Privacy Policy
Effective date: September 3, 2026
Hexgate is built to be private by design. Your passwords are encrypted on your device and never leave it. This policy explains exactly what Hexgate does — and, just as importantly, what it does not do.
The short version
- Your passwords are encrypted on your device and stored locally. They are never sent to any server.
- Hexgate has no accounts and no cloud sync. Your vault lives only on the device where you use the extension.
- We do not sell, rent, or share your personal data. We do not run ads and we do not track you.
- The only data that ever leaves your device is the optional paid-subscription interaction handled by our payment processor.
What Hexgate collects
Hexgate is a local, on-device password manager. It collects the minimum necessary to function:
- Credentials you save — usernames, emails, and passwords you choose to store. These are encrypted before they ever touch disk and can only be decrypted through your biometric authentication.
- Site information — the domain of each saved login, so Hexgate can know where to offer autofill. Site names and usernames are stored locally only.
- Settings — preferences such as theme, password-generation defaults, and your organizational "bins". Stored locally.
How your data is protected
Hexgate uses the WebAuthn PRF open web standard to derive unique encryption keys from your biometric authentication (Face ID, Touch ID, fingerprint, or a security key). Each password is encrypted under a key that can only be produced through a successful biometric challenge. Because the keys are bound to your device’s secure hardware element:
- Passwords are encrypted before they ever reach storage, including disk and backups.
- The encryption keys never leave your device.
- Data stored by Hexgate is zero-knowledge — meaningless to anyone without your biometrics.
What Hexgate does not collect
- No decrypted passwords ever leave your device.
- No account, profile, or identity information.
- No usage analytics or behavioural tracking.
- No advertising identifiers.
- We do not read, transmit, or log the content of pages you visit beyond the domain needed for autofill, and we never transmit that domain anywhere.
Extension permissions and why we use them
- Storage — keeps your encrypted vault, settings, and last-known subscription tier locally on your device.
- Active tab / Tabs — reads the active tab’s URL so Hexgate can look up and autofill the matching saved credentials, and to open the manager from the toolbar.
- All sites (host permission) — injects the autofill overlay into login forms only when you visit them, so Hexgate can offer to fill credentials where you type a password.
- Remote code — Hexgate runs entirely as static files and never loads or executes code from the internet.
Payments and subscriptions
Hexgate is free for basic use. An optional paid upgrade ("Ultimate") is processed by our payment provider, ExtensionPay, which uses Stripe to handle payments. When you upgrade or manage a subscription, you interact directly with those providers to complete payment and to authenticate your purchase. We receive only the subscription status needed to enable your upgraded features (for example, that you have an active subscription). We do not see or store your payment card details.
Data retention and control
All of your data is stored on your device. You are always in control:
- Delete any individual password, bin, or your entire vault at any time from the manager.
- Export a backup of your data (usernames, emails, and site info — passwords remain encrypted) whenever you like.
- Uninstalling the extension removes your vault from that browser.
Because we do not operate servers or store your data, there is no data for us to delete on our side — complete deletion is simply clearing your local vault.
Data sharing
We do not sell, rent, or share your personal information with any third party. The only entity that receives data from your device is our payment processor, and only for the purpose of processing an optional subscription you initiate. We never share your passwords, vault contents, or browsing activity with anyone.
Children’s privacy
Hexgate is not directed to children under 13, and we do not knowingly collect personal information from children. Because we collect no data on our servers, there is no child data in our possession to collect.
Changes to this policy
We may update this policy from time to time. Any changes will be reflected by updating the "Effective date" at the top of this page. We will not reduce your rights under this policy without notice.
Contact
If you have questions about this policy or about Hexgate’s privacy practices, you can reach us at the contact email provided on the Chrome Web Store listing for Hexgate.