Publisher: SagePennyStudio. Contact: sagepennystudio@gmail.com. Updated 15 September 2026.
Vault has one purpose: back up and recover your Chrome workspace. Version 0.2.0 adds optional paid accounts and client-encrypted cloud recovery. Optional paid checkout is available through Stripe Managed Payments.
Local protection
Vault stores tab addresses and titles, order, window membership, pinned and active state, tab-group names, colors and collapsed state, timestamps, labels, a random device identifier and settings in your Chrome profile. It excludes Incognito and excluded domains from new captures. It never reads page contents, forms, cookies, passwords or keystrokes. There are no advertising, analytics, content scripts or remote favicon requests in the extension.
Free local protection needs no account and makes no requests to the Vault service. New automatic history defaults to 7 days. Pro and Local Lifetime allow up to 1 year. Points retain the deadline saved when captured, even after a downgrade. Expired points enter a 7-day recovery bin. Named points and the latest healthy point are preserved. Local snapshots are not encrypted at rest by this extension. Uninstalling Vault or deleting the Chrome profile removes local data.
Optional paid account
Creating or connecting an account contacts the Vault service hosted on Cloudflare Workers. The service stores an account ID, a SHA-256 hash of your private account recovery code, licence and billing status, a Stripe customer ID, purchase references, device names and IDs, connection timestamps and cloud-storage metadata. Your recovery code is generated for your account and sent over HTTPS when connecting; its raw value is not stored in the service database. This device stores your account recovery code and signed licence so it can connect and check paid access. A Local Lifetime activation certificate can be saved separately and used offline.
Stripe handles checkout and payment details through Managed Payments. Vault never receives card numbers or bank details. Stripe sends authenticated purchase, renewal, cancellation, refund and dispute events to the Vault backend. These are used only to verify access and manage recovery availability. Stripe and Cloudflare also process ordinary network, fraud-prevention and security information under their own policies: Stripe privacy and Cloudflare privacy.
Optional encrypted cloud copies
Pro cloud backup is off by default and requires a separate choice. The extension encrypts each portable archive with AES-256-GCM before uploading to Cloudflare R2. Only ciphertext, an opaque copy ID, device ID, timestamps, byte size and an integrity checksum are sent to cloud storage. The cloud passphrase is never sent or stored. A random, non-extractable encryption key is stored in this device’s extension database, wrapped by a passphrase-derived key for recovery on other devices. A passphrase cannot be recovered by the publisher.
Copies are made hourly while Chrome is running and can be made manually. Each copy expires after 1 year. Uploads pause at the 250 MB account limit or without verified Pro access. Up to 5 devices may connect, with 10 MB per copy. After Pro ends, cloud recovery remains available for 30 days, then copies are scheduled for removal. Earlier individual expiry still applies. Pending uploads are held encrypted on this device so interrupted transfers can retry. Cloud recovery is an explicit download, decryption, import and preview, it does not automatically open your tabs.
Exports and permissions
Manual export/import and local recovery remain available on all plans. Readable JSON exposes its tab addresses to anyone with the file. Passphrase-encrypted archives need their original passphrase. Scheduled encrypted downloads require Pro or Local Lifetime and the optional Downloads permission. They save the latest healthy workspace to Chrome’s Downloads folder daily while Chrome runs. Exports are not automatically deleted.
The service host permission is optional and requested when you create or connect an account. It allows requests only to the dedicated Vault API. The unlimitedStorage permission supports larger local archives and reduces routine eviction, it does not grant access to other websites or files. Normal browsing requests occur when you choose to load recovered tabs.
Your controls
Pause local capture in Settings, pause cloud uploads in Account & plans, and download or remove individual cloud copies there. Disconnecting removes this device’s account code, cloud key and pending transfers; it leaves local restore points, Local Lifetime activation and existing cloud copies. Disconnecting does not cancel a subscription. Manage cancellation through Stripe Link. Exclusions do not rewrite existing history or copies.
For account-metadata removal or privacy requests, contact the support address with your account ID or Stripe receipt reference. We will arrange verification without asking you to email your recovery code, passphrase or readable archive. Exported files, other-device copies and payment records retained by Stripe must be managed separately. Service records are kept while needed to operate the account and until a verified deletion request is completed. Short-lived, salted request identifiers are used for rate limiting and removed after expiry. The app does not retain raw IP addresses in its account database.
Limited Use
Vault complies with the Chrome Web Store User Data Policy, including Limited Use. Chrome API information is used only for workspace backup, recovery and user-requested exports or encrypted cloud copies. It is not sold, used for advertising or unrelated purposes, or used to determine creditworthiness or lending eligibility. Cloudflare processes encrypted backups and service metadata to provide the chosen features. The publisher cannot decrypt cloud copies without the user’s passphrase.
This website is hosted by Cloudflare, which may process normal request and security logs. Support emails are processed by the email provider and publisher to respond to your request. Never email your private account code or cloud passphrase. Keep an independent exported copy outside this device.