Privacy Policy
The short version: SunkCost keeps everything on your machine and sends nothing anywhere — with one optional exception you switch on yourself.
No account. No server. No analytics. No cookies. The only network request the extension can ever make is the optional Claude API call described below, and it is off by default.
What SunkCost stores — locally only
- Time tallies: seconds per day per site, only for domains on your own distracting-sites list. Kept for 60 days, then deleted automatically.
- Settings: your site list, chosen mode, allowance and per-site limits, curfew hours, daily goal, and — if you enable AI nudges — your Anthropic API key.
All of it lives in chrome.storage.local on your device. It is never transmitted to us or anyone else.
Why SunkCost reads tab information
The tabs permission is used for two things: checking whether the domain of your active tab is on your list so time can be counted, and — in the block mode you choose — navigating a matching tab to the extension's own blocked page. Full URLs, page titles and page content are never read, stored or transmitted, and sites not on your list are ignored entirely.
The optional Claude API call
If, and only if, you switch on “AI-written nudges” and paste your own Anthropic API key, each notification triggers one request to api.anthropic.com containing aggregate numbers only — for example “youtube.com: 42m” — plus the local time. No URLs, no history, no identifiers. Anthropic's handling of that traffic is governed by its own privacy policy. Leave the feature off and SunkCost makes no network requests at all.
Data sharing and sale
We don't collect your data, so we cannot share it or sell it. Nobody — including us — can see your browsing time.
Deleting your data
Remove the extension from Chrome and every trace of SunkCost's data goes with it.
Changes
If this policy ever changes, the new version will be posted here with an updated date.
Contact
Questions? Email sunkcost.app@proton.me.