Privacy Policy

Last updated July 31, 2026

1. Overview

Locked In (“we”, “us”, “our”) is a browser extension that helps you stay focused by blocking distracting sites, running focus timers, and tracking your goals. This policy explains what data the extension accesses, how it's used, and the choices you have.

2. What the Extension Stores

Locked In has no server and no backend. There is no account, no sign-in, and no sync. Everything the extension stores is written to Chrome's local storage on your own device:

  • Focus sessions — the session name, chosen duration, start/end time, pause state, and any tasks you attach to the session.
  • To-dos and notes — the to-do list and free-text notes you write in the extension.
  • Blocklist — the domains you choose to block. A starter list of common distracting sites is included by default and is fully editable.
  • Session history — a local record of each completed or stopped session (name, date, and time spent), used to show your streak and yearly totals.
  • Preferences — your theme, accent color, and default session length.

We never receive any of this. We operate no servers that could collect it.

3. How Site Blocking Works

When a session is active, Locked In converts your blocklist into Chrome declarativeNetRequestrules. Chrome itself enforces those rules — the extension does not inspect your traffic. When a request is blocked, the extension is notified of that specific blocked navigation and redirects the tab to its own “blocked” screen, using the domain only to display which site was blocked. This all happens on your device. Blocked domains are not logged, stored in your history, or transmitted anywhere.

4. How We Use This Information

  • To block the sites you've chosen, for the duration you set.
  • To run, pause, resume, and restore your focus timers.
  • To show your session history, streak, and yearly time locked in.
  • To notify you and play a sound when a session finishes.

5. What We Don't Do

  • We do not collect, receive, or store your data on any server.
  • We do not sell or share your data — we never receive it in the first place.
  • We do not use analytics, tracking scripts, or advertising.
  • We do not log or record your browsing history.
  • We do not read the content of pages you visit. The extension only learns the domain of a navigation that Chrome has already blocked under your own blocklist.

6. Third-Party Requests

In the interest of full disclosure: the extension's pages load a web font from Google Fonts (fonts.googleapis.com). Like any request to a third party, this means Google can see your IP address and that a font was requested. No personal data, session data, or blocklist information is included in that request. Aside from this font, the extension makes no external network requests.

7. Permissions We Request

Chrome will show you the following permissions on install:

  • storage — saves your sessions, to-dos, notes, blocklist, and preferences on your device.
  • declarativeNetRequest and host access — lets Chrome block the domains on your blocklist while a session is running.
  • webNavigation and tabs — detects when a navigation was blocked and redirects that tab to the blocked screen.
  • alarms — ends your focus session at the right time, even if the extension is idle.
  • notifications — shows the session-complete notice.
  • offscreen — plays the session-complete sound.
  • identity — currently declared but unused. No account or profile information is read or stored.

8. Data Storage & Security

All of your data lives in Chrome's storage.local on your device and never leaves your browser. There is no cloud backup and no cross-device sync, which means your data is only as secure as your device and Chrome profile — and it is not recoverable by us if you lose it.

9. Your Choices

You can edit or delete your sessions, to-dos, notes, and blocklist at any time inside the extension. Uninstalling Locked In removes all of its locally stored data from your browser. There is nothing for us to delete on request, because we hold no copy of it.

10. This Website

This marketing site is a static site. It sets no cookies, runs no analytics or tracking scripts, has no sign-up or contact forms, and loads its fonts from its own domain. It makes no third-party requests.

11. Children's Privacy

Locked In is not directed at children under 13 and we do not knowingly collect information from them. Since the extension collects no data at all, no such information is ever received.

12. Changes to This Policy

We may update this policy as the extension changes. Material changes will be reflected here with an updated revision date.

13. Contact

Questions about this policy or your data? Reach out at timislockedin@gmail.com.