Privacy Policy
Effective: 27 August 2026.
Local processing
Core password analysis, password generation, phishing-text analysis, URL structure checks, user-selected file hashing and heuristics, encrypted vault operations, browser audits, performance diagnostics and local reports are designed to operate in the user's browser.
User-selected files
Files selected for local inspection are read by browser code for hashing and basic heuristic analysis. The standard local file scanner does not upload those files to AutoSecurityApp.
Encrypted vault
Vault content is stored in browser local storage as AES-GCM encrypted data. The encryption key is derived from the master password with PBKDF2-SHA256. The master password is not stored by the application.
Optional online services
The optional breach check sends only a short SHA-1 hash prefix to a breach-range service using a k-anonymity model. Website and email-domain audits send the public website/domain supplied by the user to AutoSecurityApp's server endpoints so public headers or DNS records can be inspected.
PWA install statistics
AutoSecurityApp may maintain aggregate PWA install-event counts. The supplied counter is designed not to intentionally store IP addresses, user identifiers, device fingerprints, browsing history, passwords, filenames or security-scan contents.
Browser storage
Local reports, encrypted vault data, PWA caches and preferences may remain in browser storage until the user clears them.
Privacy & Data Enquiries
For privacy, data-protection or rights-related enquiries contact legal@autosecurityapp.com. For general enquiries contact contact@autosecurityapp.com.
Operator: Alpha & Omega Limited.