Privacy policy for Royal Passkey & 2FA
Royal Passkey & 2FA by Royal
Privacy Policy for Royal Passkey & 2FA
Effective date: July 23, 2026
Royal Passkey & 2FA (“the Extension”) is an offline-first browser extension whose single purpose is to help users create, store, and use WebAuthn passkeys and TOTP 2FA codes in an encrypted vault on their own device. This policy explains what data the Extension processes, where it stays, and what optional features can send data off the device—only when the user configures them.
No developer servers
The Extension does not require a Royal Passkey account and does not send vault data to servers operated by the developer. Core passkey creation, sign-in, vault encryption, TOTP codes, settings, and local backups run on the user’s device inside the browser extension environment. Even if optional features are enabled, the developer does not receive, store, or process the user’s passkeys, 2FA secrets, or vault contents on developer infrastructure.
Data the Extension processes (on device)
To provide its single purpose, the Extension processes the following categories of user data locally. This matches the disclosure expected for a credential vault that participates in WebAuthn on websites:
Authentication data — passkey credential material (including private key material stored in the encrypted vault), TOTP/2FA secrets, vault password / unlock state, and related cryptographic metadata;
Personally identifiable information — identifiers supplied by the website during WebAuthn (for example username, display name, or user ID) when stored with a passkey entry;
Website content / context required for WebAuthn — limited page-context data needed to complete create and get flows (for example origin, RP ID/domain, and WebAuthn request options). The Extension does not build a general browsing history and does not sell or monetize page content.
The Extension does not collect health information, financial/payment card data for processing by the developer, precise location, web search history lists, or general click/keystroke monitoring.
How data is used
Data is used only to:
create, store, assert, list, import, export, and delete passkeys and TOTP entries in the local vault;
complete user-initiated WebAuthn authentication on websites the user visits;
apply user-requested security and UX settings (for example vault lock, language, native fallback, app priority);
deliver optional, user-configured notifications or user-initiated backup/transfer workflows that support the same vault purpose—not a separate product purpose.
Data is not used for advertising, profiling, analytics sold to third parties, or determining creditworthiness / lending decisions.
Storage and security
Vault data is stored locally via browser extension storage on the user’s device.
Vault contents are protected with encryption implemented in the Extension; users should choose a strong vault password.
When the vault locks, key material used for unlock is cleared from memory according to the Extension’s lock behavior.
Users are responsible for safeguarding vault passwords, exported backups, and any transfer files. Loss of the password and all backups may make recovery impossible—there is no developer-side recovery service.
Optional features and third parties
Import / export and transfer
Users may export or import encrypted vault data or individual protected transfer payloads between their own installs of the Extension. Those files remain under the user’s control. The developer does not host or receive those files.
Telegram notifications (optional)
By default, Telegram is off and no Telegram network calls are made. If the user explicitly enables notifications and enters their own Telegram bot token and chat/user id in Settings, the Extension may send limited notification content to Telegram’s API (https://api.telegram.org/*) so the message is delivered to that user-configured chat.
Messages go to Telegram as configured by the user—not to developer servers.
The developer does not operate the bot or chat unless the user chooses to use credentials they control.
Users can disable Telegram or clear those settings at any time; when disabled, this path is unused.
Telegram’s handling of messages is governed by Telegram’s own terms and privacy policy. Users should treat any notification content as sensitive and enable this feature only if they accept that trade-off.
Permissions (summary)
storage — persist the encrypted vault and user settings on device.
alarms — local timers such as vault auto-lock; no network use.
Host access for content scripts (<all_urls>) — required so WebAuthn create/get on websites the user visits can be handled by the local vault.
Host access to api.telegram.org — only for optional user-configured Telegram notifications.
For Firefox / AMO data-collection declarations: the Extension does not transmit vault data to developer servers (required: none). Optional Telegram delivery—when enabled by the user to their own bot/chat—is the only outbound path and is declared as optional authentication-related data. Declining that optional category (or leaving Telegram disabled) keeps the Extension fully local.
Remote code
The Extension does not execute remote code. JavaScript shipped with the Extension package runs locally. The Extension does not load remote scripts or Wasm, and does not use eval to run code fetched from the network.
Selling and sharing
In line with Chrome Web Store user data requirements, the developer confirms that:
user data is not sold;
user data is not used or transferred for purposes unrelated to the Extension’s single purpose (local passkey and 2FA vault management), except as required to operate optional user-configured features such as Telegram delivery via Telegram’s API;
user data is not used or transferred to determine creditworthiness or for lending purposes.
User controls
Users can:
lock and unlock the vault;
create, view, export, import, and delete passkey and TOTP entries;
reset Extension data (danger zone / full reset, where available);
enable, disable, or reconfigure optional Telegram notifications;
uninstall the Extension to remove its local storage according to browser behavior.
Children’s privacy
The Extension is not directed at children and is intended for users who manage their own online credentials. Do not use it to store credentials for others without appropriate authorization.
Policy updates
This policy may be updated to reflect product or legal changes. The current version is published on this page with an updated effective date. Continued use after an update means the user accepts the revised policy for that version of the Extension.
Contact
For privacy questions about Royal Passkey & 2FA, contact: accs.royal@gmail.com