← CoauthLegal

Privacy Policy

Coauth Chrome Extension · Last updated: August 6, 2026

What Coauth does

Coauth is a Chrome extension that lets you create, store, and share passkeys with a team so a shared account can sit behind phishing-resistant passkey MFA that every teammate can use. We collect the minimum needed to run that service. We do not sell your data, show ads, or track you across the web.

What Coauth stores

• Your passkeys (credentials). Passkeys you create through Coauth are stored in your vault as encrypted data. The private key material is encrypted before it is saved or synced. • Identity. When you sign in with Google, we receive your email address and a user ID (via our authentication provider, Supabase) to create your account and sync your vault. We never receive your Google password. • Team data. Team names, membership, roles, invite codes/emails, and an activity log of team actions (created, joined, shared, used, removed) — needed to make sharing work. • The site (domain) of a passkey, so the right passkey can be offered on the right site.

What Coauth does not do

• We do not collect your browsing history. • We do not read or transmit the content of the pages you visit. Coauth's content script only renders its passkey overlay during a WebAuthn request the browser routes to it. • We do not sell or rent your data to anyone. • We do not use your data for advertising, profiling, creditworthiness, or lending.

Encryption

Your vault is encrypted using audited cryptography (libsodium). Data is encrypted before it is stored locally and before it syncs to your account. Team-shared passkeys are encrypted with a team key shared only with members of that team. Note (accurate as of this version): the key that unlocks your vault is currently held by our backend so that signing in with Google is enough to open it. This means a breach of the backend could expose vault contents. We are moving to a zero-knowledge design where only you hold the unlock key; this page will be updated when that ships.

Where data is stored

Encrypted vault data, team data, and account records are stored with Supabase (Postgres), region ap-south-1. Authentication is handled by Supabase Auth with Google as the identity provider.

Permissions used

• webAuthenticationProxy — to act as a passkey authenticator so passkeys can be created, used, and shared. • identity — Google sign-in to create your account and sync your vault. • storage — to store your encrypted vault and settings. • tabs / activeTab — to show which of your passkeys match the site you are currently on. • Host access to our backend — to sync your encrypted data. • Content script — to show the passkey save / sign-in overlay on the page.

Data sharing

We do not sell, rent, or share your data with third parties. Team-shared passkeys are shared only with the members of the teams you add them to, encrypted.

Your choices and data deletion

• Sign out to lock the vault and stop Coauth from handling passkeys. • Remove a personal passkey, or unshare a team passkey, at any time from the popup. • Delete your account and data: email us and we will delete your account records and vault data.

Data retention

We keep your account and vault data until you delete your account. Team data is removed when the team is deleted. Audit-log entries are retained for the life of the team.

Children

Coauth is not directed to children under 13 and we do not knowingly collect their data.

Changes to this policy

If we make material changes we will update the "Last updated" date at the top of this page. Material changes will be noted in the extension.

Contact

Questions or data-deletion requests? Email kalpesh@buildifyapp.in. We respond to every real message.