Your vault stays with you.
Privacy policy for Maneuler Vault 0.3 · Updated September 21, 2026.
What the app stores
Passwords, usernames, cards, notes, pages and boards are saved in an encrypted KDBX file on your device. Your master passphrase unlocks this file locally. The app does not send it to Maneuler. Search and editing happen on your device; decrypted content exists in memory while the vault is unlocked.
Locking and memory
Idle locking defaults to five minutes; you can choose one, five or fifteen minutes. This preference stays in local device/browser storage. Hiding the page locks it; native desktop sleep and screen lock also lock the app. Locking removes decrypted views and clears owned mutable field and credential buffers. JavaScript strings, upstream library memory, browser processes and operating-system copies cannot be guaranteed erased. See the measured scope and remaining limits.
Android requests secure-window capture protection. iOS source covers inactive views and detected recording; it cannot universally prevent screenshots. These native source changes require rebuilt, tested installers; existing downloads retain their listed release behavior.
The optional local benchmark uses invented sample data. It does not open saved vaults, change their security settings, save results or report measurements to Maneuler.
The interactive sample vault contains invented public examples. It runs in memory, does not read or overwrite your stored vault, and is cleared when you close or lock the demo. Demo activity is not recorded or sent to us.
No Maneuler vault account
The app does not create a cloud account, upload your vault to a Maneuler database, include advertising or analytics SDKs, or send vault content to an AI service. Maneuler cannot reset a forgotten master passphrase.
Browser extension filling
When you choose Fill, the extension reads the active tab address to compare its exact HTTPS origin with the saved website. You review the ASCII address before each fill. Internationalized hostnames receive an additional warning. The address is not reported to Maneuler or saved as a browsing-history list. The selected username and password are released only after confirmation to the matching page; a compromised matching site can read values filled into it.
Transfers you choose
Export creates an encrypted file in a location you choose. If you save or share that file through another provider, that provider’s policies apply. Native Wi-Fi sync transfers encrypted vault copies between devices you pair. The main desktop approves devices and reviews incoming updates. Device labels, pairing credentials and sync revisions are stored locally. Pairing credentials use operating-system protected storage.
Sync requires a compatible private Wi-Fi subnet and a matching pinned TLS certificate. It does not establish a device’s physical proximity. It does not automatically merge conflicting edits.
Website and download requests
Opening vault.maneuler.com or downloading an installer makes ordinary HTTPS requests to Firebase Hosting, operated by Google. Network information such as your IP address and requested URL is necessarily processed to serve those requests. This is separate from vault content, which the app does not upload. See Google’s privacy policy.
Clipboard and local backups
Copying reveals the selected value to your device’s clipboard. Native apps request expiry or clear unchanged copied values after 30 seconds; the browser clipboard may retain them. Other software on your device may read clipboard content. Native sync and file replacement retain up to ten encrypted recovery copies.
Removing your data
Deleting an item moves it to the encrypted vault’s recycle bin. Older exports and recovery copies can still contain it. To remove every copy, remove the local app/browser data, native recovery files and any exported files on all devices and providers you chose. Uninstalling the Windows app intentionally preserves its data. Export a backup first if you want to keep your vault. There is no Maneuler cloud account to delete.
Limits and help
Support and security reports are messages you choose to send through your own email provider. They can contain your contact details and technical descriptions, which Maneuler uses to respond and investigate. Do not include real vault files, passphrases, passwords, payment card details or private keys. The app does not automatically collect or send a report. See our responsible-disclosure policy.
This preview has not had an independent security audit. Malware, a modified app or an unsafe browser extension may expose unlocked content. iOS is still in preparation; the public downloads page states each platform’s actual availability.
For setup and recovery help, visit Vault support. Contact ceo@maneuler.com for support and privacy questions. Never include passwords, recovery files or card details in a support request.
Previous policy: September 18, 2026. This revision adds voluntary security reporting and local lock-preference/memory handling; local vault storage and the absence of analytics or cloud accounts are unchanged.