Privacy Policy
1. Introduction
Welcome to NUFF.WORK. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our browser extension, our website at nuff.work, and any related services (together, the "Services").
By installing the extension or using our Services, you agree to the practices described in this Policy. If you do not agree, please do not use the Services.
2. Who We Are
NUFF.WORK is a digital well-being browser extension designed to help you stay focused, reduce digital fatigue, and build healthier screen-time habits. We act as the data controller for the personal information processed through the Services.
3. Information We Collect
3.1 Account Information
When you create an account, we collect your email address and (optionally) your display name. If you sign in with Google, we receive your email, name, and profile picture from Google's authentication service.
3.2 Subscription & Billing Information
If you purchase a paid plan, our payment processor collects the information required to process your transaction (such as billing address and payment method). We do not store full credit card numbers on our servers.
3.3 Usage & Productivity Data
The extension can record information about your browsing activity to provide its core features. Depending on which modes you enable, this may include:
- Time spent on individual websites (for Performance Stats)
- Domains added to your block lists (for Block Sites)
- Schedules you configure (for Sleep Mode, Dark Mode, Focus Mode)
- Completed daily tasks, streaks, and exercise sessions
- Mode preferences and ambient sound choices
By default, this data is stored locally in your browser. If you sign in to your NUFF.WORK account, selected settings and aggregated statistics may be synced to our servers so they are available across devices.
3.4 Technical Information
When you visit our website or call our API, we automatically receive standard log data such as IP address, browser type, operating system, referring page, and timestamps. We use this for security, troubleshooting, and aggregate analytics.
3.5 Communications
If you contact us by email or other channels, we keep a record of that correspondence so we can respond and improve our support.
4. What We Do Not Collect
- We do not read or store the content of the web pages you visit.
- We do not record keystrokes, form inputs, passwords, or financial data entered on third-party sites.
- We do not sell your personal information to advertisers or data brokers.
5. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Services
- Authenticate you and protect your account
- Sync your settings and statistics across devices
- Process subscriptions and prevent payment fraud
- Send essential transactional emails (account verification, password reset, billing receipts)
- Send optional product updates, with your consent, which you can unsubscribe from at any time
- Detect, investigate, and prevent abuse, security incidents, or illegal activity
- Comply with legal obligations
6. Browser Extension Permissions
The NUFF.WORK extension requests only the permissions it needs to deliver the modes you enable. Common permissions include:
- Storage — to save your preferences, schedules, and statistics locally.
- Tabs & Active Tab — to detect the current site for Block Sites, Dark Mode, and Performance Stats.
- Alarms — to trigger scheduled actions (Sleep Mode, Eye Exercise reminders, Daily Tasks reset).
- Host permissions — to apply Dark Mode styling and block screens on websites you choose.
Permissions are used solely to operate the features described in our product pages and this Policy.
7. Cookies & Local Storage
Our website uses a small number of cookies and local-storage entries strictly necessary for authentication, security, and remembering your preferences (for example, the welcome-promo countdown). We do not use third-party advertising cookies.
8. Third-Party Services
We rely on a limited number of trusted vendors to operate the Services. Each provider only receives the data needed for their function:
- Google Sign-In — for optional social authentication.
- Payment processor — to handle subscriptions and renewals.
- Email delivery service — for transactional emails.
- Hosting and CDN providers — to serve the website and API.
These providers are bound by contractual obligations to protect your data and may not use it for their own purposes.
9. Data Sharing & Disclosure
We do not sell or rent your personal information. We may disclose it only:
- With your explicit consent;
- To the service providers listed above, under strict confidentiality terms;
- When required by law, court order, or to protect our rights, users, or the public;
- In connection with a corporate transaction (merger, acquisition, or asset sale), in which case you will be notified before your data becomes subject to a different policy.
10. Data Security
We apply industry-standard administrative, technical, and physical safeguards to protect your data — including TLS encryption in transit, hashed passwords, scoped access controls, and regular security reviews. No system is perfectly secure, but we work continuously to reduce risk.
11. Data Retention
We keep your account information for as long as your account is active. If you delete your account, we erase or anonymize your personal data within 30 days, except where retention is required for legal, tax, or fraud-prevention purposes. Locally stored extension data is removed when you uninstall the extension.
12. Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate or incomplete information;
- Delete your account and associated data;
- Export your data in a portable format;
- Restrict or object to certain processing;
- Withdraw consent for optional communications;
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, contact us at the email below. We will respond within the timeframes required by applicable law.
13. International Data Transfers
NUFF.WORK is offered to users worldwide. Your data may be processed in countries other than your own. When we transfer personal data internationally, we use appropriate safeguards such as Standard Contractual Clauses or equivalent legal mechanisms.
14. Children's Privacy
Our Services are not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
15. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will notify you by email or through the Services and update the "Last updated" date above. Continued use of the Services after the effective date means you accept the revised Policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out:
NUFF.WORK Support Team
[email protected]