Why First Privacy Policy
Effective date: 2026-09-18Last updated: 2026-09-18
Why First is a local-first browser extension: your browsing data is never sent to us. This policy describes the only two things that can leave your device — the Pro license requests (activation, background refresh and deactivation) and the optional cross-device sync — and what each of them carries.
What we collect
No browsing data reaches us. Why First collects no browsing data and receives none: no account system, no remote analytics, and no first-party database of what you browse or of who you are. The only service Why First operates is the stateless Pro license check described below; it stores no browsing data and keeps no customer database.
What the extension stores locally
By default everything the extension keeps stays in your browser's local extension storage (browser.storage.local), and none of it is sent to us:
- The list of sites and URL rules you configure.
- The short intent notes ("reasons") you optionally write during a check-in.
- Raw usage statistics: visit counts and time spent per rule, per day.
The only optional exception is Pro config sync, which is off by default and carries rules and settings alone — never reasons, history or statistics — and it travels through your browser's own sync service (Google or Mozilla), not to Why First.
What the extension can see
When you navigate to a site you have configured a rule for, the extension sees the domain and URL path you are heading to, in order to decide whether to show the check-in page. It never reads page content, form fields, cookies, or anything you type into other websites.
Pro license verification
Buying Pro gives you a license key. Activation is the only time the raw key leaves your device: an activation request contains the license key, an anonymous install ID generated on your device (not a hardware fingerprint), the product ID (whyfirst-pro-lifetime), the app version, and the browser family. It never contains a domain, URL, reason, statistic or page content, and no payment or billing details.
Our license service — a stateless issuer that Why First operates, using Lemon Squeezy as payment provider and license state source — verifies the purchase and returns a signed credential, which is stored in your browser's local extension storage. The extension does not keep the raw key after activation; every later request — the background refresh and deactivation — sends the signed credential and the app version instead, and nothing else. There is no Why First user database: no account, no browsing history and no device table. Our payment provider does keep order, customer and license-instance records, as a merchant of record is required to.
The signed credential carries an offline grace period — 60 days by default, configurable between 30 and 90 days, counted from the last successful issue. While you are offline, Pro keeps working for that period. Past it, and until the next successful check, Pro features switch off and the extension falls back to Free; your rules, statistics and reasons are never deleted, and one successful check or re-activation restores Pro.
While you are online, the extension refreshes the license in the background, normally about once a week or two. If you deactivate Pro in Settings, the extension sends the same signed credential and app version so the license service can release that activation; that request is the third and last kind the extension makes. Refunded or revoked keys stop working at the next successful check, which is why we do not promise an exact revocation time.
Cross-device sync (optional, off by default)
Pro can carry your rules and settings to your other devices. When you switch sync on, the browser's own sync service (Google for Chrome, Mozilla for Firefox) transports and stores those rules and settings under your browser account terms. Why First is not part of that exchange and cannot read the synced data. Browsing history, intent reasons and statistics are never synced — they stay in browser.storage.local on each device.
Third parties
- Lemon Squeezy is the Merchant of Record: it sells Pro licenses on its hosted checkout page and is the source of truth for license, order and device-instance state. As a merchant of record it keeps order and customer records as tax and consumer law requires; those interactions are governed by its own privacy policy.
- If you enable cross-device sync, your browser vendor (Google or Mozilla) stores the synced rules and settings.
The installed extension makes no other network requests: activation, refresh and deactivation are the complete list, and none of them carries browsing data.
Your controls
- Delete any rule, note, or statistic from the extension's settings at any time.
- Turn cross-device sync off in Settings; rules already synced to your browser account follow the browser's own sync deletion rules.
- "Clear all local data" in Settings removes everything the extension has stored.
- Uninstalling the extension removes all locally stored data.
Contact
Questions about this policy: open an issue at github.com/shiquda/WhyFirst.