FocusArc

Security

Last updated: September 20, 2026

Security matters: FocusArc is designed with a local-first architecture. This page explains the current security approach and how to report suspected security vulnerabilities.

1. Security approach

FocusArc is an offline-first Chrome extension. The current build stores FocusArc application data locally in the browser and does not include a FocusArc backend, user account system, cloud synchronization service, remote code loader, analytics system, or payment flow.

FocusArc is designed to minimize the amount of information that leaves the user's device. The current version does not intentionally transmit locally stored FocusArc application data to a FocusArc-operated server.

2. Local data

FocusArc stores application information using Chrome's extension storage mechanisms. Depending on the features you use, this may include timer settings, goals, progress, rewards, preferences, scheduled blocks, Strict Mode settings, and domains that you choose to block.

Because this information is stored locally, FocusArc does not maintain a remote copy of your local application data and cannot provide cloud recovery for data that is deleted or lost from your browser profile.

3. Website access and blocking

FocusArc requests browser permissions required for its website-blocking functionality. The extension may use Chrome's extension APIs and declarative network request rules to apply blocking rules to websites or domains selected by the user.

The current version does not intentionally use website access to build a separate browsing-history profile, sell browsing information, or transmit browsing history to a FocusArc-operated server.

4. Security limitations

No software can be guaranteed to be completely secure. FocusArc's security depends on the extension code, Chrome's security model, installed browser extensions, the user's device, and the surrounding operating-system environment.

FocusArc should not be treated as a security boundary or as protection against malware, compromised devices, malicious browser extensions, or other threats outside the extension's control.

5. Reporting a vulnerability

If you discover a potential security vulnerability in FocusArc, please report it privately so that it can be investigated and, where appropriate, addressed before the details are made public.

Security reports can be sent to:

focusarcsupport@gmail.com

Please avoid publicly disclosing a suspected vulnerability before contacting the FocusArc operator. This helps reduce the risk of the vulnerability being used against other users while it is being investigated.

6. Helpful report details

When reporting a potential vulnerability, please include as much of the following information as reasonably possible:

7. Response to security reports

Reports will be reviewed based on the information provided. Depending on the nature and severity of a reported issue, FocusArc may investigate the issue, develop a fix, release an update, or provide additional information to the reporter.

Please do not include passwords, authentication credentials, private keys, or other sensitive information in a security report unless it is necessary to demonstrate the issue.

8. Updates

This Security page may be updated when FocusArc's architecture, security practices, or vulnerability-reporting process changes.

The "Last updated" date at the top of this page indicates when this page was most recently revised.