Data Veilpage handles
Veilpage stores the following data in the user’s Chrome profile:
- web origins and paths where the user created masking rules;
- CSS selectors and masking options chosen by the user;
- extension preferences and synchronization state;
- a one-way verifier for the local master key; and
- WebAuthn public credential metadata when device unlock is enabled.
Veilpage does not collect fingerprints, facial scans, device PINs, or other biometric measurements.
Optional account and encrypted synchronization
If the user enables synchronization:
- Clerk processes account identifiers, email addresses, authentication factors, sessions, and security metadata required to provide sign-in.
- Convex receives an account identifier, pseudonymous device identifier, device label and platform, revision numbers, timestamps, integrity hashes, and an encrypted synchronization snapshot.
- Page origins, paths, selectors, and masking rules are encrypted on the user’s device before they are sent to Convex.
- The recovery key used to decrypt synchronized rules is not sent to Clerk or Convex in plaintext.
The service operator cannot read the contents of a correctly encrypted synchronization snapshot without the user’s recovery key. Losing that key can make synchronized data unrecoverable.
Browser permissions
Veilpage requests access to web pages so it can apply masking rules selected by the user. It uses Chrome storage for local settings, scripting support for the page picker, and cookies for the Clerk authentication session used by optional synchronization.
Veilpage does not sell browsing activity, use page contents for advertising, or collect analytics through this privacy-policy website.
Use, sharing, and retention
Data is used only to provide Veilpage’s masking, authentication, security, and encrypted synchronization functions. Veilpage does not sell personal data or transfer it for personalized advertising, credit decisions, or unrelated purposes.
Clerk and Convex process the limited data described above as service providers. Their privacy and security terms also apply to their services.
Local data remains in the Chrome profile until the user clears Veilpage data or uninstalls the extension. Cloud synchronization data remains until the user deletes it from the signed-in Private Sync panel or a deletion request is completed. In-app deletion removes the active Convex profile, snapshots, and device records; Veilpage does not create a separate application backup of those deleted records. The Clerk account is separate and remains until an account-deletion request is completed.
User choices and deletion
Users can use Veilpage without an account, disconnect synchronization from a device, delete individual masking rules, reset a forgotten local master key while preserving local rules, or clear the extension’s local data. A signed-in user can delete their encrypted sync profile, encrypted snapshots, and registered device metadata directly from the Private Sync panel. This action does not delete the Clerk account or local rules already stored on a device. Account deletion and other deletion requests can be made through the support contact shown on Veilpage’s Chrome Web Store listing.
Security and Limited Use
Veilpage uses authenticated encryption for synchronization snapshots and limits backend data to what is necessary to operate the feature. No system can guarantee absolute security.
Veilpage’s use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.
Changes
Material changes to this policy will be reflected by updating this page and its effective date.
Contact
For privacy or support questions, use the support contact on Veilpage’s Chrome Web Store listing.