password and recovery key are never transmitted or stored by PocketProfile.
Encryption and local storage
Profiles, group names, notes, settings, values, and document metadata are stored as AES-256-GCM vault ciphertext. Original document bytes are stored as separately encrypted records protected by the same vault key. The key is derived from the master password using PBKDF2-HMAC-SHA-256 with a unique salt and 600,000 iterations. A temporary key may remain in Chrome session storage while unlocked. Original documents are limited to 5 MB each and are encrypted locally before optional cloud sync.
Website access
PocketProfile accesses the active page only after the user presses Fill page or explicitly enables save suggestions for that page. Matching and filling happen locally. Suggested values are added only after the user presses the adjacent add button and are not uploaded separately. Password, payment-card, bank, one-time-code, file-upload, hidden, disabled and read-only fields are excluded. An optional device-protected payment reference may store only the issuer, nickname, last four digits, expiry date, and billing address. Full card numbers, security codes, PINs, and magnetic-stripe data are rejected. Payment references are never filled into websites or included in shares.
Cloud sync and providers
Cloud sync is optional. The server stores encrypted vault ciphertext and cannot decrypt its contents. A random PocketProfile ID and public encryption key are stored with a cloud account so other signed-in members can address an encrypted share to that account. The corresponding private sharing key remains inside the encrypted vault. Infrastructure is hosted by DigitalOcean. Google Drive backup is separately optional. After the user presses Connect Google Drive, Chrome requests Google's drive.appdata scope so PocketProfile can create, restore, and update only its encrypted backup in the hidden application-data folder. PocketProfile cannot access ordinary Drive files. Google may process the Google account identity, backup size, timestamps, and ordinary network metadata to provide this service. Disconnecting stops future backups but keeps the existing encrypted Drive copy until the user removes it through Google. Ordinary network metadata may also be processed to deliver and protect the PocketProfile service. We do not use it for advertising.
Secure links and member sharing
One-time detail requests and read-only group shares are encrypted in the browser using a random key held in the URL fragment and the owner’s encrypted vault. The fragment key is not included in HTTP requests. Request links expire after 10 minutes and one submission. Group links expire at the selected time and can be paused, resumed, or revoked. The server stores encrypted packets plus operational metadata including expiration, pause or revocation status, access count and last-access time. Anyone with a complete active group link can decrypt the selected shared profiles, so links must be sent only to intended recipients.
When a user shares directly by email or PocketProfile ID, the sender previews and selects exact fields before the browser encrypts them to the recipient’s public key. The server routes and temporarily stores the encrypted envelope, sender and recipient account IDs, timestamps, read status and expiration. It cannot decrypt the shared profile contents. Direct shares expire after 30 days, can be removed by the recipient, and can be revoked by the sender from the immediate delivery confirmation.
Recovery keys and quick unlock
A recovery key is generated locally from the vault encryption key. PocketProfile never receives it and cannot recreate it. Anyone holding both the recovery key and encrypted vault can decrypt the vault. Device biometric matching is performed by the operating system through WebAuthn; PocketProfile never receives a fingerprint image or template. Users may optionally enable a 4–6 digit PocketProfile PIN. The PIN derives a local key with PBKDF2 to wrap the vault key with AES-256-GCM, is never synchronized or sent to PocketProfile, and is temporarily paused after repeated incorrect attempts. Because a short PIN is weaker than a master password, it should be used only on a private, protected device.
Clipboard, retention and deletion
Copied values are placed on the operating-system clipboard and may be visible to other clipboard software. Deleting the local vault removes PocketProfile data from Chrome on that device. A connected user can delete the complete cloud account directly from Security & backup. This removes the account, encrypted cloud vault, encrypted documents, active sessions, requests, and share records from the active database. Browser backups, exported backups, clipboard managers and information already submitted to other websites remain outside PocketProfile’s control.
Security and limitations
Cloud traffic uses HTTPS. Keep the master password, recovery key, devices and shared links secure. PocketProfile cannot decrypt the vault or recover a missing recovery key.
Children
PocketProfile is not directed to children under 13. It is intended for adults managing information they are authorized to manage.
Contact
Privacy and security questions: info@tallinio.com.