1. Introduction
DeepStay ("the Extension") is a Chrome browser extension that integrates a Pomodoro timer with ClickUp task management. This Privacy Policy explains what data we collect, why we collect it, where it is stored, how it is used, and your rights regarding that data.
DeepStay is designed with a privacy-first approach. We collect only the data necessary to provide core timer and ClickUp integration features.
2. Data We Collect
DeepStay collects and processes the following categories of data:
2.1 ClickUp Authentication & Account Data
DeepStay does not collect your ClickUp password. Authentication is handled securely using ClickUp's official OAuth process.
Data Collected
- ClickUp OAuth access token
- ClickUp user profile (basic profile details)
- Selected ClickUp Team/List IDs
Why We Collect It
- To authenticate you via ClickUp OAuth
- To retrieve and display your tasks
- To update task progress
- To connect focus sessions with selected tasks
Where It Is Stored
- browser.storage.local
2.2 Timer & Productivity Data
Data Collected
- Timer state (running, paused, completed)
- Timer configuration (focus duration, break duration)
- Custom presets
- Selected task
- Task progress
- Interruption logs
- Goals (if configured)
Why We Collect It
- To power the Pomodoro timer functionality
- To maintain timer continuity even if the popup is closed
- To support upcoming analytics features
- To track productivity insights locally
Where It Is Stored
- browser.storage.local
2.3 Application Settings
Data stored in storage.sync is synchronized across the user's Chrome browsers when signed in.
Data Collected
- Theme
- Accent preferences
- Audio/notification preferences
- Productivity goals
- Other app settings
Why We Collect It
- To personalize your experience
- To sync settings across browsers where you are signed in
Where It Is Stored
- browser.storage.sync
2.4 OAuth State Data
This data is temporary and cleared after authentication.
Data Collected
- Temporary OAuth state parameter
Why We Collect It
- To securely validate and complete the OAuth login process
Where It Is Stored
- browser.storage.session
3. How We Use Your Data
Your data is used strictly to:
- Authenticate your ClickUp account
- Display and manage ClickUp tasks
- Update task progress
- Run and maintain timer lifecycle
- Trigger notifications and alerts
- Improve reliability and performance
- Support future productivity analytics features
We do not
- Sell user data
- Rent user data
- Use data for advertising
- Share data with data brokers
4. External APIs & Third-Party Services
DeepStay communicates with the following external services:
4.1 ClickUp API
ClickUp receives API requests authenticated using your OAuth access token.
Endpoints used
- https://api.clickup.com/api/v2/oauth/token
- https://api.clickup.com/api/v2
Purpose
- OAuth token exchange
- Fetching tasks
- Updating task progress
4.2 Cloudflare Worker Proxy
The Cloudflare Worker acts as a secure proxy and does not use data for independent purposes.
Host Permission
- https://.workers.dev/
Purpose
- Securely exchange OAuth authorization codes
- Forward ClickUp API requests on behalf of the user
5. Browser Permissions & Justification
DeepStay uses only permissions necessary for core functionality:
identity
Used to securely authenticate users via ClickUp OAuth. This permission allows the extension to launch the OAuth login flow and obtain an access token without accessing user passwords.
storage
Used to store timer state, user preferences (theme, audio, goals), selected tasks, interruption logs, and ClickUp session data locally in the user's browser. Some settings are stored in storage.sync to allow synchronization across signed-in Chrome browsers.
alarms
Required to ensure timer sessions (focus and break phases) continue running accurately even when the extension popup is closed.
notifications
Used to send optional focus completion and break reminders to the user.
Host Permission (https://.workers.dev/)
Allows secure communication with the project's Cloudflare Worker proxy. The proxy is used to securely exchange OAuth authorization codes and forward ClickUp API requests on behalf of the authenticated user.
6. Background Service Worker
The background service worker is responsible for:
- Managing timer lifecycle using browser alarms
- Sending notifications
- Handling storage updates
- Managing OAuth flow
- Runtime messaging between extension components
Privacy boundary
No browsing history, keystrokes, or unrelated user activity is monitored.
7. Data Storage & Security
DeepStay primarily stores data locally in your browser.
Security measures include
- Secure OAuth authentication flow
- HTTPS encrypted API communication
- Restricted host permissions
- Minimal data collection principles
Access
Access to stored data is limited to the extension itself.
8. AI Usage
DeepStay does not use artificial intelligence, machine learning models, or automated decision-making systems.
No user data is processed by AI systems.
9. Data Sharing
We do not share your data with third parties except:
- ClickUp (for authenticated API operations)
- Cloudflare Worker (as a secure proxy for OAuth/API forwarding)
- When legally required
Marketing
No data is sold or used for marketing purposes.
10. Data Retention
Data remains stored:
- Locally in your browser while the extension is installed
- Until manually cleared or the extension is uninstalled
Future features
If cloud storage or analytics features are introduced in the future, this policy will be updated accordingly.
11. User Control & Data Deletion
You may:
- Disconnect your ClickUp account at any time
- Clear browser storage manually
- Uninstall the extension to remove locally stored data
- Disable notifications in browser settings
For deletion inquiries, contact
- Email: hello@visionexdigital.com.au
- Company: Visionex Digital (Pvt) Ltd
12. Children's Privacy
DeepStay is not intended for children under 13 (or applicable minimum age in your jurisdiction).
We do not knowingly collect data from children.
13. Changes to This Policy
We may update this Privacy Policy as features evolve.
Material changes will be reflected in the "Last Updated" date.
Continued use of the Extension constitutes acceptance of the revised policy.
14. Compliance Statement
DeepStay:
- Collects only necessary data
- Stores most data locally in the browser
- Does not sell or monetize user data
- Does not use advertising trackers
- Follows Chrome Web Store Developer Program Policies