Briarlock
Terms Privacy Contact

Privacy Policy

Effective September 18, 2026

This policy describes how Kenca Group LLC handles information in Briarlock app. Use of information we handle for Briarlock follows the Chrome Web Store User Data Policy, including the Limited Use requirements.

Briarlock has one product purpose: keep logins, notes, secrets, cards, identities, and Wi-Fi networks in an encrypted vault on the same account. An optional workdays calculator is also available. We only collect, use, or transmit user data that is needed for those features, to run the account, or to keep the service working and secure. We do not sell user data. We do not use it for advertising, including personalized, retargeted, or interest-based ads. We do not use it to determine credit-worthiness or for lending. We do not let people read your vault; we cannot decrypt it. Support staff may read a contact message you send us, because you chose to send it.

1. What we collect

1.1 Account

Email address and a one-way password hash (Argon2id where the server supports it). We do not store your password in a form we can recover. If you continue with Google or Apple, those providers confirm the email; we keep a provider name and a provider subject id so we can recognize that sign-in later. If you continue with phone, we keep the number in E.164 form and send a one-time SMS code. Google, Apple, and phone confirm who you are. The vault password is still required; we store only a hash of it. If you add a passkey, we keep a credential id, a public key, a sign-in counter, and a label you choose. We cannot use that public key to decrypt the vault. If you turn on email sign-in codes, we keep that setting and, when you sign in or change the setting, a hashed one-time code, a hashed challenge token, an expiry, and a short attempt count until the code is used or lapses. We email a new code for each attempt, together with the email, time, location, device, browser, IP address, and a short request id we saw, so you can tell if the attempt was yours. Creating an account with email works the same way: we keep the requested email, a hashed password, a hashed confirmation code, and the request IP until you confirm or the request lapses, then we create the account. If you ask to reset a forgotten password, we email a one-time reset code and keep a hashed copy of that code, a hashed challenge token, an expiry, and a short attempt count until it is used or lapses. If you ask to change the sign-in email, we keep the requested address, a hashed confirmation token, and an expiry until you confirm, cancel, or the request lapses. We then send mail to the new address and a notice to the current one. We also email this address after the password changes, after a sign-in from a new device or network, after email codes or a passkey change, after a sign-in email change completes, and after the account is deleted.

1.2 Vault blob

An encrypted copy of your vault (ciphertext, salt, and related fields). We cannot decrypt it. The vault password stays on your device; we never receive it in a form we can use to open that blob on the server. Logins, secure notes, secrets, payment cards, identities, and Wi-Fi stay inside that blob until you choose to share a note or secret, or put an item in an access group.

1.3 Access groups

If you create a group, we keep the group name, who owns it, member emails (as account ids), each member’s role, and opaque wrapped keys plus item ciphertexts your device sends. An item can be published to more than one group; each group stores its own ciphertext. Deleting a group drops that group’s copies only; the item stays in your vault and in any other groups. Deleting an item removes those group copies. We also keep a public key for group sharing after you unlock the vault (an elliptic-curve public key, not the vault password). If you invite an email that does not yet have a Briarlock account, we keep that pending invite until they join or you revoke it. We cannot unwrap group keys or read shared items. Removing a member drops their wrapped key and the owner’s device rotates the group key. Anyone who is not a member is refused with Access denied. We email invited people and people you revoke so they know their access changed, together with the email, time, location, device, browser, and IP address of that request.

1.4 Scheduled shares

If you email a note or secret, your device encrypts that one item and sends us the ciphertext, an unlock schedule, each recipient email, and an optional message to the recipients. We mail each recipient their own link, together with the email, time, location, device, browser, and IP address of the request, so they can tell if the share was yours. We keep the unwrap key only until that mail is sent, then drop it. We cannot read the shared item. You can cancel a share before its scheduled unlock. After unlock, the recipient opens the link; we record that it was viewed. Shares expire 30 days after the unlock time. Deleting your account removes pending shares.

1.5 Emergency access

If you name a trusted contact, your device encrypts a vault snapshot and we keep that ciphertext, the contact email, and a wait period you choose (3, 7, 14, or 30 days). We email the contact that they were named. The unwrap key stays with us until they request access and the wait ends, or you cancel. A request emails you so you can cancel before the wait ends. We cannot read the snapshot.

1.6 Settings

Rate and vault preferences saved to the account, such as currency, theme, and auto-lock.

1.7 Sessions

A session token (cookie wr_session on the website, and/or a bearer token in the extension), when it was issued, when it expires, a truncated browser user agent, and whether the session was revoked.

1.8 Sign-in protection

Recent email, IP address, and time of failed or repeated sign-in attempts, so we can slow brute-force guesses.

1.9 Contact

If you use the contact form: name, email, optional phone, subject, and message. We email that to our support inbox and send you a short receipt at the address you entered. We keep a support log with name, email, phone, subject, and a short preview of the message. We keep the sender IP briefly to slow repeat submits.

1.10 On your devices

The extension keeps a local encrypted vault and settings in Chrome storage (storage.local and storage.sync). While the vault is unlocked, an unlock key may sit in memory-only storage.session. Locking the vault or closing the browser clears that key. Auto-lock hides the vault view after idle time; fill on other sites can keep working until you lock the vault or close the browser.

1.11 Website fill

When fill-and-save is on, the extension reads login fields and related form fields on pages you visit so it can show a vault icon, fill a saved username, password, or one-time code after you choose to fill, or offer to save a login you just submitted. The first data notice lets you Continue with fill allowed, or Decline and turn fill off; the vault still works. You can turn fill on later in Settings. Page contents are not uploaded to us as part of fill, except the encrypted vault if you save a login and sync is on. Fill is off for the Briarlock website. If the vault view is locked, you can still fill or save on a page by entering the vault password there; that password is not stored.

1.12 Server logs

The host that runs this website may keep ordinary web-server logs (such as IP address, time, and the URL requested) for a short time to operate and secure the site. We do not run advertising trackers or third-party analytics on the product.

2. What we do not collect

We do not sell your information. We do not collect payment card numbers on the server. If you save a card in the vault, it stays inside the encrypted blob on your device. The product is not directed at children under 13, and we do not knowingly collect their data.

3. How we use information

  1. 3.1Create and authenticate your account, including Google or Apple sign-in, a phone SMS code, a passkey, emailing a confirmation code to finish creating an email account, a one-time sign-in code when that setting is on, and a password-reset code if you forgot the password
  2. 3.2Let you share vault items through a group you control, including adding and revoking members and emailing those people when access changes
  3. 3.3Lock other sessions after a password change
  4. 3.4Send a confirmation to a new email and a notice to the current one when you ask to change it
  5. 3.5Show the hourly rate in another currency by fetching public exchange rates. That request does not include your amount or account, and you do not need to be signed in for it
  6. 3.6Answer support and privacy requests, and delete the account when you ask
  7. 3.7Keep the service running and investigate abuse or a fault you report
  8. 3.8Email security notices when the password changes, a new device signs in, email codes or a passkey change, a sign-in email change completes, or the account is deleted

4. Chrome extension permissions

4.1 Website fill

The extension asks for access to websites so fill-and-save can run on the page you are viewing, as described above, including from a keyboard shortcut (Ctrl+Shift+L by default, and Ctrl+Shift+Y to open the extension) or the page’s right-click menu.

4.2 Session cookie

The extension may read a cookie named wr_session so it can tell that you are already signed in on the Briarlock website and keep the vault in sync. It does not use that permission to read other sites’ login cookies for fill.

4.3 Site icons

When the vault is unlocked, the extension may load a site icon from Google or DuckDuckGo using the hostname of a saved login so the list can show that site’s icon. Those services receive the hostname, not your password.

5. Cookies and local storage

Briarlock uses a cookie consent banner in line with the GDPR and the ePrivacy Directive (and equivalent UK rules). When you first visit this website, we ask you to Accept, Reject non-essential cookies, or open Cookie settings. Essential cookies needed to keep you signed in still work either way. We do not treat optional categories as accepted until you choose Accept. Your choice is stored in the wr_consent cookie.

5.1 Cookies we use

Cookie / storagePurposeDurationType
wr_sessionKeeps you signed in on the website. HttpOnly, Secure on HTTPS, SameSite=Lax.Browser sessionEssential
wr_consentRecords whether you accepted or rejected non-essential categories via the banner, so it is not shown again unnecessarily. Set only after you click Accept or Reject.365 daysConsent preference
Chrome storageThe extension uses storage.local, storage.sync, and storage.session for the vault blob, settings, and an unlock key while the vault is open. Not used for advertising.Until you clear extension data or lock/close the browser (session key)Essential for the extension

5.2 What we do not use

On this website we do not use advertising cookies, tracking pixels, third-party analytics cookies, browser fingerprinting, or cross-site tracking for ads. No data is shared with ad networks for that purpose.

5.3 Managing your consent

Review cookie categories with on this page, or from the banner when it is shown. After you remove wr_consent (or clear cookies for this site in your browser), the consent banner appears again on your next visit.

6. Sharing

We do not sell personal information. Parties that may receive information, only as needed to run Briarlock:

  1. 6.1The processor that hosts this website
  2. 6.2Frankfurter and Open Exchange Rates (api.frankfurter.app, open.er-api.com), which receive a request for public USD exchange rates, not your account
  3. 6.3Google or Apple, if you choose Continue with Google or Continue with Apple. They receive that you are signing in to Briarlock and return the verified email and a subject id
  4. 6.4The SMS path you configure for Continue with phone (Twilio, TextBee, or SMS Gate), which receives the number and the one-time code. TextBee and SMS Gate send through an Android phone you connect, using that phone’s carrier plan
  5. 6.5Google or DuckDuckGo, which may receive a hostname when the extension loads a site icon
  6. 6.6Have I Been Pwned (api.pwnedpasswords.com), if Flag breached passwords is on. Your device sends the first five characters of a SHA-1 hash of a saved login password, not the password, so it can see whether that hash appears in known breaches
  7. 6.7The mail path on this server, when we send an email-change notice, a sign-in or settings code, a password-change or new-sign-in notice, a passkey or account-deleted notice, a contact-form message to our support inbox and a receipt to you, a share link you asked us to send to a recipient you named, an emergency-access notice, or a group invite or revoke notice

6.8 Legal requests and transfers

We also share information if the law requires it, or if we must protect the service or a person from serious harm. If we transfer the service in a merger, acquisition, or sale of assets, we will not move your account data with it unless you give prior consent, except where the law requires otherwise.

7. Retention

Account, encrypted vault, and settings stay until you delete the account or we close it. Session records last until they expire, you sign out, or the account is deleted. Sign-in attempt logs for that email are removed when the account is deleted, and otherwise only kept long enough to rate-limit abuse. Local copies remain on a device until you remove the extension or reset the vault there. Contact-form support records and brief rate-limit data stay as described in section 1. Scheduled-share records stay until you cancel them, they expire, you delete the account, or we close it.

8. Security

Vault items are encrypted in the browser with AES-GCM before they leave the device. Transport to the website uses HTTPS in production. No method is perfect. You still need a strong unique password and a device you trust.

9. Your choices

9.1 Account controls

You can sign out, change your password, change your sign-in email after confirming the new address, lock the vault, turn off website fill, and delete the local vault on a device. To delete the server account and its encrypted blob, use Delete account in Settings (or the account menu on the website) and enter your password. That cannot be undone. Copies on a device stay until you delete the local vault or remove the extension. If you cannot sign in, email info@briarlock.com or use the contact form from an address we can match to the account. We will delete what we hold for that account unless the law requires a limited record of the request.

9.2 Privacy rights

Depending on where you live, you may have rights to access, correct, or delete personal information, or to object to certain processing. Send those requests the same way: email or the contact form.

10. International

If you use the service from outside the country where the servers are hosted, your information is processed in that hosting location.

11. Changes

We may update this policy. The date at the top will change. If we change how we collect, use, or share user data, the website and the Chrome extension will show that change in the product before the new practice applies. Using the service after you see that notice, or after a non-material update posted on this page, means the current policy applies to later use.

12. Contact

Kenca Group LLC is the controller for Briarlock. For privacy questions or requests, email info@briarlock.com or use the contact form on this website.

© 2026 Briarlock — Kenca Group LLC. All rights reserved.

·

Privacy Policy · Terms of Service