Back to SuperBlur
Privacy Policy

Your data, accounted for.

Last updated · October 4, 2026

Short version

The extension never collects, sends, or shares anything it blurs. We hold account and payment information — never the contents of your pages.

The rest of this page is the long version, for the curious and the careful.

01

What we collect

Page detection stays local.

Blurring runs entirely on your computer. The pages you visit, the values that get blurred, your rules and settings — none of it is sent to us. The extension has no analytics, telemetry or error reporting tool. An activated license contains your purchase email.

If you buy Pro: the minimum billing needs.

When you subscribe we receive and store your email address, your purchase history (plan, amount, dates), and the license codes we issue you. Your card and payment details go to Dodo Payments directly and never touch our servers. The extension contacts our server for account connection and license refresh — that request carries your signed code, including your purchase email. Like other web requests, the server also receives connection metadata such as your IP address. When you choose Sign in with Google, Google provides your verified email, name and account identifier. We store those details, hashed login session tokens and temporary connection requests to connect your subscription to the extension. Sign-in uses a secure, HTTP-only session cookie; Google passwords are never sent to us.

02

What is stored on your device

SuperBlur keeps settings in local and sync extension storage. Saved selections include their site and page view so they apply in the right place. Account-specific profile snapshots stay on this device; signing out hides them and signing back in restores them. This is not protection against someone with access to your browser files.

  • Your preferences

    Whether SuperBlur is on or off, and your blur intensity. Stored in chrome.storage.sync, which Chrome syncs across your own signed-in devices only.

  • Your always-show list

    When you click “always show this” on a covered value, we store a SHA-256 hash, a short display hint and scope information inchrome.storage.local. Hashes are not encryption; predictable values can be guessed.

  • Your custom rules (Pro only)

    The regular expressions you add in settings. Stored inchrome.storage.sync. This includes regex text and optional host/path scope, but not detected matches.

  • Manual masks, profiles and backups

    Saved masks include site/path and element or rectangle coordinates. Selected-text rules can contain the selected text itself. Local profiles and exported backups may contain these settings; keep backups private. License codes are excluded from exports.

  • Your Pro code (if activated)

    The code itself, stored in chrome.storage.sync, so the extension can check on every page load that you still have access.

Browser sync may send sync settings and your license to your browser provider when enabled. We receive your license during refresh, but do not receive your blur rules or page content.

03

Permissions the extension asks for

SuperBlur requests six browser permissions, and each one is there for a specific reason:

  • "storage"

    So the extension can remember your settings and rules between browser restarts.

  • "activeTab"

    For user-invoked controls on the current tab. Separately, content scripts have access to supported webpages across tabs so local protection can run there.

  • "tabs"

    So a screen share or idle event can blur every open tab, and keyboard shortcuts reach the right one. Only tab identifiers for routing — no contents.

  • "idle"

    So the optional “blur when I step away” trigger knows when you have been inactive. We learn idle/active — nothing else.

  • "alarms"

    So a paid license can quietly refresh itself before it expires, instead of logging you out every month.

  • "contextMenus"

    So “Blur selection” appears when you right-click selected text.

The extension also declares content-script access to all supported web URLs, including frames. Browser pages and other restricted surfaces are not accessible.

04

Things we do not do

  • We never see the pages you visit or the values SuperBlur hides — blurring is 100% on-device.
  • Google handles sign-in; we never receive your Google password.
  • We do not have analytics, telemetry, or usage metrics in the extension.
  • The extension does not send page contents or error reports to monitoring services.
  • We do not have advertising SDKs, tracking pixels, or cross-site trackers.
  • We do not see or store your card number — payment details go directly to our payment processor.
  • We do not sell or rent your email or purchase data. Service providers process it to deliver billing, licensing and email.
05

Third-party services

Detection does not use a remote service. Browser sync is provided by your browser vendor. The website and paid licensing use a small set of providers, each for one job:

Dodo Payments (checkout & billing)

Our payment provider and merchant of record. When you buy Pro, Dodo’s secure hosted checkout collects your payment details directly — they process the payment, handle local currency and taxes, and tell us only that a charge succeeded, for which email, and for how much. We never see card numbers. See Dodo Payments’ own privacy policy for how they handle payment data.

SendDart (transactional email)

Sends the emails you’d expect after paying: your Pro code after a purchase or renewal, and support-issued codes. It receives your email address and the message content — nothing else. No marketing lists, no tracking pixels.

Datadog (website monitoring)

Our website sends page paths, event counts, application versions, error categories and checkout operation status to Datadog to diagnose failures. These reports exclude query strings, form contents, account emails, payment details, license codes and raw exception messages. We do not record sessions or collect extension browsing activity.

Vercel, Neon & Upstash (infrastructure)

This website runs on Vercel. Purchase records and issued license codes live in a Neon Postgres database. Upstash Redis holds short-lived operational data: rate-limit counters, a 30-minute handoff that delivers your code to the checkout success page, and an issuance log (email, time, IP address, browser user-agent) we keep to detect abuse of the licensing endpoints.

Web3Forms (feedback form only)

If you submit the feedback form at /feedback, your message is forwarded to our email inbox through Web3Forms. They see your submission transiently to pass it on to us.

06

How long we keep things

Data stored by the extension stays in your browser until you delete it or uninstall SuperBlur. Purchase records are kept for as long as your subscription is active and afterwards for as long as tax and accounting rules require. The abuse-prevention issuance log is operational data we periodically clear. Feedback you submit lands in our email inbox and we keep it as long as we keep our other email — until we clean it out.

07

Your rights

Everything the extension knows about you is inside your own browser — you can see it, export it, or wipe it by removing the extension. For the purchase data we do hold (your email, purchase history, issued codes), email us and we will export or delete it, subject to records we are legally required to keep. Deleting your data ends our ability to refresh your license.

08

Children

SuperBlur is not directed at children under 13. We do not knowingly collect information from anyone, which by extension includes children.

09

Changes to this policy

If we change this policy, we will update the date at the top of this page. Material changes will be called out at install or on the next popup open, if possible.

10

Contact

Questions, concerns, or corrections? Email achleshavarshney@gmail.com or use the feedback form.

Privacy Policy — SuperBlur