Privacy policy
Short version: your browsing history never leaves your device, everything except sync, cloud AI and billing works without an account, and the extension does not collect analytics.
1. Who we are
Tomlock is operated by [COMPANY NAME], [COMPANY ADDRESS] (“we”). For privacy questions or requests, contact [CONTACT EMAIL]. This policy covers the Tomlock browser extension, the Tomlock web app and this website.
2. The short version
- Never leaves your device: your browsing history, page content, and which sites you were blocked from. The one exception is below under Smart unblock.
- Leaves your device only if you sign in: your account, your session summaries (times, minutes, lock level, status, time zone, optional label) and game totals. With Pro, also your settings and blocklists, which include the sites you chose to block.
- Smart unblock uses the page address, page title and your goal. It runs on your device by default. A cloud fallback exists for Pro only, and only if you switch it on. In that case the page address (query removed), page title and goal are sent.
- No analytics in the extension. Version 1.0 sends no usage data. If we add opt-in analytics later, we will update this policy and ask first.
- We do not sell your data and the extension contains no third-party trackers.
3. What stays on your device
Without an account, everything below stays in your browser's local storage and IndexedDB and is never sent to us. It is deleted when you remove the extension or clear its data.
| Stored locally | Fields |
|---|---|
| Sessions | Start and end time, planned and focus minutes, kind (focus or stopwatch), lock level, label, status (completed, stopped, interrupted), resisted count, combo, and a synced flag. |
| Settings | Presets, sounds and volume, notifications, lock level, calm mode and other toggles. |
| Blocklists | The sites, wildcards and path rules you add and allow-list entries. |
| Block-page log | How many times the block page appeared, grouped by domain and day (“bounces”), and the log of temporary 5-minute grants with the reason you typed. Used for your stats tab. Never uploaded. |
| Game state | A local preview of your level, XP, gems, streak, quests and badges. |
| Sync outbox | Changes waiting to be sent when you are signed in and online. |
| AI cache | Smart unblock verdicts per domain and goal for the current session. |
| Active session mirror | The running session, end time, last heartbeat and grants, so a restart can recover it. |
| Device token | A device token if you link your account. |
Your browsing history is not stored by Tomlock. The block-page log above records the domains of sites you were blocked from, on your device, so we can show you your own stats. We do not receive it.
Browser permissions and why
| Permission | Why Tomlock needs it |
|---|---|
storage | Keeps your settings, sessions and game progress on your device. |
alarms | Ends focus and break phases on time, even when the popup is closed. |
declarativeNetRequest | Blocks the sites on your blocklist during a session and shows Tomlock's block page. Rules are matched by the browser; Tomlock does not receive your browsing. |
notifications | Tells you when a phase ends. Capped at 2 a day, with quiet hours. A streak reminder is optional and off by default. |
offscreen | Plays the end-of-phase sound while the popup is closed. |
sidePanel | Shows the side panel (Today, plan, stats). |
tabs | Lets Tomlock see the address of your open tabs, on your device only, so it can switch a tab on a blocked site to the block page when a session starts and catch in-page navigation to a path rule. |
contextMenus | Adds two right-click menu items: “Open Tomlock side panel” and “Start a focus session”. They do not act on selected text, links or page content. |
Optional host permissions | Asked per site, only for sites you block, so Tomlock can show its own page instead of that site. |
Tomlock server address | Only if you sign in: one https address, the Tomlock backend. The extension makes no other network requests. |
The extension runs only code bundled in its package. It loads no remote code.
The use of information received from Chrome APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
4. What is stored when you sign in
Signing in is optional. When you link the extension to an account, the data below is stored on our servers. Authoritative game values (XP, gems, rare drops, plan) are decided by the server, which is why sessions are uploaded. The server also receives the IP address of signed-in requests, used briefly for security and rate limiting.
| Stored on our servers | Fields |
|---|---|
| Account profile | User ID, email address (from magic-link, one-time code or Google sign-in), display name, avatar file, time zone, plan (free, pro or lifetime) and plan end date, level, XP, gems, streak, best streak, streak freezes, last active day, tier, equipped cosmetics. |
| Settings | Your settings as one JSON document (up to 64 KB): presets, sounds, lock level, toggles, calm mode. Pro only: stored on the server only when sync is on. |
| Blocklists | Name, mode (block or allow), rules and active flag. Stored on the server only when sync is on (Pro). |
| Schedules (Pro) | Planned (not in version 1.0): name, days, start and end time, which blocklist, lock level, enabled. |
| Sessions | Client ID, device ID, start and end time, planned and focus minutes, kind, lock level, label, status, resisted count, combo, room session, verified flag, XP and gems awarded. Sessions are sent so the server can award XP and gems; the server rejects sessions older than 8 days and caps credited minutes per day. |
| Daily stats | Per day: focus minutes, sessions, completed, interrupted, resisted, XP. |
| Rewards ledger | Every XP and gem change with its source (session, quest, level, boss, room, drop, shop, bonus) and time. |
| Quests, badges, inventory, bosses | Quest progress per day and badges earned. Reserved for later updates, not used in version 1.0: gem-shop items owned and equipped, and weekly solo boss damage. |
| Devices | A name, browser, a SHA-256 hash of the device token (never the token), last seen time and revoked time, for each linked browser. |
| AI plans | If you save a plan: your goal, the list of items (title, minutes, lock level), whether it was made on device or in the cloud, and the time. |
| Rooms | Reserved for later updates, not used in version 1.0. Room name, emoji, owner, member count, each member's weekly focus minutes and sessions, boss state, invite token hashes with expiry, and room sessions you start (preset, minutes, start time, who accepted). |
| Room presence | Reserved for later updates, not used in version 1.0. Your status in a room (focusing, break, idle or offline) and when it ends. Your goal is included only if you choose to share it. Never site names or URLs. |
| Subscriptions | Payment provider name, customer ID, subscription ID, plan, status and current period end. Not your card details. |
| Webhook log | Event ID, provider, type and processed time for each payment event, so a replayed event does nothing. |
| AI usage (Pro) | A per-month count of cloud AI calls, to enforce 60 a month. Not the content. |
Each document is readable only by you (room data, once rooms ship, also by room members), except catalogs of quests, badges and shop items, which are public. Server credentials are never shipped in the extension, web app or this website. Version 1.0 does not include rooms, the gem shop or the weekly boss; tables for them exist on our server but are unused. If you link a different account later, your earlier local history stays on the device and is not uploaded to the new account unless you confirm.
5. Smart unblock and AI features
- What is used: for Smart unblock, the address of the blocked page (the query part removed), its title and your goal. Never the page content, never other tabs, never your history. The reason you type for a Gentle unlock is never sent.
- On device by default: where your browser supports built-in AI (Chrome with Gemini Nano), the request is handled by the browser on your device and nothing is sent to us.
- Cloud fallback (Pro only, setting off unless you enable it): if the on-device model is unavailable and you have enabled the setting, the same fields are sent through our server to our AI service provider [OWNER: name the AI provider here once confirmed]. The cloud planner similarly sends the goal, task list and minutes you typed. Limit: 60 calls a month.
- Logging: we do not log the content of these requests. We count calls per month. The provider processes the request under its own terms: [OWNER: confirm the provider's data-retention / zero-retention terms and add link] [OWNER: confirm the provider and that the "we do not log content" claim holds at the provider, T-068].
- If a verdict takes more than 5 seconds, Tomlock falls back to the normal block page for your lock level.
6. Analytics
The Tomlock extension version 1.0 contains no analytics and sends no usage events. This website may count install-button clicks without cookies or identifiers; it sets no tracking cookies.
7. Error reporting
The extension version 1.0 has no error reporting. [OWNER: state here any web app or website error tracking, with provider, only if it exists.]
8. Payments
Purchases are handled by a merchant of record, [MERCHANT OF RECORD NAME — TBD], which collects your payment details, billing address and tax information, charges you, and processes refunds. We never receive your card number. We receive your customer and subscription IDs, plan, status and period end (section 4). The merchant is an independent controller of the data it collects; see its privacy policy.
9. Who we share data with
- Hosting: our self-hosted backend runs on a server operated by us at [HOSTING PROVIDER / REGION]. Daily backups are kept for 14 days.
- AI service provider: only for the optional Pro cloud AI described in section 5.
- Merchant of record: for payments (section 8).
- Email delivery: [OWNER: confirm email provider, e.g. Brevo] sends sign-in links and account emails.
- Other room members: when rooms ship (planned): your display name, avatar, status and weekly focus minutes in rooms you join.
- We may disclose data if the law requires it. We do not sell or share personal data for advertising.
10. Retention and deletion
- Account data is kept while your account exists.
- Deletion: delete your account in the web app (Account and billing). Your data is queued for removal and removed from live systems within 24 hours. Backups age out within 14 days.
- Billing records may be kept by the merchant and by us as long as tax or accounting law requires.
- Cloud AI request content is not stored by us. Invite tokens, stale presence and expired items are cleaned up automatically.
- Local data is deleted when you uninstall the extension. A refund returns you to Free and does not delete your data.
11. Export your data
In the extension, Settings > Privacy > Export my data downloads your local data as JSON, and Settings > Privacy > Delete local data removes it from your device. Signed-in users can also export from the web app (Account and billing) or email [CONTACT EMAIL]. Export is available to every plan. Pro also includes CSV export of stats history.
12. Your rights
EEA, UK and similar (GDPR): you can ask for access, correction, deletion, restriction, portability, and object to processing, and you can withdraw consent (for example cloud AI) at any time. You may complain to your local data protection authority. Our legal bases are: contract (running your account and plan), consent (cloud AI), and legitimate interests (security, abuse prevention).
California (CCPA/CPRA) and similar: you can ask to know what we collect, to delete or correct it, and to opt out of sale or sharing. We do not sell or share personal information for cross-context behavioural advertising. We do not discriminate for exercising these rights.
To use any right, email [CONTACT EMAIL]. We respond within the time the applicable law requires.
13. International transfers
Our servers are in [HOSTING REGION]. Where data goes to a processor in another country (for example our AI service provider for optional cloud AI), we rely on [OWNER/LEGAL: transfer mechanism, e.g. Standard Contractual Clauses].
14. Children
Tomlock is not directed at children under [13 / 16 — legal to confirm per jurisdiction]. We do not knowingly collect personal data from them. If you believe a child has created an account, email [CONTACT EMAIL] and we will delete it. Strict Lock is not parental control; see the terms.
15. Security
Per-user document permissions, request rate limits, hashed device tokens, signed payment webhooks, and server credentials kept only in server environment variables. No system is perfectly secure.
16. Changes
We will post changes here and update the date. For material changes we will notify signed-in users. Release notes are in the changelog.
Last updated: 2026-10-05 (draft, version 0.1).