Hollow — Your Private Space in the Browser by iobyss
An encrypted local vault for notes, logins, files and links. Everything stays on your device: no server, no accounts, no telemetry. AES-256-GCM with an Argon2id-derived key.
Extension Metadata
Screenshots
About this extension
Hollow keeps private things private — on your own machine.
Notes you would not leave in a text file. Card numbers, passport details, door codes, licence keys, a scan of a contract. Hollow keeps them encrypted inside your browser and asks for a password before showing anything.
No account. No sync. No server to breach. Nothing leaves your computer, because there is nowhere for it to go.
What you can keep
How it is protected
Invisible to the page
Hollow lives in its own tab, in extension storage. No website can read it — not through the page source, not through scripts, not through the DOM. Clearing history and cookies does not touch it.
It asks for nothing
No permissions beyond local storage. No network requests at all — you can verify that in the Network panel. No analytics, no crash reports, no unique identifier.
Before you start
Hollow cannot recover a forgotten password. That is the point: there is no operator with a spare key. Write down the recovery phrase and keep backups —
Honest limits
Encryption protects data at rest. It cannot protect a machine that is already compromised: malware with access to your profile, running while the vault is unlocked, sees what you see. Hollow makes theft of the file useless, not theft of the
Notes you would not leave in a text file. Card numbers, passport details, door codes, licence keys, a scan of a contract. Hollow keeps them encrypted inside your browser and asks for a password before showing anything.
No account. No sync. No server to breach. Nothing leaves your computer, because there is nowhere for it to go.
What you can keep
- Notes — anything you would rather not write down in the open.
- Logins — a name, a password, an address, a comment.
- Files — documents, scans, photos, archives. Up to 2 GB each.
- Links — addresses you would rather not leave in your bookmarks.
How it is protected
- AES-256-GCM for every entry, with its own key derived per record.
- Argon2id turns your password into a key. The work factor is tuned on your machine, so a stolen copy of the vault is expensive to attack offline.
- A 24-word recovery phrase is issued once, at setup. It is the only way back in if the password is forgotten.
- A decoy password opens a separate, empty space. Nothing on disk reveals whether one is set up.
- Auto-lock wipes the key from memory after idle time, and
Ctrl+Shift+Llocks immediately.
Invisible to the page
Hollow lives in its own tab, in extension storage. No website can read it — not through the page source, not through scripts, not through the DOM. Clearing history and cookies does not touch it.
It asks for nothing
No permissions beyond local storage. No network requests at all — you can verify that in the Network panel. No analytics, no crash reports, no unique identifier.
Before you start
Hollow cannot recover a forgotten password. That is the point: there is no operator with a spare key. Write down the recovery phrase and keep backups —
Settings → Backup writes an encrypted file you can restore from.Honest limits
Encryption protects data at rest. It cannot protect a machine that is already compromised: malware with access to your profile, running while the vault is unlocked, sees what you see. Hollow makes theft of the file useless, not theft of the
Rated 0 by 0 reviewers
Permissions and data
More information
- Add-on Links
- Version
- 1.1.1
- Size
- 394.54 KB
- Last updated
- 4 days ago (Sep 8, 2026)
- Related Categories
- License
- All Rights Reserved
- Privacy Policy
- Read the privacy policy for this add-on
- Version History
- Add to collection