Skip to main content

Privacy Policy — Browser Extension

This privacy policy applies specifically to the AuraLock browser extension (Chrome, Firefox, and Chromium-based browsers). The extension is designed with privacy as a core principle: everything stays in your browser, and nothing is ever sent to any server.

Last updated: August 2026

01

What the Extension Stores

AuraLock stores everything locally in your browser’s extension storage. Nothing leaves your device.

  • Aura configurations — the name, purpose, blocked sites, duration, boundary type, and schedule for each Aura you create.
  • Active session state — which Aura is running, start time, end time, pause state, and drift count.
  • Presets — saved Aura templates for quick start from the popup.
  • Custom domains — any website domains you manually add to the site picker.
  • History and stats — completed session records, focus scores, streaks, daily drift counts, and lifetime statistics.
  • Journal entries — your mood ratings, text notes, and tags for each day.
  • Settings — theme preference, notification toggles, default duration, default boundary, and challenge difficulty.
  • Schedules — recurring Aura configurations with days, times, and autopilot settings.

All of this data is stored in chrome.storage.local (Chrome) or browser.storage.local (Firefox). It never leaves your browser.

02

What the Extension Does NOT Collect

The extension is built to protect your privacy, not to gather data about you.

  • No browsing history — the extension does not record which pages you visit.
  • No page content — the extension never reads the text, images, or HTML of any website.
  • No personal identity — there are no accounts, no sign-ups, and no user profiles.
  • No analytics or tracking — the extension does not include any analytics SDKs, tracking pixels, or telemetry.
  • No server communication — the extension never sends data to any external server or API.

The extension operates entirely on-device. There are no backend servers involved in its operation.

03

Why Each Permission Is Needed

The extension requests browser permissions only for features it actively uses. Here is what each permission does:

  • storage — saves your Auras, presets, history, journal, and settings locally in your browser’s extension storage.
  • alarms — schedules the session-end alarm so Auras terminate reliably even when the popup is closed. Also used for break reminders and scheduled Aura starts.
  • declarativeNetRequest — the browser’s built-in mechanism to redirect you away from blocked sites during an active focus session. All rules are created and managed locally.
  • declarativeNetRequestWithHostAccess — required alongside declarativeNetRequest to apply redirect rules across the websites you choose to block.
  • notifications — shows optional notifications when a focus session starts, completes, or when a scheduled Aura is about to begin.
  • tabs — opens the Active Aura page, settings page, and blocked page in new tabs. Also reads the current tab URL to check if the site should be blocked.
  • activeTab — accesses the current tab’s URL only when you interact with the extension (click the popup or open a page). Used to check if the current site should be blocked.
  • host permissions (<all_urls>) — required so blocking rules can redirect any website you select to block. The extension does not access, read, or transmit data from any website.

You can review and revoke any permission at any time from your browser’s extension settings. Revoking a permission may limit specific features.

04

How Blocking Works

The extension uses the browser’s native declarativeNetRequest API to redirect blocked sites. Here is the flow:

  • When you start an Aura, the extension creates redirect rules for each domain in your blocked list.
  • When you navigate to a blocked site, the browser itself (not the extension) redirects you to the “Waiting Outside” page.
  • The extension does not intercept, modify, or read any network requests — the browser handles everything natively.
  • When the session ends, all redirect rules are immediately removed.

This approach means the extension has minimal access to your browsing. The browser’s own API enforces the blocking, not custom code.

05

Data Retention and Deletion

You have full control over your data:

  • All data stays in your browser until you delete it. Nothing is backed up to any server.
  • Uninstalling the extension removes all stored data from your browser.
  • You can clear individual data types (history, journal, presets) from the Settings page.
  • You can export all your data as a JSON file at any time from the Settings page.
  • There is no account to close and no server-side data to request deletion of.
06

Third-Party Services

The AuraLock browser extension does not use any third-party services, SDKs, or APIs. There are no external network requests made by the extension.

The extension’s only network activity is the declarativeNetRequest redirects enforced by the browser itself. No data is transmitted to any third party.

07

Changes to This Policy

If this privacy policy is updated, the changes will be reflected on this page with a revised “Last updated” date. Continued use of the extension after changes constitutes acceptance of the updated policy.

08

Contact

If you have any questions about this policy or the extension’s data practices, email auralockapp@gmail.com. We will answer plainly.

If you have any questions about this policy or what the extension stores, email auralockapp@gmail.com. We will answer plainly.