Last updated: June 2026 (rev. 2)
<aside>
🛡️ Sanctum is a focus-support browser extension for YouTube. Its purpose is to help users notice and interrupt repetitive browsing patterns such as feed checking, Shorts scrolling, refresh loops, and impulsive video selection.
</aside>
1. Data processed locally
Sanctum’s core detection and decision logic run in the user’s browser.
Sanctum may store the following data locally in the user’s browser:
- User settings such as language preference, focus mode, feedback position, excluded domains, and opt-in preference
- Local feedback records
- Local media cache
- Intervention history and local extension state needed for focus-support features
- Intent selections and suppression windows (stored locally only, never transmitted)
This local data is used only to provide Sanctum’s focus-support features.
2. Optional improvement data
Sanctum Data Handling Disclosure (Effective July 27, 2026):
- To provide its visible YouTube wellbeing features, Sanctum processes the current YouTube page type, recommendation/autoplay/Shorts transitions, playback state, button choices, and the intent entered by the user on the device.
- By default, intents, sessions, reflections, settings, and intervention records remain in Chrome local storage. Local intervention records do not store full URLs, video titles, search terms, or the raw text of the user's viewing intent.
- Sanctum does not transmit YouTube URLs, video titles, search terms, page body text, or YouTube account information to the developer's servers.
- If the user enables improvement feedback, structured product-improvement events may be transmitted to Firebase. Depending on the feature, these may include app/schema version, event or intervention type, selected action, coarse time buckets, language, collection mode, and timestamp. Quick intervention feedback may also include text entered by the user.
- When a user explicitly presses Send feedback in the popup, the entered free-form text is transmitted with app version, language, timestamp, and a fixed source label. Merely typing or closing the popup does not send the text. Users are advised not to include personal or sensitive information.
- Firebase Anonymous Authentication is used only to authorize optional feedback writes; Sanctum does not ask the user to create an account or provide a name, email address, or password.
- The uninstall survey is optional. Its URL may include the source, extension version, and browser language. No survey response is submitted automatically.
- If the user chooses externally hosted Cherry Break media, the browser requests the media from Pixabay or its CDN, and the provider's privacy policy may apply. Sanctum does not send the user's YouTube URL, title, search terms, or intent text to Pixabay.
- Sanctum does not sell user data or use it for personalized advertising, credit, lending, insurance, employment, housing, education, or other eligibility decisions.
Feedback and Improvement Data (Stable Channel Disclosure):
- When a user explicitly presses Send feedback in the Anonymous Feedback form, the entered free-form text is transmitted to Firebase. It is used only for product improvement and error review, and users are advised not to include personal or sensitive information.
- The popup feedback payload is limited to type, feedback_text, created_at, app_version, locale, and source. It does not include browsing history, the current URL, video titles, page content, account information, or any IP address collected by the extension.
- The improvement-data opt-in is off by default. When a user explicitly enables it, only a structured summary of 13 specific technical fields is transmitted to Firebase: schema_version, client_version, event_type, rule_id, rule_category, intervention_type, user_action, post_action_pattern, time_to_next_reentry_bucket, time_to_escape_bucket, feedback_label, collection_mode, and created_at. This opt-in is also blocked in incognito mode regardless of the setting.
- The uninstall survey is entirely optional and distinct from the in-extension feedback. The survey URL includes only the source, extension version, and browser locale parameters; no free-form text is automatically submitted.
If the user enables improvement data sharing, Sanctum may send minimal non-identifying summary events for rule improvement. These events may include: