Effective date: July 17, 2026
Passkey Manager — Stack Intelligence is a Chrome extension for creating, storing, using, and securely sharing passkeys. This policy explains the data the extension handles, why it is used, and when it is shared.
Passkey Manager handles the user’s name, email address, Google account identifier when Google sign-in is used, organization membership, role, master password timeout setting, device fingerprint, and device public encryption and signing keys.
This information is used for account authentication, team membership, administration, device registration, and secure sharing.
For email/password accounts, the password is transmitted to the configured account server over HTTPS. The server stores a salted scrypt password hash, not the plaintext password.
For Google sign-in, a Google OAuth access token is sent over HTTPS to the account server for validation. The Google access token is not stored as a passkey or as the user’s master password.
The user’s master password is processed locally to derive the vault encryption key. It is not transmitted to the account server and is not stored.
Passkey private keys are encrypted locally using AES-256-GCM. Decrypted vault and key material is held only in Chrome session storage while the vault is unlocked and is cleared when the vault is locked, the timeout is reached, or the browser is closed.
The local vault also stores passkey metadata needed to identify and use a credential, including:
Website relying-party domain
Account username or display name
Credential identifier
Public key
Creation time
Last-used time
Private passkey keys remain encrypted at rest.
When synchronization or sharing is enabled, Passkey Manager transmits account session data, device public keys, organization directory information, and end-to-end encrypted passkey or shared-folder payloads to the configured Passkey Manager server.
Passkey and folder contents are encrypted for their intended recipients before transmission. The relay stores encrypted payloads until recipients retrieve and acknowledge them.
Folder creators choose recipients and assign read-only or edit permissions.
Under the current company-vault design, organization Owners and Admins receive encrypted access to company passkeys so they can perform authorized administrative and recovery functions.
During a passkey creation or sign-in request, the extension processes the active website origin and WebAuthn relying-party domain to select the correct passkey, validate the request, and display the confirmation panel.
The extension does not collect general browsing history, read unrelated webpage content, capture form entries, record keystrokes, or monitor clicks for analytics or advertising.
The server temporarily processes IP addresses for authentication rate limiting. Hosting and network providers may also process standard request metadata for security, reliability, and operational logging.
When email delivery is enabled, the user’s email address and a time-limited verification or password-reset message are provided to Resend for delivery.
Verification codes are stored by the account server only as hashes and stop being valid after 15 minutes.
Information is used only to provide, maintain, secure, and support Passkey Manager’s passkey-management functionality, including:
Account sign-in
Local vault encryption
Website authentication
Team administration
Shared folders
Encrypted synchronization
Abuse prevention
User-requested verification emails
User-requested password-reset emails
Information is not used for advertising, cross-service profiling, creditworthiness decisions, or lending decisions.
Information is disclosed only when needed to provide the service:
Google processes information for Google OAuth sign-in.
Fly.io hosts the configured account and encrypted relay service.
Resend processes recipient email addresses and message contents when email verification or password-reset delivery is enabled.
Authorized folder recipients and organization Owners or Admins receive data encrypted for the access granted to them.
Passkey Manager does not sell user data.
Information may also be disclosed when required by law, when necessary to protect users or the service from security threats, or as part of a corporate transaction subject to applicable legal requirements.
Passkey Manager’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Local vault data remains in Chrome storage until the user:
Deletes individual items
Resets the vault
Clears extension data
Uninstalls the extension
Encrypted relay messages remain until the intended recipient retrieves and acknowledges them.
Account, organization, role, device, and security records are retained while needed to operate and secure the account.
Authentication sessions stop being valid after 30 days.
Verification and password-reset codes stop being valid after 15 minutes.
Users may request deletion of their server-side account information using the contact address below.
Removing a user from a company team does not automatically delete that user’s separate account.
Data may be retained where required for security, legal compliance, dispute resolution, or legitimate backup cycles.
The extension requires HTTPS for non-local servers.
Passkey private keys are encrypted locally using AES-256-GCM with a key derived from the master password using PBKDF2-SHA-256.
Shared passkey and folder contents use recipient-specific end-to-end encryption.
Email-account passwords are protected on the server using salted scrypt hashes.
No system can guarantee absolute security. Users are responsible for protecting their master password and authorized devices.
Passkey Manager is an internal business authentication tool and is not directed to children.
This policy may be updated when functionality or data practices change.
The effective date shown at the beginning of this policy will be updated when a revised policy is published.
For privacy questions or deletion requests, contact:
Tanzeel Rahman
tanzeel.rahman@stackintelligence.com