Privacy policy
Last updated: 10 September 2026
This policy covers the Corenexis Secrets web app at secrets.corenexis.com, the Corenexis Secrets Android app, and the Corenexis Secrets browser extension (together, “Corenexis Secrets”). It is operated by Corenexis. Corenexis Secrets is currently available by invitation only.
The short version
- Everything you store in your vault is encrypted on your device before it is sent to us. We do not have your master password, your passcode or your keys, so we cannot read your vault — not the passwords, notes, cards, codes or files.
- We keep only what is needed to run your account and keep it secure. We do not sell data, show ads, or use tracking or advertising cookies.
- The browser extension only touches a web page when you ask it to fill a login there.
What we store, and why
Your encrypted vault
Items, folders, files and their names are stored as ciphertext produced on your device (AES-256-GCM, with keys derived from your master password that never leave it). We store the encrypted data so it can sync between your devices. We cannot decrypt it and we cannot reset your master password; if you lose it, only your recovery keys can restore access.
Account information
Your email address, display name, plan, and cryptographic verifiers (one-way hashes that let us check a sign-in without learning your password). If you sign in with a Corenexis account, we store its account identifier to link it.
Security records
To protect your account we keep: active sessions (IP address, browser or device description, last activity), registered devices, and a security log of events such as sign-ins, failed attempts, passcode changes and sharing. We email you when a new sign-in happens, so you can revoke it. Session records expire when unused; the security log is kept while your account exists.
Website icons
When website icons are switched on (Preferences → Website icons), the app asks our server for the icon of a login’s website. Our server fetches it from a public icon service (Google or DuckDuckGo) and returns it; the icon is then stored inside your encrypted item. This means our server learns the domain names you request icons for. The icon services see only that domain, sent from our server — not your address or identity. You can turn icons off at any time. Icons for common services, card networks and file types are built into the apps and need no request.
The browser extension
- Page access: the extension uses Chrome’s “active tab” permission. It can see the address of a tab, and fill a form in it, only after you click the extension or press its shortcut on that tab. It never reads page content in the background and never fills anything automatically.
- What it reads to fill: it looks at the page’s login fields to place your username and password, and only on the site the login is saved for — it refuses lookalike addresses and warns before filling on an insecure (http) page.
- What it stores on your computer: a sign-in token, your email address, a device identifier, and an encrypted copy of your vault (ciphertext, the same as our server holds). While the vault is unlocked, the decryption key is held in the browser’s memory only and is erased when the vault locks or the browser closes.
- What it sends: only requests to secrets.corenexis.com — to sign in, unlock and download your encrypted vault. It contains no analytics and loads no remote code.
The Android app
The app stores the same kinds of data on your phone as the extension. Fingerprint or face unlock uses a key held in Android’s secure hardware keystore; we never receive biometric data. The camera is used only to scan authenticator QR codes, on your device.
Who else is involved
- Hosting and delivery: our servers, and Cloudflare, which carries traffic to them.
- Email: security and sign-in emails are sent by the Corenexis mail service.
- Sign-in with Corenexis: if you use it, accounts.corenexis.com confirms who you are.
We do not share your data with anyone else, except where the law requires it — and even then, your vault contents are encrypted and unreadable to us.
Your choices and rights
You can export your vault, change your master password and passcode, review and revoke sessions and devices, and turn website icons off, from Settings. To have your account and all its data deleted, ask your administrator or contact us below; deleting an account removes its encrypted data, sessions and devices.
Contact
Questions about this policy: [email protected].
Changes
If this policy changes in a way that matters, we will update the date above and tell signed-in users.