← Back to Otter Vault

Support

Otter Vault is built by one person, Krishna Ganga. Every message below reaches me directly, and I aim to reply within three days.

Email support

Otter Vault for Chrome is in the Chrome Web Store.

Report a bug

Email krishna091718@gmail.com with "otter vault bug" in the subject. It helps to include:

Please never include a real password or API key in an email. Describe the shape of the value instead, for example "a 40-character key beginning sk-".

Report a security issue

krishna091718@gmail.com, subject "otter vault security" Use synthetic credentials only, never real ones. I acknowledge reports within three days and will credit you if you want that. The full threat model and the testing behind each claim are published with the project.

Machine-readable contact details are at /.well-known/security.txt.

Common questions

I forgot my vault passphrase. Can you recover it? No, and that is deliberate. Your passphrase never leaves your device and is never stored, so there is no copy for anyone, including me, to recover from. The only way forward is to create a new vault and save your secrets again.
Otter did not notice a key on a site. Send me the site and where the key appeared, for example inside a dialog, or behind a "reveal" button. Each provider shows keys differently, and I add them one by one. Do not send the key itself.
Where are my secrets stored? On your device only, encrypted with AES-256-GCM using a key derived from your passphrase. There is no server, no account, no sync and no analytics, and the extension makes no network requests.
How do I delete everything? Remove items one by one from the popup, or uninstall the extension, which deletes its storage with it. For the Mac app, delete ~/Library/Application Support/Otter Vault/.
Does Otter read the pages I visit? The extension looks at pages on your device to spot password fields and one-time key reveals. Nothing about a page is stored or sent anywhere. The only thing saved is a credential you explicitly choose to keep.

Privacy

The full policy is at krishnag1703.github.io/ottice-privacy.