FocusArc
Security
Last updated: September 20, 2026
1. Security approach
FocusArc is an offline-first Chrome extension. The current build stores FocusArc application data locally in the browser and does not include a FocusArc backend, user account system, cloud synchronization service, remote code loader, analytics system, or payment flow.
FocusArc is designed to minimize the amount of information that leaves the user's device. The current version does not intentionally transmit locally stored FocusArc application data to a FocusArc-operated server.
2. Local data
FocusArc stores application information using Chrome's extension storage mechanisms. Depending on the features you use, this may include timer settings, goals, progress, rewards, preferences, scheduled blocks, Strict Mode settings, and domains that you choose to block.
Because this information is stored locally, FocusArc does not maintain a remote copy of your local application data and cannot provide cloud recovery for data that is deleted or lost from your browser profile.
3. Website access and blocking
FocusArc requests browser permissions required for its website-blocking functionality. The extension may use Chrome's extension APIs and declarative network request rules to apply blocking rules to websites or domains selected by the user.
The current version does not intentionally use website access to build a separate browsing-history profile, sell browsing information, or transmit browsing history to a FocusArc-operated server.
4. Security limitations
No software can be guaranteed to be completely secure. FocusArc's security depends on the extension code, Chrome's security model, installed browser extensions, the user's device, and the surrounding operating-system environment.
FocusArc should not be treated as a security boundary or as protection against malware, compromised devices, malicious browser extensions, or other threats outside the extension's control.
5. Reporting a vulnerability
If you discover a potential security vulnerability in FocusArc, please report it privately so that it can be investigated and, where appropriate, addressed before the details are made public.
Security reports can be sent to:
Please avoid publicly disclosing a suspected vulnerability before contacting the FocusArc operator. This helps reduce the risk of the vulnerability being used against other users while it is being investigated.
6. Helpful report details
When reporting a potential vulnerability, please include as much of the following information as reasonably possible:
- A clear description of the suspected security issue.
- The potential impact of the issue.
- Steps required to reproduce the issue.
- The FocusArc version involved.
- The Chrome version and operating system involved, if relevant.
- Any relevant screenshots, logs, or technical information.
- A suggested mitigation or fix, if you have one.
7. Response to security reports
Reports will be reviewed based on the information provided. Depending on the nature and severity of a reported issue, FocusArc may investigate the issue, develop a fix, release an update, or provide additional information to the reporter.
Please do not include passwords, authentication credentials, private keys, or other sensitive information in a security report unless it is necessary to demonstrate the issue.
8. Updates
This Security page may be updated when FocusArc's architecture, security practices, or vulnerability-reporting process changes.
The "Last updated" date at the top of this page indicates when this page was most recently revised.