This page is for the Loginator Password Manager extension in Microsoft Edge.
Your vault stays encrypted on this Microsoft Edge profile. We do not collect it, we do not see it, and we cannot read it. Optional feedback, breach checks, and Loginator Pro billing are described below.
Overview
Loginator for Microsoft Edge is a local-first password, card, and authenticator manager. This privacy policy explains how the Microsoft Edge extension handles (or does not handle) your data. It is the policy we submit with the Microsoft Edge Add-ons listing.
Data Collection
Nothing by default.
The Microsoft Edge extension does not collect vault contents or personal information by default
We do not collect usage analytics from Microsoft Edge
We do not use cookies or tracking technologies in the extension
Optional sync uses an encrypted relay that cannot read your vault
We do not sell, share, or monetize any user data
Optional Loginator Pro on the Microsoft Edge extension is billed through Stripe. We receive only your subscription status — never your full payment card details — and Pro activates via a signed license with no account linked to your vault
Data Storage in Microsoft Edge
All vault data is stored on this device, in this Microsoft Edge profile:
Passwords and authentication entries are stored in encrypted extension storage
Payment card information is encrypted and stored locally
Your encryption keys never leave your device
Optional sync and backup are always end-to-end encrypted
Permissions in Microsoft Edge
The Microsoft Edge extension asks only for permissions it uses:
Storage holds the encrypted vault
Active tab and optional site access autofill or save on a site after you allow it
Context menus fill from the Microsoft Edge right-click menu
Downloads save a backup you start
Alarms lock the vault after idle time
Broad website access is optional. Microsoft Edge asks you before the extension can fill or save on a new site.
Encryption
The Microsoft Edge extension uses nested AES-256-GCM inside XChaCha20-Poly1305 for vault data at rest. Optional pairing uses ML-KEM-768 and ML-DSA-65. Cryptographic work happens on your device.
Feedback Feature
Opt-In Feature: Anonymous logging is disabled by default in Microsoft Edge. Submit, Report Crash, and Request Feature send only the report you choose to send.
No passwords, credentials, or personal data is ever included
You can disable feedback at any time in Settings
Feedback is automatically deleted one year after receipt
Optional Breach Checks
Password Health and Email Breach Monitoring are optional checks you start from Settings. They never send your vault or full passwords to us. Password leak checks use k-anonymity with Have I Been Pwned (only a 5-character hash prefix leaves the device).
Your Rights
Access: You have full access to your data in the Microsoft Edge popup
Portability: Export an encrypted backup anytime
Deletion: Delete entries or reset the extension in Settings
Control: We cannot access your vault
GDPR & EU/EEA Users
If you are in the European Union or European Economic Area, the following applies:
Legal basis: We do not process personal data on servers. All vault data remains on your Microsoft Edge profile. Optional features (feedback, crash reports) are based on your consent, which you can withdraw anytime in Settings.
Data retention: Your data is stored only on your device. Permanent delete overwrites the item and rotates the vault key.
Right to lodge a complaint: You may lodge a complaint with your local data protection supervisory authority.
International transfers: Optional sync uses end-to-end encryption through a relay that cannot read your data.
Children's Privacy
Loginator for Microsoft Edge is not directed at children under 13. We do not knowingly collect any information from anyone, including children.
Changes to This Policy
If we make changes, we will update the Last updated date. Continued use of the Microsoft Edge extension after changes constitutes acceptance of the updated policy.