Privacy Policy for HolyPass
Last updated September 23, 2026
HolyPass ("the extension") is a browser password manager built by Anurag. This policy explains how HolyPass handles your data.
What HolyPass stores
When you save a site, HolyPass stores, only on your own device:
- the site URL
- the username you enter
- the password you enter (encrypted)
- structural hints about the site's login form (e.g. field type/autocomplete attributes) used to re-detect the fields later — never the field's actual values
Where it's stored
All data is stored locally using Chrome's storage.local API, encrypted with a key that is generated automatically the first time HolyPass runs and is itself kept in chrome.storage.local, on your device only. HolyPass does not use chrome.storage.sync and does not sync your data across devices.
What HolyPass does not do
- It does not send any data to a server. HolyPass has no backend.
- It does not use analytics, telemetry, or tracking of any kind.
- It does not sell, rent, or share your data with any third party.
- It does not use or transfer your data for advertising, credit, or lending purposes.
How HolyPass accesses web pages
- With your explicit click of "Use current site," HolyPass reads the active tab's URL and login form structure to help you save an entry.
- When you click "GO," HolyPass opens the site and fills in the username/password you previously saved (and submits the form, only if you've turned on "Enable one-click sign in" in Settings).
- HolyPass only acts on a site when you click one of these buttons — it does not run in the background or monitor your browsing.
Data deletion
Deleting a saved site from the HolyPass popup permanently deletes that entry's data from your device immediately. Uninstalling the extension removes all HolyPass data Chrome stores for it.
Changes to this policy
If this policy changes, the "Last updated" date above will change and the new version will be posted at this same URL.