Your data, explained
Privacy policy
Effective October 1, 2026.
This policy describes the P4 Warden Chrome extension, version 1.0.2, its optional connection to the P4 Warden Mac app, and this website. It explains what the client processes even when that information stays on your device. Your chosen Vaultwarden server and optional service providers have their own privacy practices.
Information the extension handles
- Vault information: logins, passwords, usernames, verification-code secrets, passkeys, cards, identities, secure notes, folders, tags, custom fields, attachments, and Send items you choose to access or manage.
- Account and connection information: your configured server address, sign-in email, account and device identifiers, authentication tokens, and information needed to authenticate and sync.
- Website information: the active page address, login fields, and credentials involved in filling or an enabled save prompt. Optional page features inspect the relevant page and form interactions. The extension does not read Chrome's history database; it does handle page addresses needed for matching and filling.
- QR codes and clipboard contents: Scan QR code captures the visible tab only when requested and decodes it locally. Copy actions place selected values on the clipboard. A later clipboard check can clear the copied value if it has not changed.
- Preferences and local activity: feature choices, account preferences, timeout settings, generated-value history, and item-use timestamps needed for the interface.
Where information goes
The extension connects to the HTTPS Vaultwarden server you configure for authentication, encrypted vault synchronization, and operations you request. Vault content is encrypted, but the server also handles account information, authentication requests, and connection metadata such as your IP address. The server operator controls its logs, backups, and retention.
When you fill a website, the selected credentials are placed in that page's fields. Passkey requests return a response to the requesting website after the extension's approval flow. Only use these features on websites you intend to trust.
Optional website icons send the hostname saved with a login to the icon service on your configured vault server. Optional email aliases contact your chosen SimpleLogin or Addy.io service with the provider token and information needed to create the alias. These services may receive connection metadata and apply their own policies.
Optional desktop pairing exchanges account and session information with the P4 Warden app on the same Mac through a native messaging host. Touch ID verification is handled by macOS; the extension does not receive your fingerprint.
The extension contains no integrated advertising or analytics service. The site contains no analytics scripts, tracking pixels, forms, or application cookies. Its hosting provider may receive request information, such as IP address, requested URL, and browser information, when serving a page.
Local storage and retention
The extension stores account settings, preferences, and an encrypted offline vault copy on your device. Generated-value history retains up to 20 entries, encrypted under the vault account key. Saved forwarding-service tokens are also encrypted. The master password is not saved.
An unlocked session uses decrypted information in memory. Depending on your vault timeout choices, session keys and authentication tokens can remain in Chrome session storage; the Never setting can persist a usable session in local storage. Choose those settings with the security of your device in mind.
Pending captured logins expire after five minutes if you do not act on them. Clipboard clearing follows your configured delay and only clears the expected copied value. It cannot remove copies made by other apps, clipboard managers, or websites.
Locking ends access to the unlocked vault but can leave the encrypted offline copy and preferences on the device. Signing out removes account-specific cached data and credentials according to the app's sign-out flow. Uninstalling removes the extension's local storage; it does not delete data from your server, provider accounts, exported files, backups, or other devices.
Your choices
You choose the vault server and when to fill, copy, save, or share information. You can adjust timeout settings, turn off optional page features and website icons, remove provider tokens, disconnect the desktop app, revoke site access in Chrome, sign out, or uninstall the extension. Manage remote vault records and server retention through your server account and administrator.
Limited use
P4 Warden uses information accessed through Chrome permissions to provide its vault-management features. That information is not sold, used for advertising, transferred for unrelated purposes, or used to determine creditworthiness or for lending. Its use and transfer follow the Chrome Web Store User Data Policy, including the Limited Use requirements.
Support and contact
Contact the publisher at p@ccly.dev with privacy questions or data requests. If you email support, your email address, message, and attachments reach the publisher's email provider and are used to respond. Do not send passwords, vault keys, recovery codes, payment details, or unredacted vault exports.
Support messages are accessible to the publisher and its email service provider and retained only as long as needed to respond and resolve the request. This website is hosted by Vercel, which processes request metadata to deliver and secure the site. Changes to this policy will be posted on this page.