Source review completed · July 26, 2026

Privacy should be
verifiable.

Review what SELFLEX can access, what the source audit found, and how to repeat the checks on your own device.

REVIEWED VERSION1.3.6
API PERMISSIONS5
SITE ACCESSAll HTTP(S)
EXTERNAL ANALYTICSNone
PERMISSIONS AND ACCESS

What can SELFLEX see?

The list below comes directly from the v1.3.6 manifest.

BROAD SITE ACCESSHigh scope
http://*/*https://*/*

SELFLEX runs on HTTP and HTTPS pages to measure visible browsing time. Although <all_urls> is not written literally, these patterns provide equivalently broad website access.

PermissionWhy?Boundary
storage

Stores visits, durations, settings, and categories.

Extension-local browser storage
tabs

Reads active-tab URL, title, favicon, and tab lifecycle.

Open browser tabs
alarms

Runs local session maintenance.

Scheduled extension tasks
notifications

Shows break reminders.

System notifications
nativeMessaging

Connects Safari to its containing macOS app.

Matching local application
NOT REQUESTED

Additional browser areas outside SELFLEX

  • historyNo full history database access.
  • cookiesNo session-cookie access.
  • webRequestNo interception of page requests.
  • downloadsNo download access.
  • identityNo browser identity or OAuth.
  • bookmarksNo bookmark access.
TECHNICAL NOTE

“No browsing-data upload” is not the same as “zero network requests.”

SELFLEX does not upload browsing history to a SELFLEX server or analytics provider. The dashboard may request a favicon from a visited website’s own domain.

Accurate claim: SELFLEX has no remote user database, account system, telemetry, or analytics infrastructure.