隐私政策 / Privacy Policy

Auto Login Manager — Chrome 扩展(Manifest V3)v1.0.0

生效日期 Effective: 2026-09-24 最后更新 Last updated: 2026-09-24
中文隐私政策 English Privacy Policy

中 文 / ZH-CN

一句话说明

本扩展(Auto Login Manager)是一个浏览器端自动填充工具:你为特定网站保存登录配置(域名、用户名、密码),本扩展在你访问已授权网站时自动填充登录表单。所有凭据仅在设置本机口令后以 AES-GCM-256 密文保存在你自己的浏览器本机;本扩展不包含任何网络请求代码,不将任何数据上传到任何服务器。

1. 我们收集哪些数据

我们只处理你主动录入的数据,并且这些数据不会离开你的设备。

数据类型是否收集来源用途
登录配置(域名/URL 匹配规则、用户名、密码、别名)是你在扩展侧边栏手动录入,或通过「从书签导入」批量生成核心功能:自动填充登录表单(单一用途)
环境信息(环境名称、环境内配置分组)是你创建环境时录入多环境配置管理
设置项(自动提交、填充延迟、选择器、启用状态)是你配置时录入控制填充行为
自动提交失败计数是扩展运行产生防止账号因连续自动提交被锁定(纯本地计数)
浏览器书签是(仅点击「从书签导入」时)Chrome 书签 API仅在你主动触发时读取书签生成域名配置

明确不收集:

2. 数据保存在哪里

数据位置说明
域名配置、用户名、密码、环境信息chrome.storage.local设置本机口令后以 AES-GCM-256 密文保存
解锁期间的明文配置chrome.storage.session仅内存,浏览器关闭即清除;10 分钟无操作自动锁定
加密密钥句柄扩展专属 IndexedDB存的是不可导出的密钥对象(extractable: false),无法读出原始密钥字节
登录失败计数chrome.storage.local非敏感,仅用于失败次数限制

主口令本身不会被保存到任何存储位置。它仅用于派生加密密钥,解锁后只保留派生结果。

3. 加密方式

如果你忘记本机口令,数据无法恢复,这是加密设计的必然结果。

4. 权限用途(与清单权限逐项对应)

权限用途
storage保存加密配置(storage.local)与解锁期间的会话数据(storage.session)
activeTab你点击扩展图标时临时访问当前标签页,用于「在当前页面填充」与「填入当前域名」
scripting在需要时按需注入填充脚本
sidePanel显示扩展侧边栏界面
bookmarks仅当你点击「从书签导入」时读取书签,用于批量生成域名配置

网站访问权限采取最小化设计:本扩展未在安装时申请任何全站访问权限(manifest 仅含 optional_host_permissions: ["*://*/*"])。只有在你保存某个域名配置时,才会询问一次「是否允许访问该网站」;未授权的网站不会执行任何本扩展脚本。你可以随时在 chrome://extensions 中撤销授权,撤销后该网站不再自动填充(手动填充仍可用)。

无强制内容注入:本扩展的 manifest 中不包含 content_scripts 声明,不会在你未授权的情况下自动向任何网页注入脚本;填充脚本仅在已授权网站或你手动触发时按需注入。

5. 数据的导出与删除

6. 第三方共享

不存在。本扩展不与任何第三方共享数据,因为它不向外传输数据;不涉及数据出售、广告、跨站追踪。

7. 政策变更

若本政策发生实质性变更,将更新本文件顶部的「政策最后更新」日期,并随扩展版本更新一并发布;涉及数据处理方式变更时,将按 Chrome Web Store 政策要求主动进行显著披露。

8. 联系方式

如有隐私相关问题,也可通过上述渠道联系我们,我们会在合理时间内回复。

E N G L I S H

Summary

Auto Login Manager is a browser-side auto-fill tool. You save login entries (domain, username, password) for websites you choose; the extension auto-fills the login form when you visit an authorized site. All credentials are stored on your own machine, encrypted with AES-GCM-256 after you set a local master password. The extension contains no networking code and transmits nothing anywhere.

1. Data We Collect

We only handle data you enter yourself, and it never leaves your device.

Data typeCollectedSourcePurpose
Login entries (domain / URL match rules, username, password, alias)YesYou type them into the side panel, or generate them in bulk via "import from bookmarks"Core function: auto-fill login forms (single purpose)
Environment info (environment names and config groups)YesYou create environments in the UIMulti-environment config management
Settings (auto-submit, fill delay, selectors, enabled state)YesYou configure themControl fill behavior
Auto-submit failure countersYesGenerated by the extension at runtimePrevents account lockout from repeated auto-submits (local counter only)
Browser bookmarksYes (only when you click "import from bookmarks")Chrome bookmarks APIRead bookmarks only when you explicitly trigger the import

Explicitly not collected:

2. Where Data Is Stored

DataLocationNotes
Domain configs, usernames, passwords, environmentschrome.storage.localStored as AES-GCM-256 ciphertext once a master password is set
Decrypted configs while unlockedchrome.storage.sessionIn-memory only; cleared when the browser closes; auto-locks after 10 minutes of inactivity
Encryption key handleExtension-owned IndexedDBA non-extractable key object; raw key bytes cannot be read out
Login failure counterschrome.storage.localNon-sensitive; used only to throttle repeated auto-submits

The master password itself is never written to any storage. It is only used to derive the encryption key.

3. Encryption

If you forget your master password, the data cannot be recovered. That is an inherent property of the encryption design.

4. Permissions (mapped 1:1 to the declared permissions)

PermissionPurpose
storageSave encrypted configs (storage.local) and unlocked session data (storage.session)
activeTabTemporary access to the active tab when you click the extension icon, for "fill current page" and "fill current domain"
scriptingInject the fill script on demand
sidePanelRender the side panel UI
bookmarksRead bookmarks only when you click "import from bookmarks", to generate domain configs in bulk

Site access is minimal by design: the extension does not request any install-time access to all websites (the manifest only declares optional_host_permissions: ["*://*/*"]). You are asked once, when you save a config for a domain, whether to allow access to that site. No extension script runs on sites you have not authorized. You can revoke grants at any time from chrome://extensions; revoked sites simply stop auto-filling (manual fill still works).

No forced content injection: the manifest declares no content_scripts. The extension never injects scripts into any page without your authorization; fill scripts are injected on demand only on authorized sites or when you trigger fill manually.

5. Export and Deletion

6. Third Parties

None. The extension does not share data with any third party because it does not transmit data anywhere; no data selling, no ads, no cross-site tracking.

7. Policy Changes

Material changes will be reflected in the "Last updated" date at the top of this document and shipped with a new extension version. Changes to data handling practices will be proactively disclosed as required by Chrome Web Store policy.

8. Contact

For privacy-related questions, please contact us through the channels above; we will respond within a reasonable timeframe.