1. Overview & Scope
This Privacy Policy explains how the Make Your Life Easier (MYLE) Windows desktop application and the MYLE Passwords browser extension handle information. MYLE Passwords is distributed for Chromium-based browsers (Google Chrome, Microsoft Edge, Brave) and for Mozilla Firefox.
MYLE is designed as a local-first, zero-knowledge product. Your vault is created, encrypted, unlocked and read on your own computer. The browser extension is a thin client for that desktop application: it never contacts a MYLE server, an analytics endpoint, or any third-party service of ours.
- Data controller / publisher: Thomas Thanos, operating MYLE as an independent software publisher.
- Products covered: the MYLE Windows application and the MYLE Passwords extension, including its background service worker, popup and content scripts.
- Legal framing: written to satisfy the Chrome Web Store User Data Policy, the Mozilla Add-on Policies, and the EU General Data Protection Regulation (GDPR).
2. Data We Do NOT Collect
MYLE Passwords does not collect, log, transmit, sell, rent or share any of the following. This is an absolute statement, not a conditional one: there is no code path in the extension that sends this data anywhere.
- Browsing history, visited URLs, tab titles, bookmarks or navigation timing.
- Search queries, form contents unrelated to sign-in, or page text and DOM snapshots.
- Analytics, usage statistics, crash pings, heat maps, session recordings or tracking pixels.
- Advertising identifiers, fingerprints, IP-based profiling, or any data used for ad targeting.
- Personal data sold or shared with data brokers, ad networks or third-party partners — we have none.
- Your master password. It is never stored, never logged and never leaves your machine; only a key derived from it exists, in memory, while the vault is unlocked.
3. How the Browser Extension Works (Local Processing)
Everything the extension does happens on your device, between the browser process and the MYLE application installed on the same computer.
- Local form detection. Content scripts identify username and password inputs on
https://pages (plushttp://localhostandhttp://127.0.0.1for developers). Detection runs entirely inside your browser tab; no page content is sent off-device. - Native Messaging only. The extension communicates exclusively with the local MYLE Windows application via the browser's
nativeMessagingAPI, using the host manifestcom.thomasthanos.myleand an authenticated, per-user Windows named pipe. There is no HTTP client, no socket to the internet, and no remote endpoint. - Ephemeral save prompts. When you submit a sign-in form, the credential pair may be held for up to 60 seconds in volatile in-memory session storage (
chrome.storage.session) so the extension can offer to save or update the login after the post-login redirect. It is wiped immediately afterwards, and always when the browser session ends. - Explicit user action. Credentials are only ever filled when you click an entry in the inline autofill menu or the popup, and only when the frame's origin matches the stored entry over HTTPS. There is no silent or automatic filling.
4. Browser Extension Permissions Justification
Each permission requested by MYLE Passwords is listed below with its single, narrow purpose, as disclosed in the Chrome Web Store listing.
nativeMessaging— used solely to exchange messages with the MYLE desktop application installed on your own PC.activeTab— used to read the active tab's URL when you open the popup, so matching entries can be listed, and to fill credentials on your click.storage— used only for ephemeralstorage.sessionstate during sign-in form submission. No vault data and no history is written to persistent extension storage.webNavigation— used to verify which frame initiated a sign-in and confirm its HTTPS origin before any fill is allowed.- Host permissions
https://*/*,http://localhost/*,http://127.0.0.1/*— required to detect username and password inputs and render the inline autofill menu on the site you are signing in to. - Remote code: MYLE Passwords does NOT use any remotely hosted code. All JavaScript, WASM and assets are bundled inside the reviewed extension package.
5. Vault Cryptography & Optional Cloud Sync
- Local vault file. Your vault lives at
%APPDATA%\ThomasThanos\MakeYourLifeEasier\passwords.vaultand contains ciphertext only — no plaintext titles, usernames, URLs or notes. - Key derivation. Your master password derives a master key with
Argon2id(64 MiB memory, 3 passes), tuned to resist GPU and ASIC brute-force attacks. - Entry encryption. Every entry is sealed with
XChaCha20-Poly1305using a unique nonce and authenticated associated data, so tampering is detected on unlock. - Windows Hello (optional). If enabled, the vault key is sealed locally through the Windows platform TPM/credential provider. The sealed blob never leaves your device.
- Account Sync (optional, off by default). If you sign in and enable sync, only end-to-end encrypted ciphertexts and wrapped keys are transmitted to the hosted database (Supabase). Neither MYLE nor the database provider can decrypt titles, usernames, URLs or passwords, because no key material derived from your master password is ever uploaded.
- Account data for sync. When sync is enabled, the service stores your account email, an authentication identifier and encrypted record blobs with timestamps — the minimum required to authenticate you and reconcile devices, on the legal basis of performing the service you requested.
6. Chrome Web Store Limited Use Certification
MYLE Passwords' use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
- Data is used only to provide or improve the single, user-facing purpose of filling and saving your own credentials.
- Data is never transferred to third parties, except as strictly required to operate user-enabled encrypted sync, for security investigations, or to comply with applicable law.
- Data is never used or transferred for advertising, retargeting, personalisation, or credit-scoring purposes.
- No humans read your data. Vault contents are unreadable without your master password, which we do not possess.
7. User Control, Data Deletion & Contact
- Lock instantly. Lock the vault from the MYLE app or the extension popup; the in-memory key is destroyed immediately and autofill stops working until you unlock again.
- Disable browser filling. Turn off browser integration in MYLE's settings, or remove the extension from your browser. The desktop vault continues to work unchanged.
- Delete local data. Deleting
passwords.vaultpermanently removes your local vault. Because it is encrypted with a key only you can derive, deletion is irreversible. - Delete synced ciphertext. Disable sync and request account deletion; all stored encrypted records and the account row are removed. GDPR rights of access, rectification, erasure, restriction, portability and objection can be exercised by email.