Policy · effective 2026-07-21 · plain language on purpose
Privacy & cookies
The short version: all filtering happens on your device, your browsing history never leaves your browser, we run no ads, and this website sets no cookies. The long version follows — and because the code is public, every claim here is checkable, not just promised. The authoritative, version-controlled copy lives in the public repository.
The Sitr extension
What Sitr transmits about you: nothing. No browsing history, no URLs, no identifiers, no device information, no usage analytics, no crash reports. With no household configured, the extension makes no network requests at all — filtering runs inside your browser's own engine, from rulesets that ship in the package and are identical for every user.
What Sitr stores on your device: your settings — which optional categories you disabled, which sites you personally allowed or blocked, and, if you use Sitr Family, your household's shared lists, its key material, and the guardian PIN (as a salted hash). They stay in your browser's local extension storage, are never uploaded except as the encrypted household blob described below, and are deleted when you uninstall.
Sitr Family sync (optional): if you create or join a household, the extension contacts exactly one endpoint, which stores a single end-to-end-encrypted blob of household settings — shared allow/block lists, category configuration, the guardian PIN hash — never browsing data. The encryption keys are derived on your devices from a secret that is never transmitted; the server cannot read the blob, keeps no request logs, stores credentials only hashed, and rounds timestamps to the day. Any future endpoint will be documented publicly before it ships. The full protocol and the server's source code are public: sync-protocol.md and data-flow.md.
Sitr for Institutions (managed devices): on devices managed by an organization, the administrator's policy is delivered read-only through the browser's own enterprise mechanism. It can force filtering on, but it cannot make Sitr report anything about you — nothing in Sitr reports browsing, in any tier.
Analytics and third parties: none exist. No advertising, attribution, analytics, or session-replay SDKs, and no third-party code that transfers data. Reproducible builds let you confirm the published package matches the public source.
Children: Sitr is a content filter and may be installed for family use. Because we collect no personal information from anyone, we collect none from children. Family features are built to protect without surveilling — there is no browsing report, screenshot feed, or location tracking of any family member, and the household sync blob contains settings only, unreadable by us. If a future feature ever collects personal information from children, it will require verifiable parental consent and a revision of this policy first (COPPA).
This website
Cookies: none. This site sets no cookies — not first-party, not third-party, not "essential." There is no consent banner because there is nothing to consent to.
Local storage: if you use the
light/dark toggle in the header, your choice is saved as a single
value (sitr-theme)
in your browser's local storage. It never leaves your browser, and
following your system setting requires storing nothing at all.
Analytics and tracking: none. The site is static HTML with no analytics scripts, no tracking pixels, and no embedded third-party content. Our hosting provider processes IP addresses transiently to serve pages over TLS, as any web host does; we run no server-side code and keep no visitor logs of our own.
Subscriptions: Family checkout is handled by Polar as merchant of record (their privacy policy applies to the purchase itself). Afterwards, the welcome page makes one request to our own token server to fetch your subscription token — the token contains an expiry date and no identity, and the payment provider never learns anything about your household or settings.
Your rights & contact
GDPR / CCPA: we hold no personal data about you — the household blob is ciphertext we cannot read, tied to no account, name, or email — so there is nothing for us to access, export, correct, or delete beyond what you control directly: leaving a household deletes its data from your device, and a household can delete its server blob at any time. We do not sell or share personal information as defined by the CCPA.
Jurisdiction: Sitr is built by Dooplin Apps S.L., an EU company based in Barcelona, and is accountable under the GDPR — though our architecture means there is essentially no personal data to regulate, which is the stronger guarantee of the two.
Changes: policy changes are made in the public repository, so every change is visible with its full history and rationale.
Contact: [email protected] (product & support) · [email protected] (privacy & legal) · Dooplin Apps, Carrer de les Carretes 13 Bajo, 08001 Barcelona.