Back to GeniusVault

Privacy Policy

GeniusVault · Last updated September 7, 2026

The short version

GeniusVault is a zero-knowledge password manager. Your master password is never sent to us, and everything in your vault — logins, notes, cards — is encrypted on your own device before it is ever uploaded. We store only that encrypted blob. We cannot read your passwords, and neither can anyone who compromises our servers.

1. Who we are

GeniusVault is a personal password manager operated by Genius Fixers. This policy covers the GeniusVault web app at vault.geniusfixers.com, the GeniusVault browser extension, and the GeniusVault mobile app (together, the “Service”). By using the Service you agree to this policy.

2. Our core promise: zero-knowledge

GeniusVault is built so that we cannot see your secrets, even if we wanted to. Here is how that works in practice:

  • Your master password is turned into an encryption key on your device using Argon2id. It is never transmitted or stored anywhere.
  • A separate random key encrypts your vault. That key is itself encrypted with your master-password key, so only you can unlock it.
  • Every field (username, password, URL, notes, card number) is encrypted with AES-256-GCM on your device before it is uploaded.
  • We only ever receive and store the resulting ciphertext. We do not have your master password and cannot decrypt your data.

The practical consequence: if you forget your master password, we cannot recover your vault for you. That is the price of true zero-knowledge security.

3. What data we collect

To run the Service, we store the minimum needed:

  • Account email address — used to identify your account, sign you in, and send security codes. Nothing more.
  • Authentication verifier — a value derived from your master password that lets us confirm it is you, without ever seeing the password itself.
  • Your encrypted vault — the ciphertext of your items. Unreadable to us.
  • Basic operational data — session tokens and trusted-device tokens so you don’t have to re-verify on every visit, plus standard server logs (such as request timestamps) kept only for security and reliability.

4. What we can never see

Off-limits to us, by design
  • Your master password
  • Your stored passwords, usernames, and website URLs
  • Your secure notes, payment cards, and identities
  • Anything else you place inside your vault

5. The browser extension

The GeniusVault browser extension exists to fill and save logins on the sites you visit. It is important to us that you understand exactly what it does:

  • All decryption happens locally inside the extension. Your vault key is held only in the browser’s in-memory session storage and is erased when you close the browser or lock the extension.
  • The extension reads the web address of the current tab only to find logins that match that site, and reads/writes login fields only to fill them or to offer to save a new login you just typed.
  • It does not track your browsing, does not read page content beyond the login fields it acts on, and does not inject ads or analytics.
  • A password is only written into a page after you explicitly click the matching entry.

6. Extension permissions we request

Chrome asks you to approve a small set of permissions. Here is why each one is needed:

  • storage — to keep your session locally so the extension stays unlocked while you work.
  • activeTab / scripting — to detect login fields on the page you are on and fill them when you choose an entry.
  • host access — so the autofill dropdown can appear on the sites where you keep logins. Access is used solely for autofill and save; page contents are never sent to us.

7. We do not sell your data

We do not sell, rent, or trade your personal information. We do not use your data for advertising. We have no advertising business. Your encrypted vault is never shared with any third party.

8. Service providers

We use a small number of infrastructure providers to run the Service — cloud hosting (DigitalOcean), a database provider (MongoDB Atlas), and an email provider to deliver login codes. These providers only ever handle encrypted vault data or the minimal account data described above; none of them can read your vault contents. We also offer an optional breach check that, only when you choose to use it, queries the “Have I Been Pwned” service using a privacy-preserving method that never reveals your full password.

9. How we protect your data

  • End-to-end encryption with AES-256-GCM and Argon2id key derivation.
  • All traffic served over HTTPS/TLS.
  • A strict Content Security Policy on the web app to neutralise script-injection attacks.
  • Optional two-factor and email verification for new devices.
  • Encryption and decryption performed only on your device.

10. Data retention & deletion

We keep your account data for as long as your account is active. You can delete individual items at any time from within the app. If you want your entire account and its encrypted vault permanently deleted, contact us at [email protected] and we will remove it.

11. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. Because your vault is encrypted with a key only you hold, the vault contents are already in your sole control. For account-level requests, reach us at the address below.

12. Children

GeniusVault is not directed to children under 13, and we do not knowingly collect data from them.

13. Changes to this policy

If we make material changes to this policy, we will update the date at the top of this page and, where appropriate, notify you in the app. Continued use of the Service after a change means you accept the updated policy.

14. Contact us

Questions about privacy or this policy? Email us at [email protected].

© 2026 GeniusVault · Genius FixersOpen the vault →