Your data never leaves your browser — the header is built client-side and nothing is stored.

Basic auth is reversible encoding, not encryption.