This Privacy Policy explains how the P2P Vauld browser extension handles user data. P2P Vauld is maintained by Peter Schael. Privacy questions can be sent to privacy@vauld.de.
1. Extension purpose
P2P Vauld signs in to P2P lending platforms selected by the user, reads portfolio values, free cash, and return metrics, and presents this information in a local portfolio dashboard. The extension does not trade, invest, or initiate withdrawals.
2. Data handled by the extension
The extension handles the following data only to provide its stated purpose:
- authentication information: usernames, email addresses, passwords, and temporary manual-action data required for login, 2FA, or Captcha flows.
- financial data: portfolio values, free cash, net annual return, historical snapshots, and sync results read from connected P2P platforms.
- Website content: the minimum page content needed to detect login state, navigate to a dashboard, and extract portfolio metrics.
- Settings and operational data: enabled platforms, encryption settings, learned selectors, sync status, errors, and local preferences.
- Debug data: when Debug Mode is enabled, local diagnostic snapshots may contain captured login-page or dashboard-page HTML and extraction diagnostics.
3. How data is used
Data is used only to authenticate with platforms chosen by the user, retrieve and display portfolio information, maintain local history, support exports and backups initiated by the user, and diagnose connector failures. P2P Vauld does not use analytics or tracking and does not use data for advertising, profiling, creditworthiness decisions, or sale.
4. Local storage and security
- Usernames and passwords are encrypted before storage with AES-256-GCM through the browser's native Web Crypto API.
- A temporary username prefill is also encrypted before it is written to browser session storage.
- Financial metrics, history, settings, and debug data are stored locally in the browser and are not currently encrypted at rest.
- A master password is never stored. Depending on the security mode selected by the user, encryption-key material is protected by a master password or stored in the local browser profile for automatic unlocking.
5. Network communication and sharing
The extension has no developer-operated backend and does not send user data to P2P Vauld, analytics providers, advertising services, data brokers, or cloud AI services. During a user-initiated sync, it communicates directly with the selected P2P platforms over their HTTPS websites, as required to authenticate and retrieve the requested portfolio information. Those platforms process data under their own privacy policies.
P2P Vauld does not otherwise share or sell user data. Data is disclosed only when the user deliberately exports a CSV or JSON backup and chooses where to store or share that file.
6. On-device AI
Optional AI-assisted extraction uses Gemini Nano through Chrome's built-in Prompt API. Processing takes place on the user's device. Page content and financial information are not sent to an external AI API. When Gemini Nano is unavailable, the extension continues with its local heuristic extractor.
7. Retention and deletion
Stored data remains in the user's browser profile until the user removes it, a configured history-retention rule deletes it, or the extension is uninstalled. Credential controls remove saved platform credentials. History, debug information, exports, and backups remain under the user's control. Temporary session data is cleared when it is no longer needed or when the browser session ends.
8. User access and control
Users can inspect the open-source implementation, view portfolio data in the dashboard, export supported data, delete platform credentials, and remove all extension data through the browser. Because the maintainer does not receive or control locally stored user data, requests to access or delete that data must be completed on the user's device.
9. Chrome Web Store Limited Use
P2P Vauld's use of information obtained through Chrome extension APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide or improve the extension's single user-facing purpose and is not transferred for unrelated purposes.
10. Changes to this policy
This policy will be updated when the extension's data practices change. Any material change will also be disclosed through the extension's public project information and applicable Chrome Web Store disclosures before the changed practice begins.
11. Contact
Peter Schael
Email: privacy@vauld.de