Privacy Policy & Local Data Guarantee
Lokker is built on a fundamental privacy promise: your credentials remain strictly on your own device.
Lokker operates without a central cloud vault or user account server. Your passwords, 2FA keys, secure notes, credit cards, and bookmarks are encrypted client-side and saved exclusively inside your browser local IndexedDB.
Lokker contains no analytics scripts, third-party trackers, pixel beacons, or user tracking code. We do not collect or log usage statistics, search queries, or IP addresses.
When running dark web breach checks, Lokker uses SHA-1 k-Anonymity 5-character prefix search with Add-Padding: true headers. Plaintext passwords are never sent over the network.
The Lokker Chrome/Edge Manifest V3 extension communicates with website forms through isolated Shadow DOM containers. It checks credentials against target domain origins locally.
Cloud account creation and remote synchronization are 100% voluntary and strictly opt-in. If you choose to enable cloud synchronization, our Fastify v5 + Neon Serverless Postgres backend only receives and coordinates end-to-end encrypted ciphertext blobs. Your master password and encryption keys never leave your device. If you choose not to create an account, Lokker remains 100% offline, local, and functional forever.
Data Flow & Boundary Matrix
- • Master password salt & PBKDF2 parameters
- • AES-GCM 256-bit encrypted vault payload
- • User categories, tags, and settings
- • 2FA TOTP secrets (encrypted at rest)
- • Local encrypted bookmarks
- • Nothing. Zero telemetry is transmitted.
- • No tracking cookies, IPs, or analytics beacons.
- • Optional breach check sends only 5-character SHA-1 prefix with padding.
- • No cloud backups are created unless explicitly exported by you.