Skip to content
ChatVault

Privacy Policy

Last updated: September 9, 2026

Overview

ChatVault is a local-first Chrome extension for exporting, backing up, and organizing ChatGPT, Claude, and Gemini conversations. It has no application backend: there is no ChatVault server that receives, stores, or processes your conversation content. This policy describes what the extension and this website access, and what they never do.

Permissions the extension requests

The extension uses five core permissions: downloads saves ZIP archives to your browser's download folder; sidePanel displays exports, Settings and Saved chats; scripting registers packaged content scripts only on a platform you enable; offscreen creates local archive Blob URLs in a hidden extension document; and alarms checks whether an export you already started needs recovery. The alarm does not schedule new backups. Settings, job checkpoints, and optional saved conversations use the extension's own IndexedDB and do not require the Chrome storage permission.

Host access is requested per platform and is optional: https://chatgpt.com/*, https://claude.ai/*, and https://gemini.google.com/* are each requested only when you enable that platform. ChatVault never requests access to all websites, never requests cookie permissions, and never collects passwords, session cookies, or authentication tokens. Revoking a platform's permission unregisters its content scripts; other enabled platforms keep working.

Data the extension handles

When you enable a supported platform and start an export, ChatVault reads the conversation titles, messages, timestamps, conversation links, and attachment references needed to create the archive. These are website content, personal communications, and limited browsing activity on the enabled platform. ChatVault uses them only for the export, completeness checks, optional local Vault search, and user-requested re-export features.

Settings explains the local data use beside the platform access controls. The export screen also explains that first use requires access to the selected platform and that chats stay on this device. Granting the platform permission allows ChatVault to handle that platform's conversation data for exports you start. Declining the request leaves that platform disabled.

Local-only processing

Extraction, normalization, validation, rendering, and ZIP packaging all run on your device with deterministic code. Conversation bodies, titles, URLs, prompts, replies, and attachments are never transmitted to any server, never written to a console, and never included in telemetry or support bundles.

ChatVault reads only the pages your own signed-in account can already access. It does not scrape platforms from a server, bypass authentication or access controls, or export data your account cannot see.

Data stored locally on your device

The extension stores job state, checkpoints, settings and temporary archive data in your browser profile's IndexedDB. If you choose to keep conversations in Saved chats, their normalized content is also retained locally in IndexedDB. Chrome saves exported ZIP files in your configured download folder.

None of this data leaves your device. Local Vault storage is a convenience for search and re-export; it is not a substitute for keeping the exported files in safe storage.

Optional diagnostics

If you enable diagnostics, reports contain only content-free information: job and item states, product, adapter and schema versions, count ranges, and error codes such as permission, authentication, platform-change, incomplete-load, unsupported-content, storage, rendering, or packaging categories. Diagnostics never include conversation content, titles, prompts, replies, URLs, or attachments.

Website analytics

This website loads Google Tag Manager in production only. GA4 and Microsoft Clarity, when configured, run as tags inside the published GTM container. Website analytics measure page visits and link clicks; they never receive conversation content, which never touches the website at all.

Data the extension never transmits or requests

ChatVault never transmits conversation content or titles, prompts or replies, attachments, conversation URLs, or local Vault data. It never requests platform passwords, session cookies, or authentication tokens, and it does not access browsing activity outside the platforms you explicitly enable. There are no ChatVault user accounts or application backend.

Chrome Web Store Limited Use disclosure

ChatVault's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide the extension's user-facing local backup, export, integrity-checking, organization, and troubleshooting features.

ChatVault does not sell or transfer user data, use it for advertising or profiling, use it to determine creditworthiness or lending eligibility, or allow humans to read it. Because the extension does not transmit user data to ChatVault or third parties, there is no server-side retention or sharing.

Deleting your data

Open Saved chats in the side panel to delete a retained conversation, or use Settings > Delete all local data to remove retained conversations, job checkpoints, temporary archives and settings from your browser profile. There is no server-side copy held by ChatVault. Exported ZIP files remain on disk until you delete them like other files on your device.

Changes to this policy

If the product's data behavior changes, this page is updated before or with the release that changes it. Future capabilities that move data, such as encrypted cloud backup, will be documented here with their provider, purpose, retention, and deletion behavior before they ship, and will always be opt-in.

Contact

Questions about privacy are answered through support or directly at [email protected].