Privacy-first by design

Privacy Policy

Your brain is yours. So is your data. Here's exactly how Brain Rest handles it.

Last updated: July 2, 2026

Privacy at a Glance

Brain Rest is built privacy-first. Here is the short version:

  • Local first. Detailed, session-level data stays on your device. Only day-level summaries sync to your account.
  • Encrypted in transit and at rest. Synced data travels over HTTPS/TLS and is encrypted at rest by Supabase, with access locked to your account.
  • No selling, no ads. We never sell your data or use it for advertising.
  • You control it. Export, delete, or modify your data anytime.

Who We Are

Brain Rest is built and run by an independent solo developer. There is no registered company behind it. For the purposes of GDPR and similar laws, the developer of Brain Rest is the data controller for the information described here.

You can reach us any time at support@brainrest.pro.

What We Collect

Screen-time activity

  • Time spent: Duration on each website you visit.
  • Domain names: The websites you visit (domains, not full URLs).
  • Session times: Start and end of browsing sessions.
  • Activity status: Whether you are active or idle.

Detailed, session-level activity is kept locally on your device. When you are signed in, only day-level summaries are uploaded to your account: per-domain figures (time spent, visit count, last visited) and daily totals (total time, number of websites). Your individual sessions are never uploaded.

Account information

An account is required to track and sync your data. We use Supabase for authentication (email and password, or Google sign-in).

  • Email address: For your account, sync, recovery, and transactional emails.
  • Display name: Your chosen profile name.

Browsing history

Brain Rest does not request Chrome's history permission and never reads your browser history. Screen-time tracking (described above) is based only on the tab you are actively using while the extension is running. Detailed activity stays on your device; beyond the day-level summaries synced to your own account, it is never uploaded to us or anyone else — and it is never included in the optional usage analytics described below.

Product usage analytics (optional)

To understand which features are used and improve Brain Rest, we collect a limited set of usage events through PostHog (see Sub-processors). These events are pseudonymous — tied to a random identifier and, when you are signed in, your account id, never your name or email — and cover things like feature usage counts, durations, setting choices, your extension version, and your plan tier. They never include the websites you visit, URLs, page titles, or your browsing history, and precise location lookup is disabled. You can turn this off anytime in Settings → Tracking Settings → "Share usage analytics"; opting out also discards any events not yet sent.

What we never collect

  • We never collect your personal files, keystrokes, or sensitive form data.
  • We never store your password in readable form. Authentication is handled by our provider (Supabase) using industry-standard hashing, so we never see your actual password.

How We Use Your Data

  • Analytics & insights: Generate personal productivity reports and usage patterns visible only to you.
  • Smart notifications: Send break reminders and limit alerts based on your configured preferences.
  • Website blocking: Enforce your self-imposed restrictions on distracting websites.
  • Cross-device sync: Keep your day-level summaries and settings in sync across your devices while signed in.
  • Product improvement: Measure which features are used via optional, pseudonymous usage analytics (see What We Collect) to guide development.

Data Storage & Security

Local storage

  • Detailed, session-level screen-time data stays on your device.
  • Stored using Chrome's storage API.
  • Uninstalling the extension removes this local data. Note that data already synced to your cloud account is not affected by uninstalling (see Data Deletion).

Cloud sync (when signed in)

  • Only day-level summaries are uploaded — never your individual browsing sessions, and never your browsing history.
  • Stored in your own private account on Supabase; row-level security ensures only you can read it.
  • Syncs only while you are signed in; sign out to stop syncing.

How synced data is protected

Synced data is encrypted in transit (HTTPS/TLS) and at rest by our infrastructure provider (Supabase), with access restricted to your account via row-level security. We do not use end-to-end encryption, and we do not encrypt data on the client before it is uploaded. Authentication is handled by Supabase, and we keep our extension and dependencies up to date.

Sub-processors

We rely on a small number of trusted providers to run Brain Rest. We never sell your data, and we don't grant anyone access beyond what is needed to provide the service. Each provider listed below processes only the data described and is bound by its own privacy commitments.

  • Supabase — authentication and database. Stores your email, display name, and day-level screen-time summaries. Privacy policy.
  • Polar — payments and merchant of record for Brain Rest Pro. At checkout it receives your email and your Supabase user id, and it handles your payment details. Privacy policy.
  • PostHog — product usage analytics, hosted in the United States (us.i.posthog.com). Receives pseudonymous usage events: feature usage counts, durations, setting choices, extension version, and plan tier — never the websites you visit, URLs, page titles, or browsing history, and with precise location lookup disabled. You can disable this anytime in Settings → Tracking Settings → "Share usage analytics". Privacy policy.
  • Resend — transactional email (welcome, password reset, purchase confirmation). Receives your email address. Privacy policy.
  • Cloudflare — hosts our website at brainrest.pro, including the password-reset page. Processes standard web request data when you visit those pages. Privacy policy.

Payments

Brain Rest Pro is sold through Polar, which acts as the merchant of record. Polar collects and processes your payment details and email address to handle the transaction. We receive only your subscription status, your plan, and a Polar customer/subscription identifier linked to your account. We never see or store your card details.

Website Icons (Favicons)

To show recognizable site icons in your dashboard, Brain Rest loads favicons from Google's favicon service (https://www.google.com/s2/favicons). When the dashboard renders, each tracked domain is sent to Google so it can return that site's icon. If you prefer not to contact Google, you can avoid this by not opening the dashboard views that display site icons.

Your Rights & Controls

  • Access: View the information we hold about you, in the extension and in your account.
  • Export / portability: Download your data in JSON or CSV format at any time.
  • Rectify: Correct your display name and account details.
  • Delete: Remove specific data or your entire account (see Data Deletion below).
  • Control settings: Change your preferences, turn off usage analytics in Settings → Tracking Settings, and sign out to stop syncing.

To exercise any of these rights, email support@brainrest.pro.

Data Deletion

You can have your data erased at any time by emailing support@brainrest.pro. On request, we delete your cloud account, your synced screen-time summaries, and your subscription records within 30 days.

Uninstalling the extension removes only the data stored locally on your device. Data already synced to your cloud account persists until you ask us to delete it. While your account remains active, we retain the data associated with it so the service can keep working.

Chrome Web Store Limited Use

Our use and transfer of information received from the extension complies with the Chrome Web Store Limited Use policy. Data is used only to provide and improve Brain Rest's single-purpose features. It is not sold, is not used for advertising, and is not used to determine creditworthiness or for lending. We do not transfer it to others except as disclosed in this policy, or as needed for your benefit, for security, to comply with the law, or with your consent.

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons.

How we'll notify you

  • In-extension notification: A banner will appear in the extension.
  • Email (if registered): We'll send updates to your registered email.
  • Update date: The "Last updated" date at the top will change.

Version history

  • July 2, 2026: Disclosed PostHog as a sub-processor for optional, pseudonymous product usage analytics, described exactly what those events contain, and documented the in-app toggle to disable them.
  • June 2, 2026: Updated to disclose required accounts, cloud sync of day-level summaries, paid subscriptions via Polar, our sub-processors, and the favicon service; corrected encryption and data-sharing descriptions; added GDPR/CCPA, data deletion, and Chrome Web Store Limited Use sections.
  • January 2025 — v1.0.0: Initial privacy policy.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please reach out.

Email support: support@brainrest.pro (response within 48 hours).

Operated by: Brain Rest, an independent solo developer.