Privacy Policy
Last updated: July 21, 2026
Overview
ChatVault is a local-first Chrome extension for exporting, backing up, and organizing ChatGPT, Claude, and Gemini conversations. It has no application backend: there is no ChatVault server that receives, stores, or processes your conversation content. This policy describes what the extension and this website access, and what they never do.
Permissions the extension requests
The extension uses three core permissions: downloads (saving ZIP archives to a location you choose), sidePanel (the batch job interface), and scripting (registering a content script only on a platform you enable). Settings, job checkpoints, and optional Vault content use the extension's own local IndexedDB and do not require the Chrome storage permission.
Host access is requested per platform and is optional: https://chatgpt.com/*, https://claude.ai/*, and https://gemini.google.com/* are each requested only when you enable that platform. ChatVault never requests access to all websites, never requests cookie permissions, and never collects passwords, session cookies, or authentication tokens. Revoking a platform's permission unregisters its content scripts; other enabled platforms keep working.
Data the extension handles
When you enable a supported platform and start an export, ChatVault reads the conversation titles, messages, timestamps, conversation links, and attachment references needed to create the archive. These are website content, personal communications, and limited browsing activity on the enabled platform. ChatVault uses them only for the export, completeness checks, optional local Vault search, and user-requested re-export features.
Before host access is requested, the extension displays this data-use disclosure next to the enable control. Granting the platform permission is the affirmative action that allows ChatVault to handle that platform's conversation data. Declining the request leaves that platform disabled.
Local-only processing
Extraction, normalization, validation, rendering, and ZIP packaging all run on your device with deterministic code. Conversation bodies, titles, URLs, prompts, replies, and attachments are never transmitted to any server, never written to a console, and never included in telemetry or support bundles.
ChatVault reads only the pages your own signed-in account can already access. It does not scrape platforms from a server, bypass authentication or access controls, or export data your account cannot see.
Data stored locally on your device
The extension stores job state, checkpoints, and settings in your browser profile's IndexedDB and local storage. If you choose to keep conversations in the Vault, their normalized content is also stored locally in IndexedDB. Exported ZIP files are saved by your browser to the download location you choose.
None of this data leaves your device. Local Vault storage is a convenience for search and re-export; it is not a substitute for keeping the exported files in safe storage.
Optional diagnostics
If you enable diagnostics, reports contain only content-free information: job and item states, product, adapter and schema versions, count ranges, and error codes such as permission, authentication, platform-change, incomplete-load, unsupported-content, storage, rendering, or packaging categories. Diagnostics never include conversation content, titles, prompts, replies, URLs, or attachments.
Website analytics
This website loads Google Tag Manager in production only. GA4 and Microsoft Clarity, when configured, run as tags inside the published GTM container. Website analytics measure page visits and link clicks; they never receive conversation content, which never touches the website at all.
Data the extension never transmits or requests
ChatVault never transmits conversation content or titles, prompts or replies, attachments, conversation URLs, or local Vault data. It never requests platform passwords, session cookies, or authentication tokens, and it does not access browsing activity outside the platforms you explicitly enable. There are no ChatVault user accounts or application backend.
Chrome Web Store Limited Use disclosure
ChatVault's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide the extension's user-facing local backup, export, integrity-checking, organization, and troubleshooting features.
ChatVault does not sell or transfer user data, use it for advertising or profiling, use it to determine creditworthiness or lending eligibility, or allow humans to read it. Because the extension does not transmit user data to ChatVault or third parties, there is no server-side retention or sharing.
Deleting your data
You can delete a single retained conversation from the Vault, or wipe all local data from the extension's settings. The full wipe removes retained conversations, job checkpoints, and settings from your browser profile. Because no data is ever sent to a server, local deletion is complete deletion. Exported ZIP files you saved can be deleted like any other file on your device.
Changes to this policy
If the product's data behavior changes, this page is updated before or with the release that changes it. Future capabilities that move data, such as encrypted cloud backup, will be documented here with their provider, purpose, retention, and deletion behavior before they ship, and will always be opt-in.
Contact
Questions about privacy are answered through support or directly at support@chatvault.pro.