Privacy policy
StudyLock never collects a child's browsing history, page content, or search queries — this policy explains what it does store to run a parent-managed blocker. The only site name that ever leaves the device is one a child asks a parent to unblock.
What does StudyLock never collect?
- Browsing history and pages visited — never collected. Blocked attempts never leave the device as a list of sites.
- Page content and page titles — the extension has no content scripts and no scripting permission, and a permanent test fails the build if a page-reading call ever appears.
- Search queries — never collected.
The blocked-page screen itself sets no cookies, uses no web storage, and does not read the address of the page a child came from — it only reads the address of the site it is blocking, so it can show the child what triggered the block. The only site name that ever leaves the device is the one a child explicitly asks a parent to unblock.
What information does StudyLock collect?
StudyLock is a parent-managed Chrome blocker: a parent sets it up and manages it, and it enforces the rules on a child's own Chrome browser. It collects only what it needs to run that service.
From a parent
- An email address, used to sign in — either with a password, or by continuing with a Google account.
- For each child profile a parent creates: a name (up to 60 characters). Every profile starts on the same safe blocklist floor, which a parent then fine-tunes for that child.
- The block/allow rules and focus schedule a parent sets for each child profile.
From a child's Chrome extension
- A daily aggregate count for each child profile: minutes of active use and the number of pages blocked, stored as whole numbers against a date — never a list of sites.
- If a child taps "Ask a parent" on a blocked page, the single site name requested, together with whether a parent later approved or declined it.
- A device identifier for the paired Chrome browser. StudyLock's server stores only a one-way hash of this identifier — a scrambled version that cannot be turned back into the original — not the identifier itself.
- A one-time, six-digit pairing code used to link a new device, which expires ten minutes after it is issued.
Where does this information go?
What leaves the device
- Daily totalsMinutes of active use, and how many sites were blocked. Numbers only.
- One site nameOnly when your child taps ‘Ask a parent’ on a blocked page — the site they want opened.
What never leaves
- Browsing historyThe list of sites your child visited.
- Page contentAnything written on the pages they open.
- Search queriesWhat they typed into a search box.
The two things that do leave are tied to the child profile you created — that is how the dashboard knows whose they are. Neither is ever tied to a page or a history.
- Down — when a parent changes a child's rules or schedule, that change reaches the child's Chrome on its next check-in — usually within a few minutes.
- Up — the child's Chrome sends only the daily aggregate counts described above, and — if the child taps "Ask a parent" — the one site name requested. StudyLock's extension does not talk to any advertising network, analytics provider, or other third-party service; StudyLock's own server is the only destination.
StudyLock's own systems store this data to run the service — on Supabase (database) and Fly.io (hosting) as infrastructure providers — and StudyLock does not sell it or share it with advertisers or data brokers.
Payments. StudyLock does not process any payment today — the Family plan is not open yet, and no card detail has ever reached StudyLock's systems. When it opens, payment is handled by an independent payment processor acting as merchant of record. That processor collects and holds the billing details; what comes back to StudyLock is only a subscription status, a renewal date, and the processor's own customer and subscription reference codes. Card numbers are never sent to, stored by, or visible to StudyLock, and a child's information is never part of a payment — billing concerns the paying adult and the processor only.
Who can see a child's information?
Through the dashboard, only the parent or parents who share that child's profile can view it. If two parents share a profile using co-parent shared profiles, each can view the same information for that child. Access is scoped by family at the database level, so one family's information is never reachable from another family's sign-in session.
How long does StudyLock keep information?
- A child's profile, its rules, and its daily aggregate counts are kept for as long as the profile exists.
- A resolved site-access request — one a parent has approved or declined — is automatically deleted after 90 days.
- A pairing code is deleted, or simply expires, within ten minutes of being issued, whether or not it is used.
How can a parent delete this information?
You can permanently delete your account and its data at any time from the StudyLock dashboard, or by emailing privacy@studylock.org. Deleting an account removes every child profile in that family, along with its rules, aggregate counts, and site-access requests, and revokes sign-in for that account.
If a child's profile is shared between two parents through co-parent shared profiles, a parent who deletes their own account leaves the shared family — the profile and its data stay intact for the remaining parent. The profile itself is deleted only when the last parent sharing it deletes their account.
Is information collected directly from a child?
StudyLock is built for a parent or guardian to manage their own child's Chrome browser. A child does not sign up, does not create an account, and does not enter an email address or any other personal information into StudyLock directly — a parent creates the child's profile and chooses its name.
How is this information kept secure?
- All communication between the extension and StudyLock's server uses HTTPS.
- A paired device's identifier is stored as a one-way hash, never in plain form.
- A family's data is scoped by row-level access rules in StudyLock's database, so it is reachable only through that family's own sign-in.
Does StudyLock use cookies or third-party tracking?
The StudyLock dashboard uses a single first-party cookie to keep a parent signed in. It does not use third-party advertising or analytics cookies, and does not show ads or integrate with any ad network. The Chrome extension itself uses no cookies at all.
What happens if this policy changes?
StudyLock will update the "last updated" date at the top of this page whenever this policy changes, and will describe any material change on this page.
How can someone contact StudyLock about this policy?
Questions about this policy, or a request to access, correct, or delete information, can be sent to privacy@studylock.org.
Common questions
Does StudyLock read a child's browsing history?
No. The extension never reads page content — it has no content scripts and no scripting permission, and a CI test fails the build if that changes. The only site name it ever sends anywhere is the one a child explicitly asks a parent to unblock.
What can you delete, and how?
You can delete your account at any time from the StudyLock dashboard, or by emailing support. Deleting an account permanently removes every child profile in that family, along with its rules, aggregate counts, and site-access requests, and revokes sign-in.
Does a child's device send anything to a third party?
No. The Chrome extension talks only to StudyLock's own server — never to an advertising network, an analytics provider, or any other third party.
What happens to a device's data if the extension is uninstalled?
Uninstalling the extension clears everything Chrome stored for it on that device. Data already saved on StudyLock's server, such as daily aggregate counts, is removed only when a parent deletes the account, or per the retention periods described on this page.