Last updated: September 25, 2026
VaultMesh is a local-first password manager with desktop, Android, and browser extension clients. This policy explains how those clients handle information. VaultMesh does not require a VaultMesh account or operate a cloud vault service.
VaultMesh handles information you choose to put in your vault, such as login credentials, passkeys, payment cards, identities, SSH credentials, notes, and other secrets. The vault is stored in encrypted form on your device. The application also stores local settings needed to operate, such as lock preferences and authorized device information.
The browser extension may process the address of a page, form structure, and information you choose to save or fill. It communicates with the VaultMesh desktop application through the browser's Native Messaging feature. The extension does not store the vault file or Vault Key in browser storage. It stores limited non-secret preferences and remembered item identifiers locally; sensitive responses and fill values are used temporarily for the requested action.
VaultMesh does not send your vault contents to a VaultMesh account or central vault server. Information can leave a device when you enable or use a feature that requires it:
VaultMesh does not sell vault information or use it for advertising or behavioral tracking.
Vault data remains on your device until you delete it or remove the application data. Deleting an item may first place it in a recoverable trash or history area; use the application's permanent-delete controls when you want to remove those local copies. Backups and copies you create, operating-system backups, and information already submitted to another service must be managed separately.
Temporary data used for filling, verification codes, clipboard operations, and authorization is cleared according to the feature's lock, expiry, cancellation, or session rules. The browser extension does not persist decrypted vault responses as browser settings.
You can lock your vault, revoke a browser or device authorization, disable optional integrations, and delete local vault data. You can choose whether to configure email access or pair another device. Uninstalling a client removes its application-managed local data according to the operating system's uninstall behavior; separately created backups and external-service data may remain.
VaultMesh encrypts the vault on the device and limits access to sensitive values through authorized operations. No software can guarantee absolute security. Keep your device, browser, operating system, and backups protected.