Skip to content

Privacy Policy

We collect minimal data, never sell it, and give you full control. Here's exactly what we do.

Summary

DNDShield blocks ads and trackers — we don't track you ourselves. Core blocking works with no account. If you create an account, we store only what's needed to sync your settings. We never sell your data.

Last updated: April 29, 2026

Applies to: dndshield.com website, DNDShield browser extension, and DNDShield cloud account.

1. Who we are

DNDShield ("we", "us", "our") provides a browser extension and optional cloud account for ad blocking and privacy protection. Our website is dndshield.com. Questions? Email us at [email protected].

2. Extension — data stored locally

The extension works entirely locally by default. No account required. The following data is stored only on your device using chrome.storage.local:

  • Your extension settings (enabled/disabled, theme, allowlist, pause timer)
  • Blocked request counts (ads, trackers, other) — statistics only, not URLs
  • Recent blocked request log (last 200 entries) — stored locally, never sent out
  • Per-site overrides (which sites are allowed or paused)
  • Gamification data (milestone counts, badges) — local only

We do not receive any of this data unless you explicitly sync via a cloud account.

3. Extension lifecycle telemetry

To understand how the extension is being installed, updated, and used across browsers, the extension sends a small set of anonymous lifecycle events to our cloud:

  • installed — when you first install the extension
  • updated — when the extension auto-updates to a new version
  • uninstalled — when you remove the extension (via your browser's standard uninstall flow)
  • opened — once per browser session, when you open the popup or options page
  • first_block — once per install, the first time DNDShield blocks a request

Each event contains:

  • installId — a random UUID generated locally on first run; not linked to your account, email, or IP
  • browser — Chrome, Firefox, Edge, Opera, Safari, or "other"
  • version — the extension version (e.g. 1.1.0)
  • locale — your browser's UI language (e.g. en-US)
  • previous version — only for update events

We also store a hashed IP address (SHA-256 with a server-side salt, truncated) for spam and abuse detection. The original IP is never stored — the hash cannot be reversed to recover your IP, but it lets us detect duplicate events from the same source.

We do not send: blocked URLs, page content, browsing history, your IP address, cookies, account email, or any data tied to your identity. The installId is unique to your browser profile and resets if you uninstall and reinstall.

This telemetry helps us measure install success across browsers, detect bugs in updates, and understand drop-off between "installed" and "first_block" (activation). You can disable telemetry by blocking requests to app.dndshield.com in your network or firewall — the extension will continue working normally.

4. Cloud account — optional

If you create a free or paid account, we store the following on our servers:

  • Your email address and hashed password
  • Your extension settings and allowlist (for sync across devices)
  • License / plan information
  • Device tokens (to identify which devices are linked to your account)
  • Last sync timestamp

We do not store your browsing history, blocked URL details, or any page content. Sync only sends settings and allowlist — not logs.

5. Website analytics

Our website (dndshield.com) uses Umami, a privacy-friendly, self-hosted analytics tool. Umami records page views, referrers, browser, device type, and country (derived from anonymised IP, not stored). It does not use cookies, does not fingerprint, and does not track individuals across sites. We do not use Google Analytics, Facebook Pixel, or any ad-tech tracking.

6. Cookies and local storage

We use a small number of first-party cookies and local-storage entries. No third-party advertising or tracking cookies are set.

  • Authentication cookies (NextAuth) — set when you sign in to your cloud account. Required for the dashboard to work. Cleared when you sign out.
  • UTM attribution cookie (dnd_utm_v1) — when you arrive at our site via a link with ?utm_source=… tags, we store those tags in a first-party cookie for 30 days. If you later create an account, the tags are attached to your signup so we know which marketing channel referred you. Contains only the UTM values, no personal data. First-touch (does not overwrite if already set).
  • Referral attribution cookie (dnd_ref) — when you arrive via a referral or creator link (a ?ref=… tag or a creator's /c/… page), we store that referral code in a first-party cookie for 45 days so the person who referred you gets credit if you sign up later. Contains only the referral code, no personal data. First-touch (does not overwrite if already set).
  • Experiment visitor ID (dnd_exp_vid) — a random UUID stored for up to 30 days, used to keep A/B test variants stable for you across pages so you don't see different button copy on every reload. Not linked to your account or any personal data. Cleared with browser cookies.
  • Theme preference (dndshield-theme, localStorage) — remembers your light/dark/system choice. Stays on your device.

See our Cookie Policy for full details.

7. Third-party services
  • Hosting: Our servers are hosted on reputable cloud providers. Traffic may pass through CDN nodes.
  • Payment: Paid plan checkouts and subscriptions are handled by Stripe. We do not see or store your card details. Stripe receives your email and payment information directly.
  • Email: Transactional emails (welcome, verification, password reset, weekly digest) are sent via SMTP from [email protected]. No marketing emails are sent without explicit opt-in.
8. Data retention
  • Local extension data: stored on your device until you uninstall the extension or clear storage.
  • Cloud account data: retained while your account is active. Deleted within 30 days of account deletion request.
  • Extension lifecycle telemetry: retained for up to 12 months for trend analysis, then deleted. Hashed IPs are deleted with the events.
  • Server logs: retained for up to 90 days for security and debugging, then deleted.
  • UTM attribution data: stored at signup and retained as long as your account exists. Removed on account deletion.
9. Your rights

You have the right to:

  • Access the data we hold about you
  • Correct inaccurate data
  • Delete your account and all associated data
  • Export your settings/allowlist data
  • Withdraw consent at any time

To exercise these rights, email [email protected]. We will respond within 30 days.

10. Children

DNDShield is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us data, please contact us and we will delete it promptly.

11. Changes to this policy

We may update this policy from time to time. We will update the "Last updated" date at the top. Continued use of DNDShield after changes constitutes acceptance of the updated policy.

12. Contact

Questions, requests, or concerns about privacy: