Privacy
Draft. This is placeholder text for the first release of Lock In Hour. It describes how the product is being built; the final policy will be published before launch.
The short version
- Camera frames are processed in your browser and are never uploaded.
- Only events leave your device: their type, start time, end time and the Dive they belong to (for example “phone, 09:12:04 to 09:13:40”).
- The server computes every score from those events. Your browser never sends a score.
- You can delete your account and all your data from Settings.
Account data from X
You sign in with X. We store your X user ID, handle, display name and avatar, plus the time zone your browser reports. Your handle, avatar, level, streak, Deep Score and Fathoms appear on the public Depth Chart, on public Dive Log pages and on share cards. The daily Depth Chart post on X tags only people who opted in (off by default).
Camera and Sonar
- Sonar (the phone check) and the presence check run on your laptop. Frames live only in memory and are never stored or sent.
- The vision library we use (Google MediaPipe) contains usage telemetry. Our Content Security Policy blocks every connection it could make, on every page and worker, so it cannot send anything.
- The Sonar detection code will be published as open source.
Timelapse
Recording starts only if you say yes to “Record this Dive for a timelapse?”, which is asked every Dive and defaults to No. Frames and the finished video stay on your laptop (in your browser’s local storage) until you export or delete them. Unexported footage is deleted after 7 days, the next time you open Lock In Hour.
Tabs and plan matching
- Only during a Dive, the extension sends the active tab’s domain and title. Never full web addresses, page content, or anything outside a Dive.
- To label a tab on-plan or off-plan, the domain, the title and your Dive plan are sent in transit to Anthropic’s API (a small Claude model). Under Anthropic’s standard terms, API inputs and outputs may be retained for up to 30 days.
- We store a hash of the title, never the title itself. We keep the domain only when the tab was off-plan.
- Outside Dives, the extension only keeps its connection to the web app.
Blocking and notifications
- During a Dive the extension blocks x.com, twitter.com, instagram.com, tiktok.com, facebook.com, reddit.com, snapchat.com unless your Dive plan needs one of them.
- Muting Chrome notifications during a Dive is an opt-in toggle, off by default. When it is on, Chrome blocks site notifications for the Dive and restores your previous setting afterwards. Blocking notifications can make Chrome drop sites’ existing web-push subscriptions, so some sites may ask you to turn their notifications back on.
Who else sees your data
- Buddies (people whose Dive overlapped with yours) see your Dive plan and proof, and can flag a proof.
- Service providers: Supabase (database and sign-in), Vercel (hosting), X (sign-in and the daily post) and Anthropic (plan matching).
Deleting your data
Deleting your account removes your profile, Dives and events from our database, clears timelapse footage stored by this browser and clears the extension’s storage. Posts already published on X cannot be removed by us.
Contact
Contact details will be added before launch.