Policy · effective 2026-07-07 · plain language on purpose
Privacy & cookies
The short version: all filtering happens on your device, your browsing history never leaves your browser, we run no ads, and this website sets no cookies. The long version follows — and because the code is public, every claim here is checkable, not just promised. The authoritative, version-controlled copy lives in the public repository.
The Sitr extension
What Sitr transmits about you: nothing. No browsing history, no URLs, no identifiers, no device information, no usage analytics, no crash reports. With no household configured, the extension makes no network requests at all — filtering runs inside your browser's own engine, from rulesets that ship in the package and are identical for every user.
What Sitr stores on your device: your settings — which optional categories you disabled, and which sites you personally allowed or blocked. They stay in your browser's local extension storage, are never uploaded, and are deleted when you uninstall.
Sitr Family sync (optional): if you create a household, the extension contacts exactly one endpoint, which stores a single end-to-end-encrypted blob of household settings (never browsing data). The encryption keys are derived on your devices and never sent anywhere; the server cannot read the blob, keeps no request logs, and stores credentials only hashed. The full protocol is public: sync-protocol.md and data-flow.md.
Analytics and third parties: none exist. No advertising, attribution, analytics, or session-replay SDKs, and no third-party code that transfers data. Reproducible builds let you confirm the published package matches the public source.
Children: Sitr is a content filter and may be installed for family use. Because we collect no personal information from anyone, we collect none from children. Family features are built to protect without surveilling — there is no browsing report, screenshot feed, or location tracking of any family member.
This website
Cookies: none. This site sets no cookies — not first-party, not third-party, not "essential." There is no consent banner because there is nothing to consent to.
Local storage: if you use the
light/dark toggle in the header, your choice is saved as a single
value (sitr-theme)
in your browser's local storage. It never leaves your browser, and
following your system setting requires storing nothing at all.
Analytics and tracking: none. The site is static HTML with no analytics scripts, no tracking pixels, and no embedded third-party content. Our hosting provider processes IP addresses transiently to serve pages over TLS, as any web host does; we run no server-side code and keep no visitor logs of our own.
Subscriptions: Family checkout is handled by Polar as merchant of record (their privacy policy applies to the purchase itself). Afterwards, the welcome page makes one request to our own token server to fetch your subscription token — the token contains an expiry date and no identity, and the payment provider never learns anything about your household or settings.
Your rights & contact
GDPR / CCPA: we hold no personal data about you, so there is nothing for us to access, export, correct, or delete — those rights are satisfied by construction. We do not sell or share personal information as defined by the CCPA.
Changes: policy changes are made in the public repository, so every change is visible with its full history and rationale.
Contact: support@sitrshield.com (product & support) · privacy@dooplin.com (privacy & legal) · Dooplin Apps, Carrer de les Carretes 13 Bajo, 08001 Barcelona.