Privacy Policy for Royal Passkey
Royal Passkey is designed to manage WebAuthn passkeys locally in the user's browser. This policy explains what data is processed, how it is used, and what controls users have.
1) Data We Process
The extension may process the following data categories only to provide core functionality:
- authentication-related data (passkey credential data and encrypted vault data);
- identifiers provided by relying parties (such as username, display name, or user ID);
- website context required for WebAuthn operation (for example, RP ID/domain).
2) How Data Is Used
Data is used only to:
- create, store, and manage passkeys in a local encrypted vault;
- complete user-initiated authentication flows;
- provide user-requested extension settings and security controls.
3) Storage and Security
- passkey vault data is stored locally in the browser;
- vault data is protected with encryption mechanisms implemented in the extension;
- data is not sold and is not used for advertising purposes.
4) Data Sharing and Transfers
Core passkey functionality is local by default. If the user explicitly enables Telegram notifications, limited event
data may be sent to Telegram API (https://api.telegram.org/*) to deliver those notifications.
No data is shared for advertising, profiling, or credit-related decisions.
5) Remote Code
The extension does not execute remote code. Executable logic is packaged in the extension distributed via the Chrome Web Store.
6) User Controls
Users can:
- lock/unlock the vault;
- import, export, and delete passkey data;
- reset extension data;
- enable or disable optional Telegram notifications.
7) Policy Updates
This policy may be updated to reflect product or legal changes. The current version is published on this page with an updated effective date.
8) Contact
For privacy questions, contact: accs.royal@gmail.com
Back to Royal Passkey