Privacy Policy

Last updated: July 2026

LockIn MCP collects your email and account information when you sign in or purchase a license. License verification and device authorization use secure tokens; we do not sell your data.

The installer runs locally on your machine. Block lists and MCP configuration are stored on your device. Relay traffic is proxied through our Cloudflare worker only to connect your AI client to your local MCP server.

We use PostHog, Rybbit (analytics.milh.tech), and DataFast (datafa.st) for privacy-friendly website analytics on our marketing pages. Analytics data helps us understand how visitors use the site and which landing page messaging performs best; we do not sell analytics data. Automatic payment tracking from checkout URLs is disabled in DataFast because purchases are recorded server-side via Stripe webhooks.

Session cookies (`mdb_session`, `mdb_oauth_state`) are used for authentication during sign-in and device authorization flows.

We send transactional emails (email verification and, if you start checkout without completing it, one follow-up reminder about 24 hours later). You can opt out by completing or ignoring checkout; we do not send marketing email lists.

Chrome extension (optional, Pro). If you install the LockIn browser extension and sign in, it stores an OAuth access token in Chrome's local extension storage on your device. While you are connected and focus blocking is active, the extension may send page URLs to our API for distraction logging and task-aware relevance checks. We do not upload your full browsing or search history: the server only retains visits to sites on your active block list during focus (plus productive dwell time on a small set of work sites such as GitHub and Notion). For task-aware blocking, a page URL, title, and short page excerpt may be sent to LockIn's server to decide whether the page relates to your current task; this data is tied to your LockIn account, used only to operate the extension, and is not sold or shared with third-party AI agents. You can sign out from the extension popup at any time, which removes the stored token and stops server communication.

Bug reports and feature requests submitted at /report include your email, description, and optional platform or AI-prompt fields. Reports are emailed to our support inbox via Resend.

For account or licensing questions, use your dashboard or the Report form.

Terms of Service · Home · FAQ