Privacy policy for Hollow — Your Private Space in the Browser
Hollow — Your Private Space in the Browser by iobyss
Hollow — Privacy Policy
Last updated: 7 September 2026
Hollow collects nothing. No servers, no accounts, no analytics, no telemetry, no crash reports, no advertising, no unique identifiers. The developer receives no information about you, your device, or your use of the extension.
Nothing leaves your device. Hollow makes no network requests of any kind — no remote scripts, no external fonts, no external resources. This is enforced by the extension's Content Security Policy and can be verified by reading the source code or watching an empty Network panel.
Everything stays local. Notes, logins, files, links, titles, tags and settings are stored only on your own device, in this extension's IndexedDB storage. Entries are encrypted with AES-256-GCM before being written to disk, using a key derived from your master password with Argon2id. The master password is never stored anywhere, in any form.
The developer cannot read your data and cannot recover your password. This is a deliberate design decision, not an oversight.
Permissions. Two, and only two: storage (to keep the encrypted vault and settings) and unlimitedStorage (to lift the size limit so large files are not rejected). Hollow does not request access to websites, tabs, browsing history, bookmarks, downloads, the clipboard or your identity.
Your data leaves only when you export it. The "Export backup" and "Download" actions write a file to a location you choose. What happens to that file afterwards is up to you.
Deleting. Settings → Erase vault removes everything. Uninstalling Hollow also deletes its storage. Neither can be undone — export a backup first.
Questions can be sent through the support channel on this listing.