Privacy Policy for LockedIn
Last Updated: July 29, 2026
LockedIn is designed to help you stay focused while browsing. We value your privacy and believe in keeping your data on your device as much as possible. This privacy policy explains what data we collect, how it is used, and how it is protected.
What Data We Collect
- Page Context: After you provide in-product consent and start a focus session, LockedIn reads the active page's URL, title, headings, metadata, and a bounded visible-text snippet to determine whether the page supports your goal. Scanning stops when the session ends.
- Focus Sessions: We store your focus goal, rules, visited URLs and titles, classification decisions, timer durations, and productivity statistics so you can review your session history.
- API Keys: If you configure Google Gemini or Groq, the key is stored in Chrome's extension storage in your local browser profile. LockedIn does not transmit your key anywhere except the provider you selected. Do not configure a key in a Chrome profile shared with people you do not trust.
How We Use Your Data
- Local Processing: The bundled local model processes page signals on your device. In Local-only mode, page context is not sent to a cloud classification provider.
- Cloud Processing (Optional): If you choose Hybrid or AI-only and configure a provider, LockedIn sends your focus goal during session preparation. Hybrid also sends the current page's URL, title, headings, metadata, and bounded text snippet when the local model marks the page off-goal or uncertain. AI-only sends those signals for every non-rule classification. Requests go directly from the extension to Google Gemini or Groq over HTTPS.
- Stored Diagnostics: Session history retains URLs, titles, decisions, scores, reasons, and model-status metadata. Raw visible-text snippets and cloud prompt or response bodies are not retained in completed-session logs.
Where Data Is Stored
Session history, focus rules, API keys, consent records, and settings are stored locally using Chrome extension storage. Temporary model caches and active-session state use Chrome session storage. We do not operate a central server or database for browsing activity, and we do not use your activity for advertising or cross-site tracking.
Data Sharing and Selling
We do not sell or rent your data. When you explicitly configure and use Hybrid or AI-only mode, the data described above is shared only with your selected classification provider, Google Gemini or Groq, to provide the user-facing focus classification feature. Those providers process requests under their own terms and privacy policies.
Data Retention
Your session history, settings, consent record, and API keys remain in local browser storage until you clear them or uninstall the extension. Temporary session caches are cleared by Chrome when the extension session ends. You can clear all persistent extension data from Advanced Settings.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. LockedIn uses page and browsing information only to provide and improve its disclosed focus-classification and session-tracking purpose.
Changes to This Policy
If we update this policy, we will notify you by updating the "Last Updated" date at the top of this page.
Permissions We Request
To function properly, LockedIn requires certain browser permissions. Here is why we need them:
- Website access (
<all_urls>, requested when you start): To extract page signals and display an on-page distraction notice during an active focus session. This access is requested after the in-product disclosure rather than at installation.
- Tabs: To read tab URLs/titles for AI classification, and to close or group tabs programmatically when you actively block a site or request grouping.
- Scripting: To dynamically inject the overlay into tabs that were already open before the extension started.
- Web Navigation: To detect when modern single-page applications (SPAs) change pages without a full reload, so we can re-evaluate relevance.
- Idle: To detect when you are away from your keyboard so the focus timer and active usage tracking can be automatically paused.
- Declarative Net Request: To enforce dynamic, temporary blocks on distracting websites when your focus session is active.
- Tab Groups: To automatically group open tabs by relevance category (e.g., "Productive", "Distracting") to help you visually organize your workspace.
- Offscreen: To run the local ONNX ML model inference engine (Transformers.js) in a separate document context, as WebAssembly cannot be executed directly in the service worker.
- Side Panel: To provide a persistent, real-time focus session monitoring panel that stays open alongside your workflow.
- Storage: To persist your focus rules, session history, advanced settings, and API keys locally on your device.
- Alarms: To maintain a reliable periodic heartbeat for timer accuracy and to automatically end focus sessions in the background.
- Google Generative Language and Groq APIs: Host permissions are used only when you configure the corresponding provider and select Hybrid or AI-only classification.
Contact Us
If you have any questions about this privacy policy, please contact me at kushaan.koul@gmail.com.