Warmth browser extension — privacy

Last updated 22 September 2026

The Warmth extension sends data to exactly one place: the Warmth application running on your own computer. There is no Warmth server in that path, and your browsing data does not leave your machine.

What this page covers

This policy covers the Warmth browser extension for Chrome, Firefox, and Safari. The Warmth macOS app is a separate piece of software with its own behavior, described briefly at the end.

How the extension connects

The extension talks to the Warmth app over a local connection on your own computer — 127.0.0.1, on a port between 8765 and 8775. That connection never leaves your machine. The two are paired with a shared secret, so no other program on your computer can impersonate Warmth and read what the extension sends.

Safari works slightly differently. Safari extensions cannot open a local connection directly, so the extension passes messages through its own native helper, which then makes the same local connection. The destination is identical.

What the extension sends to the local app

For the tab you are currently looking at:

And when a blocked page is shown, which of your own block rules matched it.

That is the complete list.

What it never sends

Private and incognito windows

When a private or incognito window is in front, the extension reports only that a private window is focused, and whether it is playing audio. No address, no page title, and no tab count are sent — those fields are dropped before the message is built, not filtered later.

What is stored in your browser

One pairing secret, held in the browser's own extension storage, so the extension can reconnect to the Warmth app without asking you to pair it again. Nothing else is stored. Removing the extension removes it.

What the extension does not do

Why the extension asks for access to all sites

Blocking has to work on whatever site you chose to block, and that is not knowable ahead of time. The broad site permission is used for one thing only: redirecting a page you asked Warmth to block to Warmth's own explanation page. It is not used to read pages.

Blocking is also deliberately fragile in your favour. Every block list expires after ten seconds unless the Warmth app renews it, so if Warmth quits or crashes, blocking releases on its own rather than leaving your browser stuck. Password managers, sign-in pages, and checkout pages are never blocked.

Deleting your data

Uninstalling the extension removes the pairing secret from your browser. Your activity history lives in the Warmth app on your Mac, and is deleted when you delete it there or remove the app.

About the Warmth macOS app

The extension only ever hands data to the app on your machine. What the app does next depends on the settings you choose:

None of this changes what the extension itself does, which is described above.

Changes to this policy

If this changes in a way that affects what the extension collects, the date at the top of this page changes with it.

Contact

Questions about this policy: legal@octopusbuilds.com