Loading...
Loading...
Legal
Absolute Zero Toolbox is a privacy-first, on-device developer toolkit. Your vault is encrypted locally on your own machine. There is no Absolute Zero account, no Absolute Zero server, and no backend that receives your vault contents, master password, TOTP secrets, browsing history, or scan findings. We do not use analytics, tracking pixels, or advertising SDKs, and we do not sell or share personal data.
| Data | Where it is stored | Purpose |
|---|---|---|
| Master password | Never stored. A key is derived from it (PBKDF2-SHA256, 310,000 iterations) and held in memory only while unlocked | Unlock the vault |
| Vault contents (TOTP accounts and secrets, snippets, groups) | Encrypted with AES-256-GCM as ciphertext in chrome.storage.local | Provide the authenticator and snippets features |
| Derived encryption key | chrome.storage.session, only when auto-lock is set to “on browser close” or “off”; cleared when the browser fully exits | Avoid forcing a re-unlock when Chrome suspends the extension |
| Preferences (theme, auto-lock timer, pinned/hidden tools, clipboard timer) | chrome.storage.local, unencrypted | Remember your settings |
| Tool working data (API collections, scan history, temp-mail address, form-filler preferences) | chrome.storage.local | Persist your work between sessions |
All of the above stays on the Chrome profile where it was created. It is not synced to us. Uninstalling the extension removes this data for that profile. You can also export or wipe vault data from Settings at any time.
Some tools read the page you are on — for example Storage Manager, Exposure Scanner, Form Filler, and the optional Site Insights feature. This reading happens locally, in your browser, only when you run that tool. Page content is never transmitted to Absolute Zero. There is no Absolute Zero server to transmit it to.
Data leaves your browser only when you personally use a feature that requires the network, and it goes to the destination that feature names — never to us:
cloudflare-dns.com) and/or Google (dns.google).crt.sh) for the hostname you enter.ipapi.co). This is opt-in; your own IP is only looked up if you explicitly ask for it.QR codes are generated locally on your device; no image service is contacted.
These third-party services receive only what that specific tool needs to work (for example, the hostname you typed). We do not send them your vault data, and we receive nothing back about you.
Site Insights is disabled unless you turn it on in Settings. Its page-scanning script is not even loaded into web pages while it is off. When you enable it, the extension samples the current page locally to spot signals such as Stripe test keys, staging or preview hostnames, and common development build fingerprints, and may show a small in-page notice. The sampled content is analysed in your browser and is not uploaded anywhere. You can dismiss a notice, mute it per site and rule, clear muted dismissals, or switch the feature off entirely.
storage — save the encrypted vault and your preferencessidePanel, tabs, activeTab, scripting — run the side panel interface and the tools that act on the tab you choosecookies — Storage Manager cookie editing and scanner cookie checksdebugger — used only by the Interceptor tool, and only for the tab you explicitly attach it to. Chrome displays its own banner whenever this is active. Detaching ends it.declarativeNetRequest — set request headers for CORS and header probing that you initiateclipboardRead, clipboardWrite — copy codes and findings, paste tokens, and support the optional clipboard auto-clear timeralarms — auto-lock the vault after inactivitycontextMenus — the right-click “Fill this Form / Field” shortcutsThis extension is a developer tool and is not directed at children under 13.
If this policy changes materially, the “Last updated” date above will change and the updated policy will be published at this URL before the change takes effect in a released version.
Questions or privacy requests: hello@its-tahir.com
Email hello@its-tahir.com