Effective · Version 2026-07-19.2
WatchCat Privacy Policy
Last updated: July 19, 2026
1. Scope and plain-language summary
Material update: WatchCat is migrating dashboard and extension authentication to the WatchCat API. New backend-owned releases use WatchCat browser sessions and extension OAuth credentials. Previously released clients may temporarily continue the legacy Supabase Auth path during the bounded adoption and rollback window.
This policy explains how WatchCat handles information in the browser extension, public website, waitlist, account dashboard, and optional cloud sync. Free accounts stay local-only. Cloud history is available only to eligible Pro and Max accounts and begins after you connect the extension and affirmatively consent to detailed history.
2. Who is responsible
WatchCat is operated under the WatchCat name by the developer who publishes the WatchCat extension and services. For privacy questions or requests, email watchcat.extension@gmail.com. If a separate legal entity becomes the operator, this policy will be updated before that entity takes control of personal data.
3. Data kept locally by the extension
WatchCat uses browser extension storage and a local IndexedDB to keep settings, enabled sites, limits, display preferences, a separate current-day enforcement summary, item titles and identifiers, UTC activity-segment start and end, active seconds, session and segment identity, source timezone, and temporary unlocks. Cloud rows never control local blocking. Local data remains in the browser profile unless you explicitly enable cloud sync. You can delete it by clearing WatchCat extension storage or uninstalling the extension.
4. Accounts and authentication
In the backend-owned dashboard release, your browser sends registration, sign-in, confirmation, recovery, and account requests only to the WatchCat API. Supabase processes your email, account identifier, password-authentication state, confirmation/recovery state, and provider session credentials as internal backend infrastructure. The dashboard receives a host-only HttpOnly WatchCat session cookie and a session-bound CSRF value, never a Supabase key or token. The backend stores a hash of the browser handle and encrypted provider credentials needed to maintain or revoke the session.
The new account-enabled Chrome extension release connects through WatchCat OAuth Authorization Code with PKCE in a normal dashboard tab. The dashboard callback relays only the backend-issued one-time authorization code and state to the allowlisted extension; it does not receive or store WatchCat tokens. The backend records the client, authorization request and decision, scopes, grant and revocation state, and hashes of one-time codes and rotating opaque tokens. The extension keeps the access token in trusted extension session storage and its rotating refresh token in extension IndexedDB. Google and GitHub sign-in are not active.
During the migration and rollback window, an already-released dashboard or extension may still authenticate directly with Supabase. New client releases contain no fallback to that legacy path; WatchCat will retire it only after supported-client adoption and traffic checks are complete.
5. Optional cloud sync
Eligible cloud history has one scope: detailed history. Before transfer, the extension shows the categories, purpose, destination, exclusions, and controls and requires an affirmative choice. Detailed history includes the supported site and content kind, item identifier and title, UTC segment start and end, active seconds, session and segment identity, source timezone, device provenance, and derived totals, session count, and last seen. The extension also records device/link identifiers, consent receipt version and state, bounded outbox metadata, account revisions, watermarks, query/change cursors, and cache coverage.
Detailed history goes only to the WatchCat API; the backend uses Supabase Postgres as internal infrastructure for cross-device account history. The protocol excludes URLs, full browsing history, limits, PIN data, unlock overrides, and enforcement settings. Free accounts cannot enable this transfer. Existing aggregate-only accounts must accept the current detailed disclosure first. A current receipt applies account-wide, so same-account reconnection and another linked device merge missing eligible segments automatically. Signing out stops history network work on that device. Entitlement loss, revocation, or withdrawal blocks future transfer; a linked extension may make one bounded authenticated check before it observes an account-side change and deactivates its schedule. Local history and enforcement remain. Withdrawal does not itself erase stored cloud data; account deletion removes cloud history. Account export and authenticated staged deletion are provided by the product API.
6. Website, analytics, and waitlist data
The public website uses limited anonymous analytics on the landing. This may include page views, campaign and referring source, browser and device information, web-performance measurements, approximate country, automatically captured interaction metadata and heatmaps, masked session replay and related console diagnostics, call-to-action placement, and waitlist outcome categories.
Input values are masked in session replay by default. WatchCat does not intentionally send waitlist email addresses, form contents, extension history, or extension settings through website analytics. Analytics runs only on the public landing route and not on private unsubscribe URLs, and the analytics service is configured not to retain raw client IP addresses. Browser storage holds a random anonymous identifier and the cookie notice acknowledgement until site data is cleared.
If you join the waitlist, WatchCat processes your email address, source, a limited referrer, subscription and confirmation timestamps, confirmation attempts, and unsubscribe state. A one-time Cloudflare Turnstile token and request IP are used for abuse prevention. Resend delivers the confirmation email. Unsubscribing stops waitlist messages and preserves the suppression state needed to honor that choice; you may also request deletion.
7. How we use data
We use data to provide local tracking and blocking, authenticate accounts, deliver detailed sync after current consent, show account and device status, protect the services, respond to support and privacy requests, operate the waitlist, and understand the public website at an aggregate level. Depending on the context, processing is necessary to provide the service you request, to meet legal obligations, for legitimate security, service-operation, and aggregate website-measurement interests where applicable, or based on consent for processing that WatchCat presents as optional. We do not use WatchCat data for advertising profiles, credit decisions, or data-broker activity.
8. Service providers and disclosure
WatchCat uses service providers for hosting and delivery, authentication and database infrastructure, product analytics, bot protection, and email delivery. These currently include Supabase, hosting and analytics infrastructure used by the WatchCat website and API, Cloudflare Turnstile, and Resend. They process data under their own contracts and security terms only for the relevant service. We may also disclose information when required by law, to protect users and the service, or as part of a business transfer with appropriate notice and safeguards. We do not sell personal information or share it for cross-context behavioral advertising.
9. Retention
Local extension history is currently pruned on a rolling basis. Cloud history is retained while needed to provide account sync and until account deletion. Entitlement loss or consent withdrawal stops transfer but does not itself delete local or stored cloud history. Detailed-history operation receipts expire after 90 days; superseded versions and change rows older than 90 days are compacted daily only through active-device revision floors. Browser sessions default to 30 idle days and 90 absolute days; OAuth requests last 10 minutes, codes five minutes, access tokens 10 minutes, rotating refresh grants 30 idle days or 90 absolute days, and bounded auth security events 90 days. Revocation or deletion may end them sooner. Account deletion removes user-owned data and authentication last; legally required financial or audit records are de-identified and stripped of account linkage.
10. Security
Backend-owned releases use HTTPS, host-only HttpOnly cookies, exact-origin and CSRF checks, OAuth PKCE and rotating-token replay protection, scoped browser permissions, server-side token verification, access controls, row and tenant boundaries, input validation, and privacy-limited logs and metrics. No service can guarantee absolute security. Keep access to your browser profile and email account secure, and contact us if you believe your account or data has been compromised.
11. Your choices and rights
You can use Free without cloud sync; accept or decline detailed history for Pro or Max; withdraw consent, sign out, or revoke a device to stop transfer; export account data; and request account deletion to erase cloud history. Withdrawal and deletion are separate controls. Depending on where you live, you may also have rights to access, correct, delete, restrict, port, or object to processing and to complain to a local data-protection authority. We verify requests before disclosure or deletion. Privacy choices will not be used to discriminate against you.
12. Children
WatchCat is not directed to children under 13, and we do not knowingly collect account or sync data from a child under 13. Where local law requires a higher age or parental authorization for an online account, do not create or connect a WatchCat account without that authorization. Contact us if you believe a child provided personal data so we can review and delete it where required.
13. International transfers
WatchCat and its providers may process data in countries other than your own. Where required, transfers are handled through an adequacy decision, contractual safeguards, or another lawful transfer mechanism offered by the relevant provider.
14. Chrome Web Store Limited Use
WatchCat limits extension data to the user-facing purposes described in the extension, its store listing, and this policy. The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. We do not transfer extension browsing activity for personalized advertising, sale by data brokers, lending, or unrelated purposes.
15. Changes to this policy
We update this policy when WatchCat changes its data categories, purposes, sync scope, providers, retention, user controls, or applicable obligations. Editorial corrections may not trigger a notice. For material changes, we will change the version and effective date and provide an in-product notice; where a new use requires consent, we will request it before that use begins. Earlier versions may be requested by email.
16. Contact
Email watchcat.extension@gmail.com with the subject “Privacy request.” Include enough information to identify the relevant account or waitlist entry, but do not send passwords, session tokens, or PINs.