Privacy policy and terms

How Web Lock collects, stores and uses your data.

What data we collect

The sites you lock and your passwords stay in your browser. They are never sent to us, unless you turn on Sync in Web Lock Pro (below).

We collect your email address when you install and set up the extension. We only collect it so you can reset your password if you need to. If you answer the survey when you uninstall, we keep what you write. Our server also records IP addresses with requests, to limit abuse such as repeated code requests.

Campaign links

When you follow one of our campaign links (weblock.site/c/…), we set a cookie on weblock.site that holds a random id for that visit, nothing about you. It lasts up to 30 days. When you install Web Lock, it makes a random install id and opens weblock.site, which reads the cookie so we can tell which link brought the install. We count visits once a day per visitor using a one-way hash, never your address. The install id is also sent when you set up Web Lock and when you uninstall it, so we can tell how many people each link brought, whether they kept Web Lock, and whether they bought Pro.

Feedback

When you send feedback, we keep what you write and the Web Lock version and browser you sent it from (such as "Web Lock 2.0.1 · Chrome on macOS"), so we can look into problems. If you leave an email, we keep it to reply to you. If you sign in to send it (the same account Pro uses, free or not), we also keep our replies so you can read them in Web Lock, and email you a copy of each one.

Web Lock Pro

Pro is optional. Web Lock works without an account, and none of this applies unless you sign in to one.

If you sign in to a Pro account, we also keep:

  • your account's email address, which can differ from your recovery email;
  • one session for each browser you sign in on, with a label such as "Chrome on macOS" so you can tell them apart;
  • your plan: which one you bought, whether it's active, and when it renews or ends.

If you turn on Sync, we also keep a copy of your Web Lock settings so your browsers can share them: the sites you lock and block, your schedules, your recovery email, your other settings, and your Web Lock password and any per-site passwords or PINs as one-way hashes, never as the passwords themselves (We can never read the passwords). Sync is off until you turn it on, and a browser with its own separate password doesn't send that password.

Payments are handled by Stripe. You enter your card or other payment details on Stripe's page, never on ours, and we never see or store them. Stripe shares with us your plan, the amount paid and a customer reference that links your payments to your account. Stripe's privacy policy covers what it collects to process the payment.

How we use your data

We use your email address to verify your identity when you, or someone else, tries to reset your Web Lock password, to send you codes to sign in to your account, and to reply when you write to us. We use your plan to decide which Pro features your extension can use, and your synced settings only to send them to your other browsers. We don't use your data for advertising, and we don't sell it.

Where your data is stored

Collected data is stored securely on Blog Desire's server. We share it with no one except Stripe, and only what's needed to take a Pro payment. Stripe keeps its own records of payments, as the law requires of payment processors.

Deleting your data

To delete your synced settings, turn off Sync in Web Lock and choose to delete the synced copy. Your browsers keep their own settings.

To have your data or your Pro account deleted, email [email protected] from the address you used. We'll delete it, except payment records we have to keep by law. Cancel an active subscription first, or ask us to cancel it in the same email.

Changes to this policy

If we change our privacy policy, we will post the changes on this page so you always know what information we collect and how we use it. Changes take effect when they are posted here.

Last updated September 30, 2026