Skip to content
Chrome MVP
SnippetVault

Legal

Privacy Policy

SnippetVault is local-first. This policy explains what stays in your browser, what can leave it, and the controls available to you.

Last updated: August 2, 2026

This policy covers the official SnippetVault browser extension and the SnippetVault pages hosted on biqn.dev. The extension and website have different data flows, which are described separately below. SnippetVault is maintained by Bi Quanneng under the BIQN brand.

In short

  • Your snippets, labels, contexts, searches, source details, clipboard contents, and backups are not sent to SnippetVault or biqn.dev.
  • Extension records and the search index are stored as readable data in the extension's local browser storage. They are not encrypted.
  • Optional extension analytics is off by default and counts only two entry actions after you enable it.
  • The public website uses separate traffic and experience analytics as described under Website analytics.

Data handled by the extension

SnippetVault handles only the information needed to save, organize, search, copy, edit, expire, and restore your records. Depending on how you use it, this may include:

  • text or Markdown you explicitly select or enter;
  • optional labels and a context selected by you;
  • for saved webpage selections, the page title, full URL, and domain;
  • record identifiers, creation and update times, pin and last-use state, and temporary-item expiry times; and
  • local preferences such as language, theme, default expiry period, and your analytics choice.

Snippet records, labels, contexts, metadata, and the derived search index stay in the extension origin's IndexedDB. Preferences stay in Chrome extension storage. SnippetVault has no account system and no hosted snippet database or cloud sync.

Page access and browser permissions

SnippetVault runs a content script on supported webpages so it can show the selection tooltip and respond to the double-Shift search gesture. It reads only the page selection that you explicitly make and saves it only after you choose to save. It does not scan unselected page content, form fields, network traffic, browser history, or the clipboard in the background.

The storage permission keeps local preferences. The side-panel feature provides the persistent search, temporary workspace, item management, and settings interface. Optional access to Google Analytics is requested only if you enable anonymous usage analytics.

Optional extension analytics

Anonymous usage analytics is disabled by default. If you enable it in Settings > General, the extension sends only these events to Google Analytics 4:

  • open_side_panel, when the side panel opens; and
  • open_in_page_search, when double-Shift successfully opens in-page search.

These requests include a random installation identifier and technical session values needed to count events. SnippetVault does not send saved content, labels, contexts, searches, page titles, URLs, domains, clipboard data, backups, record IDs, errors, or stack traces. Requests omit credentials and referrer information. Google may still observe ordinary connection metadata such as your IP address and browser user agent and processes analytics data under its own Privacy Policy.

You can disable analytics at any time in Settings > General. This removes the optional Google Analytics host permission and prevents future events. It does not remove aggregate events already received by Google.

Backups

You can manually export a versioned JSON backup with the .sv extension. Backups can contain snippet contents, labels, contexts, secrets, full URLs, and source metadata in readable form. They are not encrypted and are never uploaded by SnippetVault. Keep exported files private.

Import previews a selected backup and, after confirmation, fully replaces local business data. It does not merge records. Search indexes and interface preferences are excluded from backups, and expired temporary items are not restored.

Retention and deletion

Vault records remain until you delete them or replace local data through an import. Temporary records remain until their expiry time, unless you delete, extend, or promote them first. Expired records are removed from normal storage and search, but SnippetVault does not promise forensic deletion from browser files or storage media.

You can delete records from the extension. Removing the extension and clearing its browser storage removes the live extension data available to SnippetVault. Exported .sv files are separate files under your control and must be deleted separately.

Website analytics

The public SnippetVault website does not receive your extension records and has no account or data-entry form. It uses the following services to understand site traffic and improve the website:

  • Google Analytics 4 measures page visits and general website usage. Google may use cookies or similar browser storage and processes data under its Privacy Policy.
  • Ahrefs Web Analytics measures page visits using its cookie-free analytics service. See the Ahrefs Privacy Policy.
  • Microsoft Clarity may be enabled to understand page interactions and improve usability. When enabled, it may collect interaction, device, session, and diagnostic data and may use cookies or similar storage subject to consent requirements. See the Microsoft Privacy Statement.

The website is delivered through Cloudflare, which necessarily receives request and connection information to serve and protect the site. See the Cloudflare Privacy Policy. You can restrict website cookies and scripts using your browser controls. Provider retention and deletion are governed by their respective policies and account settings.

Sharing, sale, and advertising

SnippetVault does not sell extension user data, use it for personalized advertising, or allow people working on SnippetVault to read your local records. Extension analytics is shared only with Google after your opt-in and only within the narrow event boundary above. Website traffic data is processed by the listed website providers.

SnippetVault's use of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data handled through browser permissions is used only to provide or improve the extension's disclosed, user-facing purpose.

Security

Local storage and exported backups are readable, not encrypted. Anyone with access to your browser profile, local files, extension DevTools, or device malware may be able to read them. SnippetVault is not a password manager or production secret manager. Use an access-controlled secret manager for production credentials.

Changes and contact

This policy will be updated when the product's data practices change. The date at the top identifies the latest revision. For privacy questions, email support@wossoft.cn. You may also open a non-sensitive issue in the SnippetVault repository. For a vulnerability or a report containing sensitive information, use the repository's private security channel and do not post the details publicly.