Français · English
Privacy Policy
Effective 22 August 2026 · Applies to the Coffre service: web application, browser extension and Android application.
The essentials. Coffre is a zero-knowledge password manager: your vault contents (item names, usernames, passwords, site addresses, fields, files and 2FA secrets) are encrypted on your device with a key derived from your master password, and that master password never leaves your device. Our servers cannot read your secrets, and neither can anyone at Axologique. We sell no information, display no advertising and use no trackers.
1. Person accountable for the protection of personal information
Under Quebec's Law 25 (Act to modernize legislative provisions as regards the protection of personal information), the person accountable is:
Olivier Bérubé — Coffre.ai (operated by Groupe Axologique Inc.)
Email: info@coffre.ai
2. Information we collect
- Account: email address, display name, and a cryptographic digest derived from your account password (never the password itself).
- Vault contents: only end-to-end encrypted data, opaque to our servers. The master password and the vault key are never transmitted.
- Devices and access: digests (hashes) of paired-device tokens and extension keys, creation and use timestamps, session identifiers.
- Billing: subscription state and customer identifiers at our payment processor, Stripe. Card numbers are handled by Stripe and never pass through our servers.
- Technical logs: IP addresses and security events strictly necessary to operate and protect the service.
3. What the extension and the Android application keep locally
- The extension keeps your settings locally, a revocable access authorization and, if you turn it on, a quick-unlock record (PIN) encrypted with a non-exportable key held by your browser. Decrypted items live only in session memory and are erased on lock.
- The Android application protects the key received during pairing with the Android Keystore and requires your biometrics or screen lock.
- None of this local data is transmitted to Coffre.ai.
4. Purposes and consent
We use this information only to: provide and synchronize the service, authenticate you, manage the subscription and billing, ensure security (abuse detection, access revocation) and meet our legal obligations. We do no profiling, no advertising, and no sale or rental of information. Any other use would be the subject of separate, prior consent.
5. Hosting and disclosure to third parties
- Service data is hosted on servers located in Quebec, Canada, administered by Groupe Axologique Inc.
- Stripe (payments): billing information is processed by Stripe, whose servers are located notably in the United States.
- Cloudflare (network): traffic to the service transits Cloudflare's global network, acting as a technical intermediary; vault contents already travel end-to-end encrypted.
- No other third party receives personal information, except where required by law.
6. Retention and destruction
Information is kept for as long as your account is active. Account deletion is available from any device, through a browser, at coffre.ai/app: the Account → Delete the account screen. That is the path that works for everyone. The Android application published on Google Play and the extension published on the Chrome Web Store do not carry that screen yet; opening coffre.ai/app in a browser deletes the same account, whichever channel you use it through. It runs immediately and erases from our active systems the account, the vault, its items, its files, its log, paired devices, extension keys, delegations, sessions and the subscription; backup copies are then erased on their normal rotation cycle. Encrypted vault data is undecipherable without your master password, backups included.
7. Security
- End-to-end encryption of vault contents (Argon2id derivation, authenticated encryption).
- Encrypted transport (HTTPS/TLS) for all communications.
- Strict separation: the server holds only encrypted data and authentication digests; regular backups before every deployment.
- Revocation: changing the account password or using "sign out everywhere" revokes sessions, extension keys and paired devices.
In the event of a confidentiality incident presenting a risk of serious injury, we will notify you and the Commission d'accès à l'information du Québec, as required by law.
8. Cookies
Coffre uses a single, strictly necessary cookie: the coffre_session session cookie that keeps you signed in. No advertising, analytics or tracking cookie is used.
9. Your rights
At any time you may: access the information we hold about you, have it corrected, withdraw your consent, close your account and delete your information, or receive your vault data.
- Access — vault contents: Vault → Import / Export → Export JSON or CSV. Decryption happens on your device; we cannot produce that content on your behalf.
- Access — everything else: at coffre.ai/app, Account → Your data → Download my account data (JSON). The file carries the account, subscription, paired devices, keys, delegations, sessions and the vault log.
- Deletion: at coffre.ai/app, Account → Delete the account, immediate and permanent.
Those last two screens live at coffre.ai/app, in a browser. The published Android application and the published extension do not carry them yet; the browser acts on the same account. If you cannot use a browser, write to info@coffre.ai: we carry out the request ourselves, free of charge and within the same delays.
For any other request — correction, withdrawal of consent, portability — write to info@coffre.ai; we answer within 30 days. If you are dissatisfied with how your request was handled, you may file a complaint with the Commission d'accès à l'information du Québec.
10. Changes
Any material change to this policy will be published on this page with a new effective date.
This policy exists in French and in English. In case of discrepancy, the French version prevails.