If you enable sync, your vault is uploaded as an encrypted blob to our backend (a Cloudflare Worker with KV storage). The server stores only the encrypted blob, a one-way authentication hash, and a salt. The server cannot decrypt your vault — it never has the key. This is zero-knowledge / end-to-end encryption. If you never enable sync, nothing leaves your device.
Masked email is generated through a provider you choose (Fastmail, addy.io, SimpleLogin, DuckDuckGo, Firefox Relay, or Forward Email) using your own account/API token, stored encrypted in your vault. The request goes directly from your browser to that provider — it never passes through Veridenti's servers. Veridenti does not operate an email service and does not receive your messages.
Veridenti contacts no analytics server unless you explicitly turn on "Share anonymous usage stats." If you opt in, what we collect is anonymous and aggregate: an active-device count via a token that rotates weekly (not a persistent identifier); coarse country (never city, never a stored IP); and form-fill success rate and which form types get fixed.
What we never collect, even when opted in: your logins, passwords, or vault contents; any value you type; the specific sites you visit or full URLs; your identity; your IP or precise location. There are no third-party trackers, no advertising SDKs, and no analytics cookies anywhere in Veridenti.
Veridenti's anti-phishing protection (look-alike-site warnings, password-reuse warnings, form-skimmer detection) runs entirely on your device, comparing pages only against your own saved logins. Your browsing is never sent anywhere for these checks.
Veridenti requests broad host access (http://*/*, https://*/*) for one reason: a password manager must be able to fill and protect logins on any site you use, and it can't know in advance which sites those are. It does not read or transmit page contents; it looks at form fields locally to fill them and to detect threats.
Because we hold only an unreadable encrypted blob and (if opted in) anonymized aggregates, we hold no personal data we can identify you by. You can still request deletion of any synced blob. We do not sell personal information as defined by CCPA.
Veridenti is not directed to children under 13 and does not knowingly collect their data.
We'll post changes here with a new "last updated" date. Questions: privacy@veridenti.com.
← Back to veridenti.com