Loading...
Loading...
Legal
Absolute Zero Toolbox is a developer toolkit that runs entirely on your own device. There is no Absolute Zero account, no Absolute Zero server, and no backend operated by the developer. The developer does not receive, store, or have any access to your data.
This policy describes, in full, what data the extension collects, how it is handled, how and where it is stored, and the circumstances in which it is shared with third parties.
The extension collects and processes the following categories of user data. All of it is collected locally on your device, and only as a direct result of an action you take.
What: Two-factor authentication (TOTP) secrets and account labels you add to the vault, reusable text snippets you save, and the master password you choose.
How it is collected: Only when you enter it — by typing a secret, pasting an otpauth:// URI, importing a QR code image, or saving a snippet. The extension never scans your device or your browser for credentials.
Why: To generate time-based two-factor codes and to store snippets you asked it to keep.
What: The content of the page in the tab you are working on — its HTML, cookies, and site storage values.
How it is collected: Only at the moment you run a tool that requires it: Storage Manager, Form Filler, Exposure Scanner, or the optional Site Insights feature. There is no background reading, no continuous monitoring, and no reading of tabs you are not acting on.
Why: To perform the specific action you requested — for example listing the cookies for the current site, filling a form with test data, or checking a page for exposed credentials.
What: Your settings (theme, auto-lock timer, pinned and hidden tools, clipboard timer) and the work you create in the tools (saved API collections, scan history, form-filler preferences, and any disposable email address you generated).
How it is collected: Created by you as you use the extension.
Why: To remember your configuration and preserve your work between sessions.
The extension does not collect, and has no capability to collect, any of the following:
The extension contains no analytics, no telemetry, no tracking pixels, and no advertising software of any kind.
All processing happens locally, inside your browser, on your own device.
The developer has no access to any of this data at any point. It is never sent to the developer, and no infrastructure exists that could receive it.
| Data | Where it is stored | Protection |
|---|---|---|
| Master password | Never stored anywhere | Not applicable — only a derived key is held in memory while unlocked |
| Vault contents (TOTP secrets, snippets, groups) | chrome.storage.local, on your device | Encrypted at rest with AES-256-GCM |
| Derived encryption key | chrome.storage.session, and only when auto-lock is set to “on browser close” or “off” | Held only for the browser session; cleared when the browser fully exits |
| Preferences | chrome.storage.local, on your device | Stored unencrypted; contains no secrets |
| Tool working data | chrome.storage.local, on your device | Stored unencrypted; contains only what you created |
All storage is local to the Chrome profile where it was created. Nothing is synced to the developer, and nothing is stored on any server operated by the developer.
Site Insights is switched off unless you explicitly enable it in Settings. While it is off, its script is not loaded into any web page.
When you enable it, the extension samples the current page locally to detect signals such as sandbox payment keys, staging or preview hostnames, and development build fingerprints, and may show a small in-page notice. The sampled content is analysed entirely in your browser and is never uploaded to anyone. You can dismiss a notice, mute it for a specific site and rule, clear those dismissals, or switch the feature off at any time.
Because all data stays on your device, you control its lifetime completely.
The developer cannot delete your data on your behalf, because the developer never holds it.
Vault contents are encrypted at rest using AES-256-GCM. The encryption key is derived from your master password using PBKDF2-SHA256 with 310,000 iterations and a random per-installation salt. The master password itself is never stored, and the derived key is held only while the vault is unlocked.
Because encryption is tied to a password only you know, there is no recovery mechanism. If you forget your master password, the vault cannot be decrypted by anyone, including the developer.
storage — save the encrypted vault and your preferencessidePanel, tabs, activeTab, scripting — run the side panel interface and let tools act on the tab you choosecookies — Storage Manager cookie editing and Exposure Scanner cookie checksdebugger — used only by the Interceptor tool, and only on a tab you explicitly attach it to. Chrome displays its own banner the entire time it is active, and detaching ends itdeclarativeNetRequest — set request headers for CORS and header probes that you initiateclipboardRead, clipboardWrite — copy codes and results, paste tokens, and support the optional clipboard auto-clear timeralarms — lock the vault automatically after inactivitycontextMenus — the right-click “Fill this Form” and “Fill this Field” shortcutsThis extension is a developer tool intended for professional use. It is not directed at children under 13 and does not knowingly collect data from them.
If this policy changes materially, the “Last updated” date above will change and the revised policy will be published at this URL before the change takes effect in a released version of the extension.
Questions, concerns, or privacy requests: hello@its-tahir.com
Email hello@its-tahir.com