ALI Vault Browser Extension Privacy

ALI Vault is an internal credential-management extension for authorized ALI Support Services users. It is designed to retrieve encrypted Vault records, decrypt them locally after the user supplies the Vault Master Password or verifies an enrolled passkey, and fill login or payment-card fields only after an explicit user action or per-site inline-autofill approval.

Data processed

The extension processes the signed-in ALI account identity, ALI Vault session data, encrypted Vault records, website origins used for credential matching, login fields selected by the user, and passkey credential identifiers plus random PRF salts used for optional passkey Vault unlock. Plaintext usernames, passwords, approved custom login fields, and selected payment-card values (cardholder name, card number, expiry, security code, and postal code) exist only as required to provide the requested fill or copy operation. Payment-card PIN values are not released to the browser autofill path.

Storage and retention

The Master Password and decrypted Vault Key are not persistently stored by the extension. For optional passkey unlock, ALI Vault stores only a passkey credential identifier, random PRF salt, and an AES-GCM-encrypted Vault-Key envelope on the ALI Vault service. WebAuthn biometric information, device PINs, and PRF outputs are handled by the browser/authenticator and are not sent to or stored by ALI Vault. The revocable extension session and the short-lived inline credential cache use chrome.storage.session, not persistent local or sync storage. The inline cache expires after five minutes of inactivity. The server-side extension session expires or can be revoked according to ALI Vault session controls.

Network use

The extension communicates with https://vault.alisupportservices.com for website-session handoff, Microsoft sign-in fallback, authorization checks, encrypted Vault retrieval, and session revocation. If the Vault website is already signed in in the same Chrome profile, that website cookie is used only by the browser to authorize creation of a separate revocable extension session; the website cookie is not copied into extension storage. ALI Vault does not use advertising or third-party analytics in the extension. Credentials are not sent to unrelated third parties. When a user chooses Fill, the selected values are written only to the active HTTPS page in the user's browser. ALI Vault never clicks a payment confirmation or form-submit control.

Website access

Required host access is limited to the ALI Vault service. Inline autofill access to other HTTPS sites is optional and is requested per site. Login matching remains restricted to the exact HTTPS origins saved in the selected Vault record. Payment cards are not background-matched to websites: card fill requires an explicit card selection on an active HTTPS page, or an explicit inline selection on a site for which the user granted ALI Vault access.

Purpose limitation

Extension data is used only to authenticate authorized ALI users, enforce Vault access controls, present matching credentials, and perform user-requested fill or copy operations. ALI Vault does not sell extension data.

Support

Authorized users should contact ALI Support Services through the organization's normal IT support channel for extension access, revocation, or privacy questions.