Complete transparency on how we handle your data. Your privacy is our top priority.
Locksy ("the Extension") is built with privacy at its core. This policy explains exactly what data we collect (spoiler: almost nothing), where it's stored (on your device only), and how you maintain complete control. We believe in radical transparency and your right to privacy.
One distinction matters throughout, and we would rather draw it clearly than let the strong claims below be read too broadly. The Extension is the software you install in your browser: it is local-only and involves no servers of ours. This website is an ordinary marketing and publishing site, and like nearly every site it does use a small number of third-party services. Every section below refers to the Extension unless it says otherwise; the website is covered separately at the end.
Stored locally on your device only
Your password is hashed using PBKDF2 with 600k iterations before storage. Military-grade security with 120 years crack resistance.
Whether the extension is currently active or inactive. That's it.
Which tabs are locked, plus the address of each locked page so you can be taken back to it after unlocking. Stored on your device only, deleted the moment a tab is unlocked or closed, and kept across a browser restart so restored tabs stay unlockable.
Failed login attempts and lockout timestamps for brute-force protection.
storagePurpose: Store your hashed password and settings locally
Note: Never leaves your device
tabsPurpose: Identify which tabs you want to lock
Note: We don't read page content
activeTabPurpose: Lock the current tab with one click
Note: Only tab ID, no content
notificationsPurpose: Confirm lock/unlock actions
Note: Just visual feedback
webNavigationPurpose: Keep lock active when tab refreshes
Note: Prevents bypass attempts
<all_urls>Host Permissions: Allows locking any tab. Only activates on tabs YOU explicitly lock. No automatic monitoring.
In the Extension
Separate from the Extension — and not local-only
It would be easy to let the claims above blur into an implication that this website is equally hermetic. It is not, and saying so plainly is more useful than a badge. Here is every third party involved in serving this site, and what each one receives.
The site is served from a commercial hosting platform, which keeps standard server logs — IP address, user agent, requested path, timestamp — for operational and abuse-prevention purposes. This is unavoidable for any hosted website; we do not build profiles from it or feed it into any analytics product.
We may display advertising through the Google AdSense network to fund the project. Google and its partners set cookies and may use them to serve ads based on your prior visits to this and other sites. You can opt out of personalised advertising at Google Ad Settings, the Network Advertising Initiative, or the Digital Advertising Alliance. Full detail, including cookie names and durations, is in our cookie policy. None of this touches the Extension, which contains no ad code whatsoever.
The forms on our contact and uninstall pages are handled by Web3Forms, a third-party relay that forwards whatever you submit — name, email address, message — to the developer's inbox. If you would rather not involve a relay, email us directly instead.
Support chat is provided by Crisp. Opening it loads their widget and creates a conversation record on their infrastructure containing what you type. It is optional — nothing is sent unless you start a chat.
The product demo is a YouTube embed. Playing it lets Google set cookies and register a view, on Google's terms rather than ours.
The strength checker and generator make no network requests at all — nothing you type leaves the page. The breach checker is the exception: it sends the address you enter to a third-party public breach index, because that lookup cannot be performed locally. That page states as much before you use it. The browser privacy score makes two requests to Google while it runs — an ad-script probe used to detect content blockers, and a STUN request the WebRTC leak test requires, which by design lets that STUN server observe your public IP. Neither result is sent to us or retained, and that page explains both in detail.
What we do not do on the website either: sell your data, run behavioural analytics of our own, or require an account to read anything here. If your browser sends a Global Privacy Control signal, ad networks subject to applicable privacy law are required to honour it as an opt-out request — our browser privacy score will tell you whether yours is sending one.
For users in the European Union:
For California residents:
Don't take our word for it. Review network request logs in your browser's developer console to verify that zero external communication is initiated by the extension.
Contact Supportvansh-121
Report privately via GitHub Security Advisories. Do not disclose publicly until patched.
Effective as of October 20, 2025
We built this to protect your privacy, not invade it. ❤️