diskus.ai Open Diskus

Greenbox Safe Browser Extension — Privacy Policy

Effective date: 7 August 2026

This policy covers the Greenbox Safe browser extension published by Discus IT Pvt Ltd (“Diskus”, “we”, “us”). The extension is a companion to the Greenbox Safe app, and the app has its own policy: the Greenbox Safe Privacy Policy. That document covers the extension too, in outline; this one is the detailed account of the extension specifically, and it is the policy referenced from the extension's listing in the Chrome Web Store and the Edge Add-ons store. Neither is covered by the general Diskus AI Privacy Policy, which describes an account-based service that Greenbox Safe is not. Your use is governed by the Diskus AI Terms of Service.

The short version. The extension has no account and sends us nothing. There is no analytics, no telemetry, no error reporting and no usage reporting. Your credentials stay in your browser, encrypted. We do not have a server for this extension to talk to.

1. There is no account and no sign-in

The extension does not ask you to register and there is nothing to sign in to. It holds no identifier for you, and we hold nothing for you. Because there is no account, there is no account data to correct, export or delete — everything the extension knows is on your own machine, and section 8 describes how to remove it.

2. What the extension stores in your browser

The extension stores the login entries you import or save, encrypted with AES-256 GCM, in your browser's own extension storage. It also stores your settings — for example whether autofill is enabled, your auto-lock timeout, and the sites you have excluded. All of it is local to the browser profile you installed it in.

We never see, store or transmit your passwords. That is not a promise about our intentions; section 3 explains why it is not something the extension is capable of doing.

3. No analytics and no telemetry

The extension collects no analytics and no telemetry whatsoever. It does not report which features you use, does not send error or crash reports, and does not transmit browsing history, page contents, passwords or TOTP secrets. It sends no vault data to any Diskus server, because there is no Diskus server behind this extension.

This is structural rather than a matter of configuration. The extension's manifest.json declares "host_permissions": [] — an empty list. Under Manifest V3 an extension with no host permissions cannot make cross-origin network requests at all. The extension's code also contains no fetch, XMLHttpRequest or sendBeacon call. There is therefore no code path by which it could report anything, and no setting that could turn one on.

4. Autofill and local processing

When you ask the extension to fill a login, it reads the active page's address and its login fields inside your browser in order to find and fill a matching credential. This happens locally. The page address is not transmitted to us or to anyone else, and it is not recorded as history.

The extension acts on the active tab only after you interact with it directly — by opening the popup or side panel, using a keyboard shortcut, or choosing Fill with Greenbox Safe from the right-click menu. It does not run on pages you have not invoked it on, and you can exclude specific sites entirely from the Options page.

5. Detecting a login you have just typed

After you interact with Greenbox on a page, the extension can detect a submitted username and password so it can offer to save or update the entry. A new or changed login stays in browser session memory for no more than five minutes while it waits for your Save or Update decision, and is cleared as soon as you dismiss the prompt, save, lock, auto-lock, or close the browser. It is never sent anywhere during that window.

6. Vault and key files you open

When you select a Greenbox vault or key file, the extension reads and decrypts it locally, in memory, in the vault workspace. The file you picked is not uploaded. Only the login fields you explicitly import, or confirm saving, are copied into the encrypted browser vault.

If the file you choose happens to live in a folder synced by Google Drive, OneDrive, Dropbox or a similar tool, the extension simply reads it through your browser's file picker like any other file. It holds no credentials for those services and makes no API calls to them; whatever that provider does with the folder is governed by your arrangement with them, not by us.

7. Permissions, and why each one exists

8. Your control and deleting your data

You can edit or delete individual entries, clear all locally stored vault entries, and change or reset your settings from within the extension. Uninstalling the extension removes its browser-managed local storage according to your browser's own behaviour.

There is nothing for us to delete on request, because we hold nothing. If you also use the Greenbox Safe app, see section 10 of the app's privacy policy for removing vault copies you have placed elsewhere.

9. Children

The extension is not directed at children and collects nothing from anyone, including children.

10. Changes to this policy

We may update this policy as the extension changes. Material changes will be announced on this page and the effective date above will be revised. If a future version of the extension ever collects anything — including any form of analytics — this policy will be updated before that release ships, not after.

11. Contact and grievance redressal (India)

Questions or requests regarding privacy in the Greenbox Safe browser extension: hello@diskus.ai.

In accordance with the Information Technology Act, 2000, the IT Rules, 2021, and the DPDP Act, 2023, grievances are handled by our Grievance Officer, reachable at hello@diskus.ai (subject line “Grievance”). Acknowledgement within 24 hours; resolution within 15 days. Discus IT Pvt Ltd is registered and operates in India.