Privacy policy for DyneBridge
DyneBridge by DyneCorelab
DyneBridge Privacy Policy
Last updated: September 6, 2026
DyneBridge is a browser extension that works together with the DyneBridge Android app to fill your saved login credentials — a username or email, and a password — into your browser, over your own local Wi-Fi network. Here's what it actually does with your data, in plain terms.
The only thing DyneBridge's extension ever touches is the login credentials you choose to send from your phone to a website you're actively logging into. That's it — no browsing history, no analytics, no device info, no contacts, no financial data. If Firefox shows you an "authenticationInfo" permission during install, that's exactly what this refers to: your username and password, nothing more.
Your credentials are encrypted on your phone before they ever leave it, using AES-256-GCM, with the key derived through an ECDH (P-256) exchange that's set up by scanning a QR code — a channel only your phone's camera and your browser can see. The extension is the only thing able to decrypt them; nothing in between ever sees the plaintext or the key.
Everything happens on your own Wi-Fi network, between your phone and your computer. Nothing is ever sent to us, to any server we run, or to anyone else over the internet. A small relay program runs locally on your computer just to pass encrypted messages back and forth, because browser extensions can't open network connections on their own — but that relay only ever handles encrypted ciphertext, never the actual credentials. Each message also carries a sequence number and timestamp so nothing can be replayed or tampered with, and your phone's identity is verified during setup so another device on the same network can't slip in credentials of its own.
We don't run analytics, crash reporting, ads, or any kind of tracking. The extension doesn't phone home, doesn't check in with any server on its own, and doesn't send usage data anywhere.
We don't keep your credentials anywhere either — there's no server, no database, no backup. The extension holds the most recent credentials briefly in your browser's session storage, just so you're not stuck rescanning the QR code if you reopen the popup a moment later. That cache clears itself after a few minutes, or the moment your browser session ends, and it never leaves your device.
You're always the one who starts the process — by opening the extension and scanning a QR code with your phone. Nothing happens on its own or in the background. Removing the extension wipes any locally cached data along with it.
Why the extension asks for the permissions it does:
Active tab access lets it know which site you're on and fill the login form there. It loads a content script on every page you visit — not because it does anything on most of them, but because it can't know ahead of time which site you'll want to log into. On every page other than the one you're actively filling, that script just sits there, doing nothing, reading nothing, sending nothing — until your phone tells it to, which only happens right after you scan a QR code. Local network access lets it talk to the small relay program on your own computer. And storage is used only for that short-lived credential cache described above. None of these permissions are ever used to collect or send data anywhere beyond your own devices.
Your rights under GDPR, CCPA, and similar laws: these laws are built around the idea that a company holds a copy of your data somewhere and you have rights over that copy — access, correction, deletion, portability, opting out of sale. DyneBridge doesn't hold a copy anywhere. Your credentials live only on your phone and, briefly, in your browser's own session storage — both of which you already fully control. There's nothing on our end to access, correct, delete, or opt out of, because nothing is stored on our end in the first place. If you ever think that's not actually the case, or have any other question, reach out using the contact info below.
DyneBridge isn't directed at children and doesn't knowingly collect anything from them.
If this policy ever changes, the update will be posted here with a new date.
Questions? Reach us at support@dynepass.com.
The full, most up-to-date version of this policy is always available at:
https://dynepass.com/dynebridge-privacy-policy.html