Privacy Policy
Last updated: July 12, 2026
Securiqon (“we”, “us”) provides Secure Document Sharing, a Chrome extension that encrypts documents on your device and optionally uploads ciphertext bundles to your own Google Drive. This policy describes how the extension handles information.
Contact: support@securiqon.com
Summary
- Your passphrase never leaves your device and is not transmitted to us.
- File contents and vault metadata are encrypted locally before any optional cloud upload.
- We do not operate application servers that receive your files or keys.
- We do not sell your data, show ads, or use analytics trackers in the extension or on this website (v1).
- Google Drive is optional transport: only ciphertext bundles are stored on Drive, on your Google account, inside an app folder named Secure Document Share.
- Local exports (decrypted ZIP files to your computer) happen only when you choose Export; we do not receive those files.
Information we do not collect
We do not collect, store, or receive on our servers:
- Your vault passphrase or derived master keys
- Decrypted file contents, filenames, folder names, or comments
- Bundle encryption keys (delivered by you over separate channels)
- Browsing history unrelated to the extension’s operation
The extension has no backend operated by Securiqon for vault or bundle data.
Information stored locally on your device
The extension stores data in Chrome local storage and IndexedDB on your computer, including:
| Data | Purpose |
|---|---|
| Vault profiles and encrypted file/folder records | Local encrypted vault |
| Wrapped encryption keys | Unlock vault with your passphrase |
| Extension settings (theme, language, auto-lock) | Preferences |
| Activity log entries (encrypted) | Local audit trail |
| Bundle records and draft state | Bundle creation and tracking |
| Google OAuth tokens | Connect to your Google Drive for bundle publishing |
Google Drive app folder id (driveAppFolderId) | Remember the Secure Document Share folder on your Drive for new bundle uploads |
Known Google accounts (driveKnownAccounts) | Show a local account picker when reconnecting Drive (account id and, when available, email address) |
| Resumable upload checkpoints | Resume large Drive uploads after interruption |
| Bundle comment author labels | When you add comments on bundles, the extension may store your Chrome profile email locally as the author name (not sent to Securiqon) |
All sensitive content is encrypted at rest under keys derived from your passphrase. Uninstalling the extension or resetting the vault removes local data subject to browser behavior.
Chrome profile email and Google account labels (identity.email)
If you are signed into Chrome with a Google account, the extension may read your profile email only on your device to:
- Label you vs other authors on bundle comments in the vault UI
- Help you pick the correct Google account when connecting Drive (Connect Google Drive dialog)
When you connect Drive, the extension may also read your Google account email from Google’s OAuth userinfo endpoint and store it locally in driveKnownAccounts together with a Google account id, so the account picker can list accounts you have used before.
Where email appears in the UI:
- Connect Google Drive dialog: account buttons may show the email address (or a short account id if email is unavailable).
- Settings → Google Drive status: shows only connected / disconnected — not your email address.
We do not send profile or Google account emails to Securiqon servers and do not use them for advertising or analytics. If you are not signed into Chrome, Connect Google Drive asks you to sign in to Chrome first; comment authors may appear as a generic local label instead.
Google account and Google Drive
If you choose to connect Google Drive:
- The extension uses a developer OAuth application (Securiqon) configured in the extension manifest. You sign in with your Google account.
- The extension requests OAuth scope
https://www.googleapis.com/auth/drive.file— access only to files created or opened by the app. - OAuth tokens are stored locally in
chrome.storage.localon your device. - Encrypted bundle blobs are uploaded to your Google Drive, not Securiqon’s.
- On first upload (or if the folder was removed), the extension creates or reuses a Drive folder named Secure Document Share and stores its folder id locally. New bundles are placed in that folder. The folder and files remain on your Drive under your control; deleting the folder in Google Drive does not delete your local vault.
- If multiple Google accounts are signed into Chrome, the Connect Google Drive flow lets you choose which account to authorize; previously connected accounts may appear in a local picker (
driveKnownAccounts). - Before the first sign-in, the extension shows what Drive access is used for (in-product disclosure).
- You can disconnect Drive, clear sign-in cache, or reset the Google Drive connection from the extension at any time.
Recipients who open bundles via the receiver page need only a Drive link/ID and bundle key; they do not need to connect Drive in the vault.
Chrome permissions
| Permission | Why it is needed |
|---|---|
storage | Save vault, settings, and OAuth tokens locally |
identity | Google OAuth sign-in flow (drive.file scope) |
identity.email | Read Chrome profile email on-device for comment author labels and Drive account picker (not sent to us) |
sidePanel | Main vault user interface |
windows | Open the side panel from the toolbar popup |
downloads | Save decrypted exports and backups to your computer when you choose Export |
offscreen | Cryptographic operations in an isolated document |
alarms | Schedules low-frequency background tasks in the service worker when periodic local checks are required. |
Host access to googleapis.com, accounts.google.com, drive.google.com, drive.usercontent.google.com | Google Drive API and OAuth only |
We request the narrowest permissions needed for stated features.
Exporting decrypted files to your computer
When your vault is unlocked, you may export files, folders, or an entire profile as a plain ZIP archive (decrypted contents and folder names). Export uses Chrome’s downloads permission and saves the ZIP only to your computer — not to Securiqon.
You choose the save location (where supported by Chrome). Exported ZIP files are not encrypted by the extension; protect them like any sensitive document on disk. We do not upload export ZIPs to our servers.
This is separate from encrypted bundles published to Google Drive and from optional encrypted profile backup files (Pro), which remain encrypted.
How you share data with others
When you publish a bundle, you choose recipients and channels. Typical flow:
- Ciphertext is stored on Google Drive (or you export a bundle file manually).
- You send the Drive link and bundle key separately (e.g. email + chat).
We do not control or monitor those communications.
Data retention and deletion
- Lock vault: clears keys from memory; data remains encrypted on disk.
- Disconnect Google Drive: removes local OAuth tokens; files and the Secure Document Share folder already on Drive remain until you delete them in Google. Local
driveKnownAccountsanddriveAppFolderIdmay remain to speed up reconnecting. - Clear Google Drive connection / reset Drive settings: removes local OAuth tokens and Chrome sign-in cache; does not delete files on Google Drive.
- Uninstall extension: removes extension local storage per Chrome rules.
Children’s privacy
The extension is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect personal information from children.
International users
Data processing occurs on your device. If you use Google Drive, Google’s policies apply to data stored on their service.
Changes to this policy
We may update this policy. The “Last updated” date will change. Continued use after changes constitutes acceptance of the updated policy.
Disclaimer
This Privacy Policy describes how data is handled. It is not a warranty or security guarantee. Use of the extension is at your own risk and is governed by our Terms of Service, including “as is” disclaimers and limitation of liability.
Contact
Questions about privacy: support@securiqon.com
Google API Services — Limited Use Disclosure
Secure Document Sharing’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide or improve user-facing features of the extension (creating or locating the Secure Document Share app folder, uploading and downloading encrypted bundles on your Google Drive, and showing which Google account you connected).
- We do not transfer Google user data to third parties except as necessary to provide the feature (Google’s own services), to comply with law, or with your explicit consent.
- We do not use Google user data for advertising, sell it, or use it for credit eligibility.
- Humans do not read your Google user data except with your explicit consent, for security investigations, or as required by law.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.