Last updated: 2026-05-31
This Privacy Policy describes how the Teampass Password Manager browser extension (the “Extension”) for Microsoft Edge, Google Chrome and Mozilla Firefox handles user data. The Extension is published by the Teampass project (the “Publisher”, “we”, “us”) and is designed to act as a client interface to a self-hosted Teampass password manager server.
By installing or using the Extension you agree to this Privacy Policy.
For any privacy-related request (access, rectification, erasure, portability, restriction, objection), please email [email protected]. We will respond within 30 days.
The Extension has a single purpose: to let users securely retrieve, autofill, create and save credentials stored on their own self-hosted Teampass server, directly from the websites they visit.
The Extension is not a cloud service. It does not host any user vault. All credentials remain on the Teampass server instance operated by the user or their organisation.
The Extension uses the browser’s chrome.storage.local and
chrome.storage.session APIs to persist:
All of this data stays on the user’s device. None of it is sent to the Publisher or to any third party.
When the user performs an action in the Extension (search, autofill, save, update, delete), the Extension sends an authenticated REST API request to the Teampass server URL configured by the user. This exchange may include:
The Publisher has no access to this traffic. It flows directly between the user’s browser and the user’s server.
To verify that the user holds a valid licence, the Extension contacts
the endpoint https://licence.teampass.net/api/v1.1/. The following
data is transmitted:
This data is used only to verify the validity of the licence through an RSA-signed response. It is not used for profiling, advertising or analytics. A 5-day grace period is applied in case the licence server is unreachable, so the Extension keeps working offline.
The Extension does not collect or transmit:
| Permission | Why it is required |
|---|---|
storage |
Persist server URL, JWT token, encrypted transient credentials and user preferences locally. |
activeTab |
Read the URL and form fields of the tab the user is currently interacting with, to match and autofill credentials. |
clipboardWrite |
Copy a secret (password, TOTP, username) to the clipboard when the user clicks the copy button. The Extension never reads the clipboard. |
tabs |
Detect successful logins across multi-step flows (2FA, SSO redirects) so the “save credential” prompt can appear on the correct tab. |
<all_urls> (host permission) |
Allow autofill and credential capture on any website the user chooses to log into. |
No permission is used for any purpose other than the one listed above.
The Extension does not load, execute or evaluate any
remotely-hosted code. All JavaScript shipped with the Extension is
bundled in the package distributed through the Microsoft Edge Add-ons
store (and equivalent stores). A strict Content Security Policy
(script-src 'self') forbids loading external scripts, eval() and
inline scripts. External endpoints only return data (JSON), never
executable code.
We do not sell, rent, trade or transfer user data to any third party. We do not use user data for advertising, profiling, credit scoring or lending purposes. We do not use user data for any purpose unrelated to the Extension’s single purpose described in section 2.
The only network destinations contacted by the Extension are:
https://licence.teampass.net/api/v1.1/.licence.teampass.net is kept for
the duration of the active subscription and for any legal
retention period required afterwards. Users can request deletion
at any time by emailing [email protected].The Extension is not directed at children under 16. We do not knowingly collect data from children.
The licence server is operated within the European Union. Data exchanged with the user’s Teampass server is transferred to the infrastructure chosen by the user or their organisation, and is subject to that infrastructure’s location and policies.
If you are located in the European Economic Area, the United Kingdom, Switzerland, California or any jurisdiction granting similar rights, you may:
Send any such request to [email protected].
We may update this Privacy Policy from time to time. Material changes will be announced through the Extension’s release notes and on the project website. The “Last updated” date at the top of this document always reflects the latest revision.
Questions, requests or concerns about this Privacy Policy: [email protected]