Privacy
Kagisecure Privacy Policy
Kagisecure is a password manager that keeps your vault on your own Mac. We don't have your data, and we don't ask for it.
The short version
- Your vault is an encrypted file on your Mac. There is no Kagisecure account and no Kagisecure server that holds your data.
- The browser extension talks only to the Kagisecure app on the same Mac. It sends the address of the site you are on, and nothing goes to us or to anyone else.
- A password or one-time code reaches a web page only after you approve that fill in the app.
- No analytics, no tracking, no advertising, no crash reporting that sends anything.
- The one network request we make is the macOS app's update check, described below.
Who we are
Kagisecure is published by ITSUCARA, K.K. (“Itsucara”, “we”). This policy covers the Kagisecure browser extension, the Kagisecure app for macOS, and this website, kagisecure.com. Kagisecure is open source, so you can check what is described here against the code.
What the browser extension accesses, and why
The extension has one purpose: to fill sign-in details from your Kagisecure vault into the page you are on. To do that, it runs on web pages (http and https) and does the following:
- Looks for sign-in forms. It checks the page, in your browser, for username, password and one-time-code fields. It reads the fields' attributes and labels to recognize them. It does not read what you type into them.
- Asks the app which saved logins fit this site. The request carries the site's origin (for example
https://example.com) and, inside a frame, the origin of the page that contains it. It does not carry the full address, page path, page content or your browsing history. The app answers with the titles and usernames of matching items, which the extension uses to show its key icon and its menu. Never a password. - Fills only when you ask. A password or a one-time code is requested only when you click the key icon, press the keyboard shortcut or choose an item in the extension's popup. The Kagisecure app then asks you to approve with Touch ID, your login password or an Apple Watch. There is no autofill on page load.
- Agent-requested fills (optional, off by default). If you turn this on in the app and an AI agent asks to sign in for you, the app asks the extension about the tab in front. The extension reports whether that tab is visible and which kinds of fields it has (username, password, one-time code), together with the tab's origin. The app shows you its own approval sheet. Only then is the value written into the page, and the agent is told only which fields were written.
The extension requests two browser permissions: nativeMessaging, to reach the Kagisecure app on your Mac, and activeTab. It doesn't request access to your browsing history, bookmarks, cookies or downloads.
Once a value is written into a web page, that page can read it, as with any password manager. If you use the extension's one-time-code action on a page with no code box, the code is copied to your clipboard instead. The Kagisecure app clears its own clipboard copies after a delay you can set; the extension can't clear what you do with the clipboard afterwards.
What is stored, and where
- Your vault. A single encrypted file on your Mac (XChaCha20-Poly1305, with a key derived from your master password using Argon2id). Kagisecure holds the unlocked key only in the running app and drops it when you lock, sleep or go idle. We never receive the file or the key.
- An audit log. The app keeps a log of approvals and fills, so you can see what used your secrets. It stays on your Mac.
- The extension stores nothing on disk. It doesn't use browser storage. While you sign in on a site that asks for your username and password on separate pages, it keeps in memory, for at most 60 seconds, which saved item you chose and the site it was for, so the second page can continue. It is discarded when the timer ends, the tab closes or leaves the site, or the vault locks, and the popup has a Forget button.
- Shared vaults (optional). If you create or join a shared vault, the app writes encrypted record files to a folder you choose, such as an iCloud Drive or Dropbox folder. What happens to files in that folder is up to the sync service you picked, under that service's own terms. Kagisecure doesn't run or see that service.
What leaves your Mac
From the browser extension: nothing. It contains no code that contacts a web server. It passes messages only to the Kagisecure app on the same Mac, through a small helper that ships inside the app (on Chrome and other Chromium browsers) or through the app's own Safari extension. Everything stays on your Mac.
From the macOS app: the update check. Official builds of the Kagisecure app update themselves using Sparkle, a widely used update framework. It checks https://kagisecure.com/mac/appcast.xml when the app starts and then every hour while it runs. If a newer version exists, the app downloads it from https://kagisecure.com/mac/releases/. The update feed and each download are cryptographically signed, and the app verifies the signature before installing anything. The check does not send a system profile, and it carries no vault data, no account and nothing from the browser extension. As with any web request, our server necessarily sees that a request came from your IP address at a particular time. You can turn the checks off in Settings > Updates; nothing is then checked, even at launch, and you can still choose Check Now. Builds you compile yourself contain no updater.
Where you send things. A few other flows are yours to decide, and we don't operate them:
- Websites. When you approve a fill, the value goes into that website's sign-in form, and the site receives it when you submit it.
- AI agents. If you connect an agent such as Claude Code or Codex to Kagisecure, the agent can see names and structure: item titles, categories, and environment and variable names. It never sees secret values. Whatever an agent does with those names is governed by the agent's own provider and settings.
- Downloads. The app is distributed through GitHub and Homebrew, and downloading it is governed by those services' policies.
What we don't do
- We don't sell or rent user data, and we don't transfer it to third parties. We don't have it to transfer.
- We don't use analytics, advertising, tracking pixels or fingerprinting, in the extension, the app or this website. This website sets no cookies and loads no third-party scripts.
- We don't use user data for advertising of any kind, or for creditworthiness or lending decisions.
- We don't send crash reports or usage statistics.
- We don't run remote code in the extension. All of the extension's code is packaged with it and it loads nothing from the internet.
- Our staff can't read your data. It never reaches us.
Chrome Web Store User Data Policy
Kagisecure's use of information received by the browser extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. In particular, the extension uses website addresses and form-field information only to provide its single purpose of filling sign-in details from your vault, and it doesn't transfer or sell that information.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Children
Kagisecure is a general-purpose tool and isn't directed at children. We don't collect personal information from anyone, children included.
Changes to this policy
If the software or this policy changes in a way that affects your privacy, we will update this page and its effective date before the change ships.
Contact
Questions about this policy: hello@kagisecure.com. To report a security vulnerability, please follow the instructions on the home page.
ITSUCARA, K.K.