PBPasswordBank
PasswordBank

Privacy policy

Last updated: 19 September 2026

Who we are

PasswordBank operates the PasswordBank website and browser extension. Contact support@passwordbank.net for privacy questions, support, or deletion requests. This policy covers our personal and company password-vault features.

Information we handle

How the browser extension works

The extension accesses supported websites to detect login fields, suggest matching saved logins, generate passwords, and fill credentials you select. Website origins are sent to PasswordBank to find matching logins; this is not a general browsing-history service. When a password form is submitted, the extension may temporarily capture the username, password, website origin, and page title to offer a save prompt. Saving to a vault requires your action.

Your PasswordBank account password is transmitted to our HTTPS sign-in endpoint and is not persisted by the extension. A revocable connection token and account metadata are stored in browser-local extension storage. Pending captured credentials are kept in browser session storage, are filtered out after five minutes when accessed, and are cleared on disconnection or session termination. Closing a save prompt is not the same as permanently deleting a previously saved vault item.

Why we use information

We use information to authenticate users, store and retrieve logins, enforce vault permissions, fill and save credentials, detect password-health issues, maintain security records, and respond to support requests. The extension does not include advertising or analytics SDKs. We do not sell personal information or use vault contents for advertising.

Storage and security

Vault usernames, passwords, URLs, and notes are encrypted at rest using a server-held application key. Account passwords are hashed. Titles and some operational metadata are not encrypted vault fields. This is server-side encryption, not end-to-end or zero-knowledge encryption: the application can decrypt vault data to fulfill authorized requests, and control of the server and its encryption key permits decryption. No system can guarantee absolute security.

Website sessions use cookies needed for sign-in and request security. Removing the extension does not delete your server account or saved vaults.

Sharing and service providers

Personal-vault access is restricted to the owning account through application permissions. Company-vault items are available to authorized company members according to their assigned permissions. Company administrators can manage access and view relevant security and activity information; their administrator role alone does not grant access to every saved secret.

We use Laravel Cloud to host the application. Hosting and support-email providers process information needed to deliver those services. If external breach checking is enabled, the server sends only the first five characters of a SHA-1 password hash to the configured Pwned Passwords-compatible service; it does not send the plaintext password or full hash. We may disclose information where required by law or necessary to protect the service and its users.

Retention and deletion

Saved vault data remains stored until it is removed through a completed deletion process. Deleting an item in the application moves it to recoverable trash; it is not immediate permanent erasure. Security records, support correspondence, and backup copies may be retained where necessary for security, recovery, or legal obligations. We do not promise immediate deletion of every backup copy.

To request account or data deletion, email support@passwordbank.net from your registered email address with the subject “PasswordBank deletion request”. Tell us whether you want your account, personal vault, or particular data deleted. We may verify your identity and clarify the scope before acting. Company-owned records require appropriate company authorization and are not automatically erased when an employee account is removed. We will explain any information that must be retained when handling your request.

Your choices and policy updates

You can manage vault items and revoke browser connections through your account. You can also email us to request access to, correction of, or deletion of your information, subject to identity verification and applicable requirements. When this policy changes, we will update the date on this page.