This Privacy Policy applies to the Smart Safe Password Manager mobile application, the Smart Safe Web App and the Smart Safe Browser Extensions for Google Chrome and Mozilla Firefox (collectively, “Smart Safe”). Smart Safe is developed by Christian Conti, who can be contacted at chri.c79@gmail.com.
Last updated: July 28, 2026
The data controller for personal data processed directly by Smart Safe is Christian Conti. This policy explains what data Smart Safe processes, why it is processed, where it is stored, when it is deleted and the choices available to users.
Most vault content is stored locally on the user's device or, when synchronization is enabled, as an encrypted database in the user's own Google Drive application data folder. The Developer cannot view or recover the user's master password or the decrypted contents of the vault.
Smart Safe may be used for private or business purposes in accordance with this document and the terms of the store or platform from which it was obtained.
Google Play Terms of Service
Google Drive synchronization is optional. When enabled, the user authenticates with a Google
Account through Google's authorization flow. Smart Safe requests access only to its private
Google Drive application data folder (appDataFolder) and does not request access
to the user's other Drive files.
Smart Safe stores the encrypted Smart_Safe.db backup in this private application
data folder. Files in that folder are hidden from the normal Google Drive interface, cannot be
shared and are accessible only to Smart Safe through the authorized Google account. Smart Safe
updates this encrypted file when synchronization is performed.
The Google Account email address used for synchronization may be stored locally in Smart Safe preferences or temporarily in Firefox session extension storage so the selected account can be displayed. The user can disconnect Smart Safe from Google Drive or remove the hidden application data through the Google Account/Drive settings.
The Smart Safe Browser Extension is a read-only companion to the Smart Safe Web App. Its sole purpose is to let the user import credentials from an already unlocked Smart Safe Web App, match saved accounts to the website open in the active browser tab, and fill or copy a selected username and password after an explicit user action.
The extension may process the following categories of data:
The extension does not create or modify vault records, automatically submit login forms, record browsing history, monitor pages in the background, display advertising, perform analytics or build user profiles.
Imported credentials are not sent to the Developer. They are used locally in the browser only to provide the credential matching, copying and filling functions requested by the user.
The Smart Safe Firefox Extension is a read-only companion for the Smart Safe password manager. Unlike the Chrome extension, it can connect directly to the user's private Google Drive application data folder after the user explicitly authorizes access through Google OAuth.
The Firefox extension requests the Google OAuth scopes needed to access only the private
appDataFolder and to read the email address of the authorized Google Account. It
downloads the encrypted Smart_Safe.db file, reads the file metadata needed for
synchronization and decrypts the database locally in Firefox only after the user enters the
database password. The extension does not upload, modify, share or delete vault records or the
database stored in Google Drive.
The Firefox extension may process the following categories of data:
The OAuth access token and its expiration time are stored in Firefox local extension storage so the user is not required to sign in every time the popup is opened. The token is removed and a revocation request is sent to Google when the user selects the disconnect function. OAuth tokens also expire according to Google's rules and may be renewed through Google's authorization flow. Smart Safe does not store or distribute a Google OAuth client secret in the extension.
Decrypted credential records, the database password, the source Google email address and related synchronization metadata are kept only in Firefox session extension storage while the vault is unlocked. They are removed when the user locks the extension, when the automatic-lock timer expires, when the extension session is reset or when the browser session ends.
Network requests made by the Firefox extension are limited to Google's OAuth, user information and Google Drive API endpoints required for the user-requested synchronization. Vault contents and the database password are not sent to the Developer, Google or any other third party by Smart Safe. The extension does not use advertising, analytics, telemetry, tracking or profiling.
The Chrome and Firefox extensions request only the permissions necessary for their stated purposes:
These permissions are not used for advertising, tracking, analytics, background browsing monitoring or unrelated functionality. The extensions do not download or execute remote code; all executable extension code is packaged with the extension.
Smart Safe processes data only where necessary to provide and secure its requested functions.
The email address entered for PREMIUM verification may be transmitted securely to the Smart Safe server solely to verify the user's purchase or entitlement. It is not used for advertising or profiling.
Smart Safe does not sell personal data. Smart Safe does not transfer personal data to third parties for advertising, data-broker, creditworthiness, lending or unrelated profiling purposes. Data may be processed by platform providers such as Google only when required to provide the user-selected Google Drive, browser or store functionality and subject to their applicable terms and privacy policies.
No vault content is shared with the Developer. The encrypted database stored in Google Drive remains under the user's Google account and is not made available to other users or third-party applications through Smart Safe. The Firefox extension communicates directly with Google OAuth and Google Drive API services for the user-requested authorization and download operations.
chrome.storage.session on Chrome or browser.storage.session on Firefox) while the extension is unlocked. They are cleared when the user locks the extension, the automatic-lock timer expires, the extension session is reset or the browser session ends.Because the Developer cannot access locally stored or encrypted vault data, requests concerning that data must normally be completed by the user through Smart Safe, the browser or Google Drive.
Smart Safe Chrome Browser Extension's use of information received from Chrome APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Smart Safe Firefox Extension uses information obtained through Firefox WebExtension APIs only to provide the user-facing authentication, synchronization, credential matching, copying, filling, locking and settings functions described in this policy.
Smart Safe's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Information obtained through Chrome, Firefox or Google APIs is used only to provide or improve the user-facing Smart Safe functionality, to maintain security, or where required by applicable law. It is not used for personalized advertising and is not sold.
Depending on applicable law, including the GDPR where applicable, users may have rights to be informed, access personal data, request correction or deletion, restrict processing, receive portable data, object to processing and lodge a complaint with a competent data protection authority.
To exercise rights concerning data held directly by the Developer, contact chri.c79@gmail.com. The Developer may need to verify the requester's identity before acting on a request. Data stored only on the user's device, in the browser session or in the user's Google Drive account is not accessible to the Developer and can be managed directly by the user.
Smart Safe uses encryption and secure network connections to protect data in transit and at rest where applicable. The browser extensions use temporary session storage for decrypted credentials and do not use browser synchronized storage for passwords. The Firefox extension stores only the Google OAuth access token and its expiration time in local extension storage to preserve the user's authorized connection. Users are responsible for protecting their master password, Google Account and device access.
No system can guarantee absolute security. Users should keep Smart Safe, the browser and the operating system updated and should lock the application or extension when it is not in use.
The user acknowledges that software may contain defects and may not satisfy every requirement. Installation and use are at the user's own risk. The user is responsible for maintaining suitable backups and for any data loss. Smart Safe is provided “as is”, without express or implied warranties. To the maximum extent permitted by law, the Developer is not liable for damages arising from the use of, or inability to use, Smart Safe.
Smart Safe is owned by Christian Conti. Except where applicable law expressly permits otherwise, users may not modify, translate, reverse engineer, decompile, disassemble, attempt to derive source code from, or create derivative works from Smart Safe or any part of it.
The Developer provides no warranty and, to the maximum extent permitted by applicable law, is not responsible for losses or damages related to use of Smart Safe. The user remains responsible for deciding whether Smart Safe is appropriate for the intended use.
This Privacy Policy may be updated when Smart Safe functionality, legal requirements or platform policies change. The “Last updated” date at the top of this page identifies the latest revision. Material changes will be communicated through the website, application, extension or store listing where appropriate.
Questions or privacy requests may be sent to chri.c79@gmail.com.