简要承诺
收藏夹保险箱是一款客户端浏览器扩展。开发者不运营用于接收、分析或出售用户数据的后台服务器;扩展不包含广告、行为分析、遥测或跨网站跟踪功能。
扩展只为用户明确使用的功能处理数据:加密隐私收藏夹、将受保护网址在隐身窗口打开,以及把加密备份保存到用户自行选择的本地文件或第三方存储服务。
扩展处理哪些数据
- 收藏夹数据:文件夹名称、网页标题、网址及层级结构。启用完整备份时,快照还会包含普通浏览器收藏夹。
- 当前页面信息:仅在用户主动点击“收藏当前网页”时读取当前标签页的标题和网址。
- 保险箱安全数据:加密密文、随机盐、初始化向量和密钥派生参数。主密码只用于本机派生加密密钥,不会被持久保存或发送给开发者。
- 备份设置与凭据:用户选择的 WebDAV、S3 或云盘连接设置。OneDrive、Dropbox 的 OAuth 令牌以及 WebDAV/S3 凭据随保险箱一起加密;Google 访问令牌由 Chrome 管理。
- 运行状态:自动锁定策略、最近活动时间、备份是否成功以及待执行备份状态。
数据如何使用
上述数据仅用于提供用户可见的核心功能,不用于广告、画像、信用评估、数据经纪或任何与收藏夹保险箱无关的目的。
锁定状态下,扩展不会在界面显示受保护文件夹名称、网页标题或网址。用户解锁后,解密操作在浏览器本地完成。
安全措施与保存期限
- 本地保险箱和备份使用 PBKDF2-SHA-256(600,000 次迭代)派生密钥,并使用 AES-256-GCM 加密。
- 派生后的会话密钥仅存放在 Chrome 的会话存储中,并按用户设置的锁定策略清除。
- 本地数据保留到用户删除相应内容、清除扩展数据或卸载扩展为止。
- 第三方存储中的加密备份保留到用户通过相应服务删除为止。断开云盘连接不会自动删除已有备份。
- 主密码无法找回;开发者没有解密用户保险箱或备份的后门。
浏览器权限用途
用户的选择与控制
用户可以随时锁定保险箱、导出加密备份、取消保护收藏夹、断开云盘账户,或者通过卸载扩展删除本机扩展数据。
如需删除云端备份,用户应在其选择的云盘、WebDAV 或 S3 服务中删除相应文件。撤销 OAuth 授权可在 Google、Microsoft 或 Dropbox 的账户安全设置中完成。
儿童隐私、政策更新与联系
本扩展不以儿童为目标,也不会主动收集年龄信息。若本政策发生实质变化,更新后的版本将在本页面公布,并修改生效日期。
隐私相关问题可通过 Chrome 网上应用店商品页面 中发布者提供的联系方式反馈。
LIMITED USE DISCLOSURE
Google API 有限使用声明
从 Google API 获取的信息,其使用和传输将遵守 Chrome 网上应用店用户数据政策,包括“有限使用”要求。
The use and transfer of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
ENGLISH VERSION
Privacy Policy
Effective date: September 7, 2026
Bookmark Vault is a client-side browser extension. The developer does not operate a backend server that receives, analyzes, or sells user data. The extension contains no advertising, analytics, telemetry, or cross-site tracking.
Data handled
The extension processes bookmark folder names, page titles, URLs, folder structure, encrypted vault data, lock and backup settings, and—only when the user explicitly saves the current page—the active tab's title and URL. A full backup also contains ordinary browser bookmarks. The master password is used locally to derive an encryption key and is never persistently stored or sent to the developer.
Storage and backup
Cloud backup is disabled by default. When enabled by the user, backup contents are encrypted on the device with AES-256-GCM before being transmitted to the user's selected Google Drive, OneDrive, Dropbox, WebDAV, or S3-compatible service. OneDrive and Dropbox OAuth tokens and WebDAV/S3 credentials are stored inside the encrypted vault; Google access tokens are managed by Chrome. The developer cannot read users' backups.
Use, sharing, and retention
Data is used only to provide the extension's user-facing bookmark protection, private-window opening, and backup features. It is not used for advertising, profiling, or sale. Data remains locally until the user removes it, clears extension data, or uninstalls the extension. Encrypted cloud backups remain until the user deletes them from the selected provider.
User control and contact
Users may lock the vault, export encrypted backups, unprotect bookmarks, disconnect providers, revoke OAuth access, and delete local or cloud data at any time. Privacy questions may be sent through the publisher contact method shown on the Chrome Web Store listing.