Last updated: 26 August 2026 · Applies to: the NettForge browser extension for Chrome, Brave, Edge and Firefox
Summary
The NettForge extension helps you sign in to your NettForge account and fill your saved logins on
websites. Your vault is encrypted on your device and only decrypted in memory while
it is unlocked. We do not sell or share your data, we do not show
ads, and we do not track your browsing. The extension talks to only one server —
NettForge's own — and only to sync your own encrypted vault.
1. What the extension accesses
- Your NettForge account — when you sign in, the extension uses your email and
master password to derive your encryption key on your device and to authenticate you. Your
master password is never sent to us and never stored.
- Your encrypted vault — the extension downloads your vault as encrypted data
(ciphertext) and decrypts it in memory to show and fill your logins.
- The current page's web address — to decide whether you have a saved login for
the site you're on, so it can offer to fill it.
- Login form fields on a page — only to fill your username/password when you (or
your autofill setting) ask it to, and to offer to save a new login you type.
2. Your vault stays yours (zero-knowledge)
Your passwords are encrypted with a key derived from your master password using Argon2id and
AES-256-GCM. The extension keeps the encrypted vault in your browser's extension
storage, and the decrypted copy only in temporary in-memory session storage while
it is unlocked — it is wiped when the browser closes or the auto-lock timer fires.
We never receive your master password or the readable contents of your vault, and we could
not read them even if compelled to.
3. The permissions we ask for, and why
- Read the sites you visit / run on web pages (host access & content script)
— so the extension can detect a login form on the site you're on and fill your saved login. It acts
only on login pages and only with data from your own unlocked vault.
- Storage — to keep your encrypted vault and your settings in the browser.
- Scripting / activeTab — to fill the username and password fields on the page
when you choose to.
- Tabs — to read the current tab's address so it can match it to your saved logins.
- Alarms — to run the auto-lock timer that clears your unlocked vault from memory.
- Access to nettforge.com — to sign in and sync your own encrypted vault.
4. What is sent, and to where
The only network destination is NettForge's own servers (nettforge.com), and only
to: authenticate your sign-in and sync your encrypted vault. No page content, no
browsing history, and no vault contents are ever sent to us or to anyone else. The extension contains
no third-party analytics, advertising, or tracking code, and loads no remote code.
5. What we never do
- We never sell, rent, or share your personal information or vault data.
- We never use your data for advertising or to build a profile of you.
- We never transmit the pages you visit or what you type (other than saving a login you
choose to save, which is encrypted into your own vault).
- We never transfer your data to third parties except as required to provide the sync service
(our hosting), and even then only as encrypted, unreadable data.
6. Storage & deletion
Your encrypted vault and settings stay in your browser until you sign out in the
extension, which removes them from that browser. Uninstalling the extension also removes its stored
data. Your account and the server copy of your encrypted vault are governed by our main
Privacy Policy.
Questions about the extension and your privacy? Email
privacy@nettforge.com or use our
contact page.