Last updated: July 24, 2026
Privacy Policy
The core principle
BlurPatch does not send visited page content, element selectors, or replacement text to our servers. Your blur configuration is stored locally by the browser.
Account data
When you sign in with Google, we receive basic profile data: an account identifier, name, email address, and optional profile image. We use it only for authentication, plan management, and account-related communication.
Billing data
Payments are handled by Stripe. We do not store full card details. We store customer and subscription identifiers, plan status, and abbreviated payment method information provided by Stripe.
Plan limit enforcement
The extension syncs rule and installation identifiers, rule type, grouping information, creation date, and an account-scoped HMAC of the hostname. Raw domain names, selectors, and page content are not sent. Deleted rules are marked as deleted and retained for statistics until the account is permanently deleted.
Blur impression statistics
Only while the extension is signed in, we count when an actually blurred target enters the visible area of an active tab. Events are batched in browser memory, and the server stores minute-level aggregates associated with the account, installation, rule identifier, and account-scoped HMAC of the hostname. We do not send page content, selectors, URL paths, query strings, or raw domain names. Closing the page can discard a batch that has not yet been sent.
Public lifetime counter
The home page displays a live global total of recorded blur impressions. The public value contains no user, installation, or rule identifier, domain, event time, or page content. The realtime channel receives only the current total and its technical revision number.
Data deletion
You can disconnect the extension at any time. Permanently deleting the account removes rule history, minute-level impression aggregates, request rate-limit state, resets, and the account HMAC key. The anonymous lifetime total remains because it is not linked to an account and cannot be used to reconstruct its activity; contact the service administrator about account and billing data.