Last updated: September 2026
Duofocus is a Chrome extension that blocks or allows websites on a time-based schedule (Study, Free, Sleep modes). Settings are password-protected. By default, all data stays on the device.
An optional Cloud Sync feature allows a parent or user to link the extension to an account at duofocus-server.vercel.app and view usage data remotely from any browser. Cloud Sync is disabled until you explicitly activate it using a pairing code.
| Data | Purpose | Stored where |
|---|---|---|
| Schedule & mode rules | Controls which sites are blocked at which times | chrome.storage.local on your device |
| Password hash (salt + SHA-256) | Protects settings from being changed without a password | chrome.storage.local on your device |
| Usage statistics | Time-per-site tracking shown in the settings panel | chrome.storage.local on your device |
When Cloud Sync is enabled, the following data is sent to Duofocus servers approximately once per minute:
| Data | Purpose | Stored where |
|---|---|---|
| Domain names and time spent (seconds per domain per day) | Lets the parent dashboard show usage history | Google Firebase Firestore, linked to your account |
| Blocking schedule and mode rules | Allows remote schedule management from the dashboard | Google Firebase Firestore, linked to your account |
| Device name (set by account holder) | Identifies this device in the dashboard | Google Firebase Firestore |
| A random device token | Authenticates this device to the API without requiring a password | chrome.storage.local on your device |
What is NOT sent even with Cloud Sync on:
youtube.com)Third-party services used for Cloud Sync:
How to disable Cloud Sync: Open the extension settings → Cloud tab → click Disconnect. All future syncing stops immediately. To delete your stored data, contact abhinav@starmesh.ai.
If you create an account at duofocus-server.vercel.app (required to use Cloud Sync), your Google account email address is stored via Firebase Authentication solely to identify your account. It is not shared, sold, or used for marketing.
| Permission | Why it's needed |
|---|---|
| storage | Save schedule, rules, password hash, and usage stats locally |
| declarativeNetRequest | Block or allow sites according to the schedule — all rules run locally |
| alarms | Check the schedule every minute to switch modes at the right time |
| tabs | Detect the active tab for usage time tracking |
| webNavigation | Detect redirect chains so the blocked page can show which domain triggered the block |
| <all_urls> | Required to evaluate and block/allow any website based on the schedule |
Duofocus is designed to help parents manage screen time for children. The extension does not knowingly collect data from children directly. When Cloud Sync is used for parental monitoring, the account is held and managed by the parent, not the child.
If this policy changes, the updated version will be posted at this URL with a new "Last updated" date.
Questions or data deletion requests? Email abhinav@starmesh.ai