Privacy

Kagisecure Privacy Policy

Effective

Kagisecure is a password manager that keeps your vault on your own Mac. We don't have your data, and we don't ask for it.

The short version

  • Your vault is an encrypted file on your Mac. There is no Kagisecure account and no Kagisecure server that holds your data.
  • The browser extension talks only to the Kagisecure app on the same Mac. It sends the address of the site you are on, and nothing goes to us or to anyone else.
  • A password or one-time code reaches a web page only after you approve that fill in the app.
  • No analytics, no tracking, no advertising, no crash reporting that sends anything.
  • The one network request we make is the macOS app's update check, described below.

Who we are

Kagisecure is published by ITSUCARA, K.K. (“Itsucara”, “we”). This policy covers the Kagisecure browser extension, the Kagisecure app for macOS, and this website, kagisecure.com. Kagisecure is open source, so you can check what is described here against the code.

What the browser extension accesses, and why

The extension has one purpose: to fill sign-in details from your Kagisecure vault into the page you are on. To do that, it runs on web pages (http and https) and does the following:

The extension requests two browser permissions: nativeMessaging, to reach the Kagisecure app on your Mac, and activeTab. It doesn't request access to your browsing history, bookmarks, cookies or downloads.

Once a value is written into a web page, that page can read it, as with any password manager. If you use the extension's one-time-code action on a page with no code box, the code is copied to your clipboard instead. The Kagisecure app clears its own clipboard copies after a delay you can set; the extension can't clear what you do with the clipboard afterwards.

What is stored, and where

What leaves your Mac

From the browser extension: nothing. It contains no code that contacts a web server. It passes messages only to the Kagisecure app on the same Mac, through a small helper that ships inside the app (on Chrome and other Chromium browsers) or through the app's own Safari extension. Everything stays on your Mac.

From the macOS app: the update check. Official builds of the Kagisecure app update themselves using Sparkle, a widely used update framework. It checks https://kagisecure.com/mac/appcast.xml when the app starts and then every hour while it runs. If a newer version exists, the app downloads it from https://kagisecure.com/mac/releases/. The update feed and each download are cryptographically signed, and the app verifies the signature before installing anything. The check does not send a system profile, and it carries no vault data, no account and nothing from the browser extension. As with any web request, our server necessarily sees that a request came from your IP address at a particular time. You can turn the checks off in Settings > Updates; nothing is then checked, even at launch, and you can still choose Check Now. Builds you compile yourself contain no updater.

Where you send things. A few other flows are yours to decide, and we don't operate them:

What we don't do

Chrome Web Store User Data Policy

Kagisecure's use of information received by the browser extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. In particular, the extension uses website addresses and form-field information only to provide its single purpose of filling sign-in details from your vault, and it doesn't transfer or sell that information.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Children

Kagisecure is a general-purpose tool and isn't directed at children. We don't collect personal information from anyone, children included.

Changes to this policy

If the software or this policy changes in a way that affects your privacy, we will update this page and its effective date before the change ships.

Contact

Questions about this policy: hello@kagisecure.com. To report a security vulnerability, please follow the instructions on the home page.

ITSUCARA, K.K.