Privacy policy
1. We cannot read your visa data
The passport details, portrait photo and original documents you enter on the application page are stored only in your own browser (localStorage / IndexedDB); photo cropping and compression happen on your device. Clearing the site data in your browser deletes everything.
The optional cloud backup is end-to-end encrypted.With the AutoePass extension installed and Google sign-in, the profile card (fields, portrait, document images) is encrypted on your device with the password you set (AES-256-GCM, key derived by PBKDF2 over 310,000 iterations) and only the ciphertext is uploaded. The server stores three things: a hash of the Google account identifier, a blob of ciphertext and an update time.We do not have the password, cannot decrypt the blob and cannot recover it for you;if you forget the password, the cloud copy is useless data. Signing out or clearing in the extension deletes the cloud copy at any time. Google sign-in only identifies you; we read no contacts, mail or drive.
Without the extension or without signing in, the data exists only in this browser on this device; clearing the cache, switching browsers or changing computers loses the card, and we hold no copy to restore. Use "Save offline" below to export your own copy.
2. The offline file
On the card page you can export the card as one HTML file with the fields and both images packed inside; double-click to open it in a browser or print it to PDF. The export runs entirely on your device and the file is saved straight to your own disk, never passing through our servers.
Choose plain or encrypted. A plain file is readable by anyone who opens it, so keep it off shared computers. Encryption uses AES-256-GCM with a key derived from your password by PBKDF2 (310,000 iterations, SHA-256); the ciphertext, salt and IV are all inside the file, which decrypts locally when opened.We do not have this password and cannot reset it; if you forget it, the file cannot be opened.
The one exception is document recognition.When you upload a passport data page or add a document to "My documents" and its fields are to be read automatically, that one image is relayed through our server to a third-party vision model (Qwen2.5-VL on OpenRouter) for a single recognition pass. The "auto-recognise" switch above the upload area is on by default, can be turned off at any time and is remembered locally; when off, the document is still stored and you type the fields yourself. The image is used for that one pass only; we do not retain it or use it for anything else.
3. What we log
To learn where users want to go and to avoid double counting, when you click "Request this route" or "Go to the official site" the server records only the first 16 characters of a salted hash of your IP address and the destination code; no raw IP, device details or names.
The site is served through Cloudflare, which handles connection-level logs under its own privacy policy.
4. The browser extension
By default the extension runs on only two kinds of page: aievisa.shop (this site, to hand the profile card between the page and the extension) and evisa.gov.vn (the official Vietnam e-visa form, adapted field by field).
On any other site it does not run automatically. Only when you click "Fill this page" in the extension icon, and the browser asks and you agree, does it run a single fill on that site. Access is granted per site and can be withdrawn at any time in Chrome's extension settings.
The identity fields it handles (name, passport number, date of birth, address, contacts and so on) and the document images are kept in the browser's local storage on your device; with cloud backup on, they are synced encrypted as described in section 1. It never submits forms, never pays and never bypasses CAPTCHAs. When filling, it only writes values into the page's inputs and places files from your wallet into upload boxes; it reads nothing else on the page.
Two optional features send a small amount of content to our server: with "Let a model judge unrecognised fields" on, the form'slabel text and dropdown option text (never any value you entered) is sent to our server and relayed to a third-party language model to judge what each field means, cached per site; document recognition is described in section 2. Both can be switched off in the extension settings.
In the terms of the Chrome Web Store data declaration, the extension handles two data types:Personal identity data (name, passport number, date of birth, address, email, phone, emergency contact and the document images in the wallet), stored on your device and, with cloud backup on, transmitted and stored end-to-end encrypted;Authentication data, the identity token returned by Google sign-in, used only to attribute the backup and not stored on the server. Browsing history, website content, financial data, health data, location, personal communications and user activity are not collected at all. Data is not sold, not used for advertising and not used for anything unrelated to the extension's core function.
If field-mapping crowdsourcing is added in future, it will upload only form label text and the field name it maps to, never any value you entered; it will ask for your separate consent, default to off, and this policy will be updated before it ships.
5. Image credits
The crowdfunding page header is a photograph of a Thai border counter by Sharon Hahn Darlin, used under CC BY 2.0 , cropped and darkened by us.
6. Contact
For any privacy question, contact us through the details in the footer.