Privacy Policy
Last updated: August 3, 2026
This policy covers the Raven web app and the Raven Chrome extension, which work together as one product. Starting a RavenLock session in either place, and the account you sign into, are shared between them.
1. Information we collect
Account information
When you create a Raven account, we collect your name, email address, and password. Authentication is handled by Supabase; we never see or store your password in plain text.
Usage data
- Focus session history — start/end times and duration of your RavenLock sessions
- The list of sites you've chosen to block
- Streaks, feathers, and focus statistics derived from your session history
- Friend group membership and activity you choose to share with a group
We do not collect your general browsing history — only whether a page you visited matched your own blocked-site list, which is evaluated locally in your browser.
2. How the Chrome extension uses its permissions
The extension requests the minimum permissions needed to block sites and run a tamper-resistant timer:
declarativeNetRequest— redirects navigation to sites on your blocked list to the extension's own blocked-screen page. Matching happens entirely inside Chrome's network stack; the extension does not read or transmit the pages you visit.host_permissions: <all_urls>— required bydeclarativeNetRequestso a block rule can match a site regardless of which domain you've added to your list.storage— saves your current session state (active/idle, time remaining, blocked domains) locally in your browser.alarms— runs the recurring check that verifies your session's remaining time against a trusted network clock and polls for sessions started on the web dashboard.activeTab— used incidentally by the extension UI; not used to read page content.incognito: spanning— lets your block rules also apply in Incognito windows if you separately enable "Allow in Incognito" for Raven yourself in Chrome's extension settings. We never require or check for this.
3. Third-party services
We use a small number of service providers to run Raven. They process data on our behalf and are contractually/technically restricted to that purpose — we do not sell data to them or anyone else.
- Supabase — hosts our database and handles authentication. See Supabase's privacy policy.
- WorldTimeAPI — the Chrome extension periodically checks the current UTC time from this public API to stop a session timer from being shortened by changing your computer's clock. No account or personal information is sent with this request.
4. What we don't do
- We don't sell your data.
- We don't show ads or use your data for ad targeting.
- We don't track your browsing outside of matching it against your own blocked-site list.
- We don't read the content of pages you visit.
5. Data retention & deletion
You can permanently delete your account and all associated data (profile, sessions, blocked sites, feathers, group memberships) at any time from Settings → Delete account in the web app.
6. Children's privacy
Raven is intended for users 13 and older. We do not knowingly collect data from children under 13.
7. Changes to this policy
If this policy changes, we'll update the "Last updated" date above. Material changes will be communicated in-app.
8. Contact us
Questions about this policy or your data? Email support@focusgate.site.