Focus — privacy policy
Last updated 17 August 2026 · Focus browser extension · © Andrea Novero · GPL-3.0
Focus is a research tool. It is part of doctoral research at the University of Padova on sustained attention while studying and working. If you are using it as a study participant, the consent form you signed governs the research use of your data and takes precedence over this page wherever it is more specific.
The extension is free software, so every claim here can be checked in the source rather than taken on trust.
What Focus records
Focus measures whether you are working, not what you are working on. Its unit of measurement is a "heartbeat" — one second of detected activity on a page or a program you have put on your own whitelist.
- Activity counts — points earned for focus, points lost to going idle, and the daily totals they add up to.
- Your whitelists — the domain strings (e.g.
arxiv.org) and program identifiers (e.g.code) you chose to have counted as work. These are lists you wrote; they are not a browsing history. - Your account email, from Google sign-in, and your time zone.
- Team and competition membership, if you join one.
What Focus never records
None of the following is stored, transmitted or logged anywhere, by design:
- No browsing history. The URL of a page you visit is never sent to or stored on any server. Nothing records that you opened a page, only that activity happened on a whitelisted one.
- No page content — no text, no form input, no keystrokes. The content scripts listen for the fact of a mouse move, key press or scroll, never for which key.
- No window titles. The optional desktop agent reads the foreground program's identifier and refuses to report titles, because a title leaks document names, message contents and page titles.
- No analytics, no advertising, no third-party trackers, no sale of data, and no use of your data for anything other than the research described in your consent form.
Where data goes
| Feature | What leaves your machine | To whom |
|---|---|---|
| Sync (requires sign-in) |
Score deltas, daily totals, your two whitelists, your time zone, your email address | The study's Supabase database, hosted in the EU. Row-level security means a request signed by your account can only reach your own rows. |
| Teams & competitions (opt-in, per team) |
The same figures, plus your whitelisted domains, become visible to people you share a team or an accepted friendship with | Those people, and nobody else. Joining is deliberate and needs a password; leaving stops it. |
| Phone nudge (off unless you pair a phone) |
A fixed message ("come back — this lapse is about to cost N points"), encrypted so that only your phone can read it | Your phone's push service (Google FCM on Android, Apple on iPhone), which relays bytes it cannot decrypt. It is sent by your browser; no Focus server learns that a nudge happened. |
| AI page classifier (off by default) |
The URL and title of a page you are on, if and only if you switch this on | The address you configure. The default is a model on your own
machine (localhost), so nothing leaves it. Point it at a remote
service and that service receives them. |
| Desktop agent (optional, separate install) |
Nothing. It answers one question — which program is in front — to
127.0.0.1 only, refuses requests from web pages, and writes
nothing to disk. |
No-one. It has no account, no session and no network beyond loopback. |
With no account signed in, Focus is entirely local: everything lives in
chrome.storage.local on your own computer.
Pairing a phone
The QR code you scan carries a one-time code and your browser's own public key. The page you open on the phone hands back a push subscription, which lives on the server for at most ten minutes and is deleted the moment your computer collects it. After that the pairing exists only on your two devices. The signing key is generated on your machine and never uploaded — which is the reason no server can send you a notification, and therefore why no server can know when you drifted.
Permissions, and why each exists
- Access to the pages you visit — the companion has to be drawable on any page you decide counts as work, and that set is yours to write, so it cannot be a fixed list. The scripts run everywhere but act only on whitelisted pages.
- Tabs — to tell whether the page in front is on your whitelist.
- Idle — to notice you have stopped, which is the entire point.
- Sign-in (identity) — Google sign-in, requesting only
openid email profile. Focus never reads your mail, contacts, files or calendar. - Downloads — to hand you the desktop-agent installer that ships inside the extension. Nothing else is ever downloaded.
- Storage, windows, alarms, display info, scripting — settings, the floating companion window and its placement, and the timers that survive the service worker being suspended.
127.0.0.1:47317— the optional desktop agent.
Your data, your call
- Stop syncing: sign out. The extension keeps working, locally.
- Stop being visible to others: leave the team or competition.
- Stop the nudges: unpair the phone, or turn the switch off.
- Delete everything: ask, and your rows are deleted. Uninstalling the extension removes the local copy immediately.
Questions, corrections, or a deletion request: andrea9roa9@gmail.com.
Source, issue tracker and the full data model: github.com/noveroandrea/focus