Secret Protection Guide & User Manual
Effective 2026-09-07 · Seller: tinygem
Translation notice: This page is translated from Korean. You can also read the Korean source using the language menu. Your statutory rights remain unchanged regardless of language.
By default, we restrict AI tools from receiving raw secrets. This is not a product that prevents OS compromise or access through other tools, or guarantees secrecy in every circumstance.
Optional sharing of values: “Share value with AI” is off by default for each field. If you enable it after confirming the notice, current and future AI connections registered to this vault can read that value in full. This is separate from AI access, destinations and task approvals. For web connections, shared values pass through the relay server and AI service. The AI service’s storage and processing policies apply.
Values already sent to AI cannot be recalled by turning this setting off later. Choose carefully before sharing. After sharing is successfully disabled, new reads are blocked, but information already approved for delivery, in transit or delivered cannot be recalled. Changing a value or restoring a backup disables sharing; enabling it again requires confirmation.
How to use it
Store secrets in value fields and approve AI connections and task scopes separately. AI sends approval identifiers and task inputs; Bossanova checks permissions locally and sends required values to approved destinations. AI receives limited receipts or statuses for each task. Destinations receive actual values, and labels/descriptions may be visible to AI.
Currently supported tasks are limited GitHub operations and EU VIES VAT checks. Filling arbitrary sites or generating contracts containing secrets is not currently supported. The PC and connection program must be running. Secrets are not used while the vault is locked. Receipt does not mean completion.
Outside the protection boundary: prevention
- Secrets in names or descriptions: Use labels that are safe to share. Do not repeat secret values in titles or descriptions.
- Direct disclosure: AI can see secrets you paste into chat or provide in files, screens or exported results. Also consider clipboard history and synchronization after viewing or copying values.
- Excessive AI permissions: Administrator privileges, unrestricted shell commands, file/screen/accessibility/clipboard access, debugging and memory access are separate from Bossanova connection approval. Use automatic approval carefully and allow only what is needed. Disconnecting Bossanova does not revoke permissions granted to other tools.
- Compromised device: OS/account compromise, malware, keyloggers and modified apps can intercept values or passwords. Use official releases and security updates. Vault encryption does not make a compromised OS safe.
- Destinations and external copies: Approved services receive values. Check the recipient’s sharing settings, permissions and policies. External copies such as documents, backups and screenshots, and values already sent, are not recalled by locking the vault or disconnecting AI.
- External information and inference: AI may still learn or infer information from public sources or permitted task results.
If you suspect a compromise
Stop AI tasks, lock the vault and revoke the connection and other tools’ access. If the device may be compromised, isolate it from the network and revoke or replace service tokens and passwords from a separate trusted device. Information already sent must be addressed separately with the recipient. Do not attach raw secrets, master passwords or vault files to support requests.
Liability and your rights
To the extent permitted by law, tinygem is not liable for losses caused by users, third parties or external conditions where tinygem is not at fault. This does not exclude statutory liability for intentional misconduct, gross negligence, product defects or breaches of security obligations, or users’ statutory rights. For details, see Section 5 of the Terms.