Browser Extension Privacy Policy
Last updated: September 7, 2026
This policy covers only the Dopa Break browser extension. The Dopa Break app and website have their own Privacy Policy, which covers account data the extension has nothing to do with. If you only use the extension and never create a Dopa Break account, that other policy does not apply to you at all.
Who is responsible for this extension
Dopa Break is built and run by its founder, a sole trader in Pakistan trading as Dopa Break. Questions about this extension go to [email protected] or the Contact page, and a human reads them.
What data does this extension collect?
Stored only on your own device, always, whether or not you connect an account:
- Your settings. Whether the pause is turned on, how many seconds it lasts, how long the quiet period is before the same site can pause you again, and the list of extra sites you have added.
- Daily counts per site. For each site and each calendar day: how many times the pause was shown, how many times you continued, and how many times you walked away. That is the entire shape of the data, a day, a site name, and three small numbers. Counts older than 45 days are deleted automatically.
- A short cooldown timestamp per site. The last time you were paused on a given site, kept only for the length of your browser session, so you are not shown the pause again a few seconds later on the same site.
- A device token, only if you connect an account. An opaque code that lets this device submit counts for your account. It is not your Dopa Break password or session, and it cannot be used to read anything back or sign in anywhere.
Sent to Dopa Break's server, only if you choose to connect an account:
- The same daily counts described above: for each site you track, the calendar date and how many times the pause was shown, continued, or walked away from. Nothing more. This is sent roughly once an hour while the browser is running, and immediately the first time you connect. If the extension is offline, it simply tries again on the next hourly check; nothing is lost.
What this extension never collects
- No URLs. Only a bare site name such as "reddit.com", never the page you were on, never a query string, never a video ID or a username.
- No page titles and no page content. The extension never reads what is on the page beyond drawing its own pause on top of it.
- No fine-grained timestamps, even when an account is connected. The only time information ever sent is which calendar day an event happened on; the short-lived cooldown timestamp above never leaves your device at all.
- No browsing history beyond the sites you have chosen to pause.
- No location, no financial information, no health information, no personal communications, and no authentication information or credentials. Your Dopa Break password or session is never seen by, or sent from, the extension.
Does anything leave your device?
Only if you connect an account, and only the daily counts described above. With no account connected, this extension has no server connection of any kind, and nothing described above is ever transmitted, synced, or uploaded anywhere: everything lives in your browser's own local storage for as long as the extension is installed.
Connecting an account is optional and is never turned on for you. To connect: tap "Connect a Dopa Break account" in the popup, sign in on dopabreak.com, and confirm. From that point on, roughly once an hour, any counts not yet sent are sent to your account so you can see the same trend on the website. The pause itself works identically with or without an account connected.
Why the extension asks for each permission
- storage: to keep your settings, your daily counts, the short cooldown timestamp above, and, only if you connect an account, the device token, all on your device.
- alarms: to check once an hour whether there are counts waiting to be sent, and if so, and only if an account is connected, to send them. With no account connected, this hourly check does nothing: there is no device token to send with, so no network request is made.
- scripting: to turn on the pause for a site you add yourself, and only after you separately grant permission for that one site through your browser's own permission prompt.
- Host permissions for YouTube, Reddit, X, Instagram, TikTok and Facebook: so the pause can be drawn on those pages. The extension does not read anything else on those pages, and any site you add later is never granted access until you approve it yourself.
- Optional host permissions (declared broadly, granted narrowly): the extension declares the ability to later request access to any site, purely so that whichever specific site you decide to add is available to ask permission for. In practice it only ever requests the one origin you just typed in, through Chrome's own permission prompt; it never requests, and is never granted, access to every site at once.
Does this extension show ads, track you, or sell data?
No. It does not sell data, does not use anything it collects for purposes unrelated to the pause-and-count feature described here, and does not use anything it collects for creditworthiness or lending decisions. There are no ads in the extension, no cross-site tracking, and no analytics of any kind bundled into it.
How do I delete this data?
Uninstall the extension. Chrome and Edge both delete an extension's local storage completely when it is removed, including the device token, which stops any further sync immediately. If you had connected an account, the counts already sent before you uninstalled remain in that account, the same as any other Dopa Break data, until you delete your account from Settings in the app, which deletes them along with everything else. You do not need to contact anyone to uninstall the extension itself.
Children
This extension is meant for the same audience as the Dopa Break app: people aged 13 and over, consistent with the Terms of Use.
Changes to this policy
If what the extension collects ever changes, this page changes first, and the date at the top changes with it.
Contact
Questions about this policy? Email [email protected] or use the Contact page.