Privacy Policy
Lock-In is a focus tool. To do its job it needs a small account record: your handle, your blocklists, and your focus sessions. This page lists everything the apps store about you, why, for how long, and how to delete it. It describes what the software actually does, not what it might do.
What we never collect
- Browsing history, open tabs, or the addresses of pages you visit.
- The content of web pages, form entries, cookies, or keystrokes. The extension has no access to page content.
- Your location, contacts, files, or payment details.
- Analytics, advertising identifiers, or tracking. The apps contain no analytics or advertising code.
We do not sell your data, share it with advertisers, or use it for anything other than running Lock-In.
Your sign-in
Accounts are handled by Google Firebase Authentication. When you register or sign in, your email address and password are sent to Firebase. Your password is managed by Firebase and is never stored in the Lock-In database or visible to us. Firebase also sends your verification and password-reset emails.
What is stored in your account
Everything below lives in a Google Firebase Realtime Database hosted in Singapore (Google Cloud region asia-southeast1). Only you, while signed in, can read or change your own record, except the few items listed under What other users can see.
| What | Details and why | How long |
|---|---|---|
| Profile | Your handle (as displayed, and in lowercase), a copy of your email address, when the account was created, whether your email is verified, and onboarding progress. Needed to run the account and show your name. | Until you delete your account |
| App settings | Whether a focus session is running, your lock mode, whether the desktop app starts with Windows, and the date the daily counter last reset. | Until you delete your account |
| Current session | Whether a session is running, when it ends, the goal you typed for it, the sites and apps it blocks, and a random ID for the device that started it. Lets your phone, computer and extension follow the same session. | Replaced each time a session starts or ends |
| Session history | For each finished session: the goal you typed, minutes focused, time, and whether it was completed or ended early. An emergency disarm is logged as an ended session with zero minutes. Powers your dashboard. | Until you delete your account |
| Daily totals | Minutes focused per calendar day, used for streaks, plus a running minutes total. | Until you delete your account |
| Devices | For each device you use: a random device ID, the label “Windows Desktop” or “Web Browser”, minutes used today, and last sync time. No device names, hardware details or IP addresses are stored. | Cleared at the start of each new day |
| Blocklists | Website domains you choose to block (for sessions or permanently), default sites you have unblocked, and program names you block (for example discord.exe), with the random ID of the device that added each program. |
Until you remove them or delete your account |
| Friends | The user IDs of friends you add to The Pack. | Until you delete your account |
| Online status | Whether you are online, offline, or in a session, and when that last changed. | Replaced whenever it changes |
| Extension status | The time the extension last checked in, its version number, and “online”. Lets the desktop app warn you if the extension is not running. Only written once your profile exists. | Replaced every check-in (about every 30 seconds) |
| Google Calendar link | Only if you connect it: the Google Calendar embed link you paste, used to show your calendar in the desktop app. Anyone holding such a link may be able to view that calendar, so disconnect it when you no longer need it. | Until you disconnect it or delete your account |
| Handle reservation | A separate index that maps your lowercase handle to your user ID, so no one else can take the same handle. | Until you delete your account |
Accounts created with older versions may also hold fields those versions wrote, such as an emergency-unlock expiry time or a tab-refresh signal. Current versions do not write them, and Delete Account removes them along with everything else.
What other users can see
These items can be read by any signed-in Lock-In user. They contain no email address or activity details.
- Your display handle, so friends can see who you are in The Pack.
- Your online status (online, offline, or in a session) and when it last changed.
- The handle reservation, which shows that a handle is taken and which user ID holds it.
What stays on your device
- Chrome extension: your Lock-In user ID, kept in the extension’s local storage so it stays signed in. Page addresses are checked against your blocklist in memory and never saved or sent anywhere.
- Desktop app: a random device ID, your daily intentions and weekly plan (these are never uploaded), and a local file holding your blocklists and the current session’s end time so blocking survives a restart.
- Web app: a random device ID.
This local data is removed when you uninstall the app or extension, or clear the browser’s site data.
Services we rely on
- Google Firebase (Authentication and Realtime Database) stores your account and the data above.
- Vercel hosts this website and the Lock-In web app.
- GitHub hosts the desktop app downloads.
- Google Calendar is contacted only if you connect a calendar.
These providers process data only to provide their service. We do not share your data with anyone else.
Deleting your data
In the desktop app, open the Block Registry screen and use Delete my account in the Danger Zone. In one step it removes your entire account record (every item in the table above) and every handle reservation you hold. It then deletes your sign-in account.
If Firebase decides you have not signed in recently enough to delete the sign-in account, the app signs you out instead. Your data is already gone at that point, but your email address may remain registered for sign-in. Sign in again and repeat Delete Account, or email us and we will remove it.
Two things Delete Account cannot reach:
- If other users added you as a friend, their friend lists still contain your user ID. It is a random ID with no name or other data attached, and it no longer points to an account.
- Data stored on your own devices, listed above. Uninstall the app or extension to remove it.
The web app does not yet have a delete button. If you use Lock-In only on the web, email us and we will delete your account and data.
Children
Lock-In is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has registered, email us at caydencmy@gmail.com and we will delete the account and its data.
Changes to this policy
If what Lock-In stores changes, we will update this page and the date at the top before the change ships.
Contact
Questions, data requests, or deletion requests: caydencmy@gmail.com