Privacy Policy

This Privacy Policy applies to the Smart Safe Password Manager mobile application, the Smart Safe Web App and the Smart Safe Browser Extensions for Google Chrome and Mozilla Firefox (collectively, “Smart Safe”). Smart Safe is developed by Christian Conti, who can be contacted at chri.c79@gmail.com.

Last updated: July 28, 2026

Scope and data controller

The data controller for personal data processed directly by Smart Safe is Christian Conti. This policy explains what data Smart Safe processes, why it is processed, where it is stored, when it is deleted and the choices available to users.

Most vault content is stored locally on the user's device or, when synchronization is enabled, as an encrypted database in the user's own Google Drive application data folder. The Developer cannot view or recover the user's master password or the decrypted contents of the vault.

Terms of Use

Smart Safe may be used for private or business purposes in accordance with this document and the terms of the store or platform from which it was obtained.

Google Play Terms of Service

Synchronization with Google Drive

Google Drive synchronization is optional. When enabled, the user authenticates with a Google Account through Google's authorization flow. Smart Safe requests access only to its private Google Drive application data folder (appDataFolder) and does not request access to the user's other Drive files.

Smart Safe stores the encrypted Smart_Safe.db backup in this private application data folder. Files in that folder are hidden from the normal Google Drive interface, cannot be shared and are accessible only to Smart Safe through the authorized Google account. Smart Safe updates this encrypted file when synchronization is performed.

The Google Account email address used for synchronization may be stored locally in Smart Safe preferences or temporarily in Firefox session extension storage so the selected account can be displayed. The user can disconnect Smart Safe from Google Drive or remove the hidden application data through the Google Account/Drive settings.

Smart Safe Chrome Browser Extension

The Smart Safe Browser Extension is a read-only companion to the Smart Safe Web App. Its sole purpose is to let the user import credentials from an already unlocked Smart Safe Web App, match saved accounts to the website open in the active browser tab, and fill or copy a selected username and password after an explicit user action.

The extension may process the following categories of data:

  • Authentication information: usernames, email addresses and passwords selected by the user from the unlocked vault.
  • Current tab information: the active page URL or domain, used only to find credentials associated with that website.
  • Website content: visible login-form elements needed to identify and fill username and password fields.
  • Extension settings: the Smart Safe Web App address and the selected automatic-lock timeout.

The extension does not create or modify vault records, automatically submit login forms, record browsing history, monitor pages in the background, display advertising, perform analytics or build user profiles.

Imported credentials are not sent to the Developer. They are used locally in the browser only to provide the credential matching, copying and filling functions requested by the user.

Smart Safe Firefox Extension

The Smart Safe Firefox Extension is a read-only companion for the Smart Safe password manager. Unlike the Chrome extension, it can connect directly to the user's private Google Drive application data folder after the user explicitly authorizes access through Google OAuth.

The Firefox extension requests the Google OAuth scopes needed to access only the private appDataFolder and to read the email address of the authorized Google Account. It downloads the encrypted Smart_Safe.db file, reads the file metadata needed for synchronization and decrypts the database locally in Firefox only after the user enters the database password. The extension does not upload, modify, share or delete vault records or the database stored in Google Drive.

The Firefox extension may process the following categories of data:

  • Authentication information: usernames, email addresses and passwords extracted locally from the decrypted vault.
  • Google Account information: the email address of the Google Account selected for synchronization.
  • OAuth information: the Google OAuth access token and its expiration time, used only to authenticate requests to Google APIs.
  • Database information: the encrypted database file, its modification time and the database password entered by the user.
  • Current tab information: the active page URL or domain, used only to match saved accounts to the current website.
  • Website content: visible login-form elements needed to identify and fill username and password fields after a user action.
  • Extension settings: the selected automatic-lock timeout and other local preferences.

The OAuth access token and its expiration time are stored in Firefox local extension storage so the user is not required to sign in every time the popup is opened. The token is removed and a revocation request is sent to Google when the user selects the disconnect function. OAuth tokens also expire according to Google's rules and may be renewed through Google's authorization flow. Smart Safe does not store or distribute a Google OAuth client secret in the extension.

Decrypted credential records, the database password, the source Google email address and related synchronization metadata are kept only in Firefox session extension storage while the vault is unlocked. They are removed when the user locks the extension, when the automatic-lock timer expires, when the extension session is reset or when the browser session ends.

Network requests made by the Firefox extension are limited to Google's OAuth, user information and Google Drive API endpoints required for the user-requested synchronization. Vault contents and the database password are not sent to the Developer, Google or any other third party by Smart Safe. The extension does not use advertising, analytics, telemetry, tracking or profiling.

Browser Extension permissions

The Chrome and Firefox extensions request only the permissions necessary for their stated purposes:

  • activeTab: grants temporary access to the active tab after the user interacts with the extension.
  • scripting: runs packaged extension code in the active tab to import data where applicable or fill the selected login fields.
  • storage: stores local preferences, keeps decrypted vault data temporarily in browser session storage and, in Firefox, stores the Google OAuth access token and expiration time in local extension storage.
  • alarms: schedules the automatic lock that removes temporary decrypted credentials and the database password after the selected timeout.
  • identity (Firefox): opens and completes the Google OAuth authorization flow initiated by the user.
  • Google API host access (Firefox): permits requests only to the Google Drive, OAuth token-revocation and Google user-information endpoints required for synchronization and disconnection.

These permissions are not used for advertising, tracking, analytics, background browsing monitoring or unrelated functionality. The extensions do not download or execute remote code; all executable extension code is packaged with the extension.

Data collection, use and sharing

Smart Safe processes data only where necessary to provide and secure its requested functions.

The email address entered for PREMIUM verification may be transmitted securely to the Smart Safe server solely to verify the user's purchase or entitlement. It is not used for advertising or profiling.

Smart Safe does not sell personal data. Smart Safe does not transfer personal data to third parties for advertising, data-broker, creditworthiness, lending or unrelated profiling purposes. Data may be processed by platform providers such as Google only when required to provide the user-selected Google Drive, browser or store functionality and subject to their applicable terms and privacy policies.

No vault content is shared with the Developer. The encrypted database stored in Google Drive remains under the user's Google account and is not made available to other users or third-party applications through Smart Safe. The Firefox extension communicates directly with Google OAuth and Google Drive API services for the user-requested authorization and download operations.

Storage, retention and deletion

  • Local vault: retained on the user's device until the user deletes the data or uninstalls/clears the application.
  • Google Drive backup: retained in the user's private application data folder until deleted by the user or removed when Smart Safe is disconnected/uninstalled from Google Drive.
  • Browser extension credentials: kept only in browser session extension storage (chrome.storage.session on Chrome or browser.storage.session on Firefox) while the extension is unlocked. They are cleared when the user locks the extension, the automatic-lock timer expires, the extension session is reset or the browser session ends.
  • Firefox database password and synchronization metadata: kept only in Firefox session extension storage while the vault is unlocked and removed together with the temporary credential records.
  • Firefox OAuth data: the Google access token and its expiration time are retained in Firefox local extension storage to maintain the authorized connection. They are removed when the user disconnects Google, clears extension data or removes the extension; the token also expires according to Google's rules.
  • Browser extension settings: retained locally until changed, reset or the extension is removed.
  • PREMIUM verification email: retained only for as long as necessary to verify and administer the user's entitlement, comply with legal obligations and prevent abuse.

Because the Developer cannot access locally stored or encrypted vault data, requests concerning that data must normally be completed by the user through Smart Safe, the browser or Google Drive.

Limited Use disclosures

Smart Safe Chrome Browser Extension's use of information received from Chrome APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Smart Safe Firefox Extension uses information obtained through Firefox WebExtension APIs only to provide the user-facing authentication, synchronization, credential matching, copying, filling, locking and settings functions described in this policy.

Smart Safe's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Information obtained through Chrome, Firefox or Google APIs is used only to provide or improve the user-facing Smart Safe functionality, to maintain security, or where required by applicable law. It is not used for personalized advertising and is not sold.

Your privacy rights

Depending on applicable law, including the GDPR where applicable, users may have rights to be informed, access personal data, request correction or deletion, restrict processing, receive portable data, object to processing and lodge a complaint with a competent data protection authority.

To exercise rights concerning data held directly by the Developer, contact chri.c79@gmail.com. The Developer may need to verify the requester's identity before acting on a request. Data stored only on the user's device, in the browser session or in the user's Google Drive account is not accessible to the Developer and can be managed directly by the user.

Security

Smart Safe uses encryption and secure network connections to protect data in transit and at rest where applicable. The browser extensions use temporary session storage for decrypted credentials and do not use browser synchronized storage for passwords. The Firefox extension stores only the Google OAuth access token and its expiration time in local extension storage to preserve the user's authorized connection. Users are responsible for protecting their master password, Google Account and device access.

No system can guarantee absolute security. Users should keep Smart Safe, the browser and the operating system updated and should lock the application or extension when it is not in use.

Disclaimer

The user acknowledges that software may contain defects and may not satisfy every requirement. Installation and use are at the user's own risk. The user is responsible for maintaining suitable backups and for any data loss. Smart Safe is provided “as is”, without express or implied warranties. To the maximum extent permitted by law, the Developer is not liable for damages arising from the use of, or inability to use, Smart Safe.

Warranty

The Developer provides no warranty and, to the maximum extent permitted by applicable law, is not responsible for losses or damages related to use of Smart Safe. The user remains responsible for deciding whether Smart Safe is appropriate for the intended use.

Changes to this policy and contact

This Privacy Policy may be updated when Smart Safe functionality, legal requirements or platform policies change. The “Last updated” date at the top of this page identifies the latest revision. Material changes will be communicated through the website, application, extension or store listing where appropriate.

Questions or privacy requests may be sent to chri.c79@gmail.com.