Transparency Report · June 2026

Data Practices.
No Surprises.

A plain-English breakdown of every data type FocusScore collects, why we collect it, how long we keep it, and the controls you have. Zero jargon. Zero data sold.

See What We Collect →support@focusscore.ai

Last updated: June 2026 · Applies to FocusScore Chrome extension and web dashboard

0
Data ever sold
12
Data types collected
30 days
Deletion window
GDPR
Fully compliant
At a Glance

Our Data Commitments

No legal jargon. Here is exactly what we do and do not do with your data.

🚫

We NEVER do this

Keystroke or password logging
Browsing history collection
Screen recording or screenshots
Reading page text or form inputs
Selling data to advertisers or data brokers
Third-party tracking pixels or ad networks
Device fingerprinting
Cross-site tracking

We ALWAYS do this

Ask before we measure — a separate, unticked question
Treat an unanswered consent question as a refusal
Keep blocking and filtering working if you decline
Data encrypted in transit (TLS 1.3)
Data encrypted at rest (AES-256)
Pseudonymous UUID — no name or email unless you sign in
Local computation — page content and full web addresses never leave your browser
Right to export your data (JSON, any time)
Right to delete all data (any time, within 30 days)
GDPR & UK GDPR compliant
Full Inventory

What Data We Collect

Every data type we store, why we collect it, and how long we keep it.

Data TypeWhat exactlyWhy we need itRetentionPersonal?
Behaviour eventsEvent type (watch, scroll, tab-switch, idle), duration, timestampCore score calculation30–90 daysNo
Focus ScoreComputed 0–100 score, signal breakdownDashboard & reporting12–24 monthsNo
Platform breakdownPer-platform time and Shorts ratioDistraction analytics12–24 monthsNo
Websites visitedThe website name only (e.g. github.com) and time spent — never the full address, page path, search terms or page titleYour time-by-category breakdown30–90 daysYes
Activity switchesA daily count of how often you moved between types of activity — a number only, with no record of what you switched betweenAttention-fragmentation insights30–90 daysNo
Ads filteredA count of ad interruptions filtered, and which surface (web, YouTube, a social platform)Showing what the filter avoided, if you turn it on30–90 daysNo
Email addressOnly if you register an accountLogin, weekly report deliveryUntil deletedYes
Extension settingsBlock lists, toggle states, preferencesRemembering your configIn browser & server sync if logged inNo
Survey answersYour responses to the onboarding surveyPersonalising AI insightsUntil deletedYes
Focus sessionsTimer start/end, session name, completion statusBefore/after & trend reports12–24 monthsNo
Health & wellbeingDaily mood check-in (1–5 plus an optional note, encrypted at rest) and, if you connect a wearable, sleep and resting heart-rate summariesRelating rest and mood to your Focus Score12–24 months; wearable data is deleted as soon as you disconnect the sourceYes
Connected account tokensOAuth tokens for any social or calendar account you linkPublishing and calendar correlation you switch on12–24 months, or until you disconnect the accountYes
Push notification tokensA per-device token for the mobile appDelivering report-ready and re-engagement notifications12–24 months, or until you sign outYes
Feedback & support messagesAnything you choose to write to us in the appAnswering you and fixing what you report12–24 monthsYes
Consent recordsWhich permissions you granted or withdrew, and whenProving consent was freely given, as GDPR requires12–24 monthsYes

“Personal?” — whether this data could identify you directly. Non-personal data is always tied to a random UUID, never your name.

Health & wellbeing data is a special category under Art. 9 of the UK GDPR. It is off until you switch it on, each source opts in separately from your account terms and your tracking consent, each can be withdrawn on its own, and none of it is ever sold or shared. The full wording is in section 2 of the privacy policy.

How It Works

The Data Flow, Step by Step

From your browser to the dashboard — here is exactly what happens to your data at each stage.

🌐
STEP 1You browse

On YouTube, Facebook, Instagram, Twitter/X, Reddit, LinkedIn and TikTok the extension reads the page to measure watch time, scrolling and idle time. Everywhere else it records only the website name and how long you spent there — it does not read those pages at all.

🔬
STEP 2Signals extracted locally

Watch time, scroll speed, tab switches, and idle time are measured on-device. Web addresses are reduced to just the website name here, and the rest of the address is discarded before anything is sent. No page content leaves your browser.

🔢
STEP 3Score computed in extension

The weighted scoring engine calculates your Focus Score (0–100) using the five signals, on your device. Nothing about the page itself is read or sent — see the next step for what does leave.

☁️
STEP 4Anonymised data synced

The score, event counts, platform breakdown, and the website names with time spent are sent to our servers under your pseudonymous UUID. No personal data unless you're signed in.

📊
STEP 5Analytics built server-side

Trends, platform breakdowns, and AI suggestions are generated from your aggregated data and displayed in the dashboard and weekly report.

🤖
STEP 6AI insights via Groq

Personalised coaching tips and reports are generated by a third-party AI provider (Groq) from aggregated, non-identifying numbers only — never your content, URLs, name, or email. Falls back to rule-based tips if AI is unavailable.

Where your data lives

A deployment can declare the region it is hosted in. When it does, FocusScore stops sending any user content to a processor outside that region — AI coaching runs on the self-hosted model, and falls back to plain rule-based text rather than an overseas provider. The current posture of this deployment is readable at /compliance/residency — a declared region, whether egress is restricted, and every processor that can receive user content.

We are explicit that the hosting region is a declaration about infrastructure, which the application cannot prove on its own — what it enforces is that data does not leave it. Regional hosting for a specific customer is arranged as part of a contract; ask us.

Your Controls

You Are in Control

Five ways to manage or remove your data — no waiting, no forms, no dark patterns.

⬇️

Export your data

Download everything we hold in JSON format from the dashboard Settings page. Available any time.

🗑️

Delete your data

Delete all your data permanently from the dashboard or by emailing support@focusscore.ai. Processed within 30 days.

☑️

Grant or withdraw tracking consent

Behavioural tracking is off until you explicitly turn it on, and withdrawal sits in the same panel as the grant. Withdrawing also drops anything queued on your device but not yet sent.

⏸️

Disable tracking per platform

Toggle tracking on/off for each platform individually in the extension popup Settings tab.

🔕

Unsubscribe from emails

Unsubscribe from weekly reports at any time using the link in any email, or from the dashboard.

🧩

Remove the extension

Removing the extension stops all data collection immediately. Your server-side data remains until you request deletion.

Questions?

Questions About
Your Data?

Email support@focusscore.ai and we will respond within 72 hours. Data deletion requests are always honoured within 30 days.

Read Privacy Policy →Contact Us