Duofocus — Privacy Policy

Last updated: September 2026

Short version: By default, Duofocus stores everything locally on your device and sends nothing anywhere. An optional Cloud Sync feature (off by default) lets you view usage data remotely — it only activates when you explicitly link a device to an account.

What Duofocus does

Duofocus is a Chrome extension that blocks or allows websites on a time-based schedule (Study, Free, Sleep modes). Settings are password-protected. By default, all data stays on the device.

An optional Cloud Sync feature allows a parent or user to link the extension to an account at duofocus-server.vercel.app and view usage data remotely from any browser. Cloud Sync is disabled until you explicitly activate it using a pairing code.

Data stored locally (always)

DataPurposeStored where
Schedule & mode rulesControls which sites are blocked at which timeschrome.storage.local on your device
Password hash (salt + SHA-256)Protects settings from being changed without a passwordchrome.storage.local on your device
Usage statisticsTime-per-site tracking shown in the settings panelchrome.storage.local on your device

Cloud Sync (optional, off by default)

Cloud Sync is opt-in. Nothing is sent to any server unless you link the extension to an account using a pairing code in the Cloud tab of the extension settings.

When Cloud Sync is enabled, the following data is sent to Duofocus servers approximately once per minute:

DataPurposeStored where
Domain names and time spent (seconds per domain per day)Lets the parent dashboard show usage historyGoogle Firebase Firestore, linked to your account
Blocking schedule and mode rulesAllows remote schedule management from the dashboardGoogle Firebase Firestore, linked to your account
Device name (set by account holder)Identifies this device in the dashboardGoogle Firebase Firestore
A random device tokenAuthenticates this device to the API without requiring a passwordchrome.storage.local on your device

What is NOT sent even with Cloud Sync on:

Third-party services used for Cloud Sync:

How to disable Cloud Sync: Open the extension settings → Cloud tab → click Disconnect. All future syncing stops immediately. To delete your stored data, contact abhinav@starmesh.ai.

Account data (Cloud Sync accounts)

If you create an account at duofocus-server.vercel.app (required to use Cloud Sync), your Google account email address is stored via Firebase Authentication solely to identify your account. It is not shared, sold, or used for marketing.

What is never collected

Permissions used

PermissionWhy it's needed
storageSave schedule, rules, password hash, and usage stats locally
declarativeNetRequestBlock or allow sites according to the schedule — all rules run locally
alarmsCheck the schedule every minute to switch modes at the right time
tabsDetect the active tab for usage time tracking
webNavigationDetect redirect chains so the blocked page can show which domain triggered the block
<all_urls>Required to evaluate and block/allow any website based on the schedule

Children's privacy

Duofocus is designed to help parents manage screen time for children. The extension does not knowingly collect data from children directly. When Cloud Sync is used for parental monitoring, the account is held and managed by the parent, not the child.

Changes to this policy

If this policy changes, the updated version will be posted at this URL with a new "Last updated" date.

Contact

Questions or data deletion requests? Email abhinav@starmesh.ai