AttentionBack to the site ↗

Privacy policy

Effective date: September 8, 2026

Attention is developed by Aleksey Voloschuk. It helps you decide whether to read, skim, save or skip an article using your current goal, available time and a saved personal profile. This policy describes the standard Attention browser extension and its project website.

The extension works without an Attention account or external AI. Ordinary evaluation runs on your device. The developer does not receive your reading data automatically. Optional services receive data only through the features described below.

Data handled on your device

Before you save a personal profile, Attention uses page titles, link labels and page structure on your device only to show a profile setup invitation. It does not extract article bodies, request evaluations or track reading. Saving a meaningful profile enables recommendations; deleting it returns cards to the setup invitation. An existing locked vault stays silent until you unlock it.

When data leaves your device

AI article analysis and profile creation

Cloud AI is blocked by default. To use it, you supply a Vercel AI Gateway key, select a model, disable Local only mode and request an AI action. Opening a card or the extension popup does not itself send an AI request.

An article AI request sends Vercel AI Gateway and the selected model provider the article title, source, excerpt, headings and text, your current goal and scenario, and selected profile and knowledge signals. One request uses at most 24,000 characters of source blocks for both the assessment and passage selection; the other listed context is additional. If you imported browser history, selected derived signals may include whether the page was encountered before and matching topics and source hostnames. The full profile, raw browsing history and imported Readwise, Obsidian or Notion note/highlight bodies are not included in these AI requests.

Source blocks and their neighboring context are sampled across sections of long articles. If the full article does not fit, the card reports partial coverage. There are no extra passage-selection requests or automatic retries. If the AI check fails, local analysis is used with an explanation. Successful evaluations keep request count, provider token usage when available and elapsed time inside your encrypted vault. They are not sent to the developer. AI requests use your provider account and may incur usage charges.

When you request AI-assisted profile creation, your three short answers about internet use, known topics and leisure preferences are sent to the same Gateway and selected model provider, with each answer limited to 1,500 characters. Your existing full profile is not sent.

The suggested default model is Google Gemini; you can choose another provider/model in AI settings. These services process requests under their own policies and your account terms. Attention does not guarantee their retention or model training practices. Enabling Local only blocks further cloud AI requests; it does not disable the connected services below.

Readwise

When you connect or synchronize Readwise, your token authenticates direct requests to Readwise to import your highlights and notes into a local index. When you choose Save to Readwise, the selected quotation, article title, author when available, cleaned source URL and timestamp are sent to Readwise. Removing the connection deletes Attention’s local token and index; it does not delete highlights in your Readwise account.

Obsidian and Notion

Obsidian access is limited to the folder you choose through the browser’s folder picker. Attention reads and indexes notes locally and does not modify the original files or upload them. The folder handle is kept only in the active extension page’s memory and is cleared when the vault is locked or reset. After that page closes or Chrome restarts, you must choose the folder again for the next synchronization. Imported notes remain encrypted in the vault; the original files are outside it.

Notion connection is not enabled in the standard release because it has no configured OAuth service. The code also supports separately configured builds: in those builds, Notion authorization uses an OAuth broker to exchange authorization codes and refresh or revoke tokens, and chosen workspace pages are fetched directly from Notion into a local index. Such a deployment must identify its broker and disclose its data handling before making that connection available.

Profile handoff, support and voluntary sharing

The recommended ChatGPT or Claude setup opens the provider with a fixed profile-generation prompt, using the clipboard or an application link. Attention does not automatically send your existing profile or articles to that conversation. You choose what to discuss with the provider and which result to import. Attention does not access either account or read your chat history. A detailed manual profile is also available.

Support development opens a separate Ko-fi page without an article or profile payload. Ko-fi and its payment providers handle payments; the extension does not receive card, bank or payment account details.

The optional pilot, diagnostic profile export and error diagnostics are not shared automatically. A diagnostic profile export contains counts and structural checks, without personal field values, goals, titles, URLs, quotations, source text or credentials. Error diagnostics contain failure codes and timestamps, excluding raw error messages. Pilot exports contain the experiment’s permitted measurements, without article text, URLs, goals or profiles. Exported files are outside the encrypted vault. If you send a file or report through GitHub, the developer and anyone with access to that report can read what you share.

Storage, permissions and deletion

Attention stores personal data in an encrypted vault in the current Chrome profile. This includes stored profiles, goals, article data, saved items, derived browsing history, decisions, feedback, reading and knowledge memory, source content and search indexes, credentials, pilot records and diagnostics. It does not use Chrome Sync to synchronize your data.

Personal records are encrypted with AES-256-GCM in local IndexedDB. A randomly generated data key is encrypted with a key derived from your password using PBKDF2-SHA-256, a random salt and 600,000 iterations. Attention does not store your password or send it to a server. Persistent extension storage outside the ciphertext holds non-personal vault and coordination metadata, including the salt and encrypted data key.

While unlocked, the data key is held in Chrome’s memory-only session storage, accessible only to trusted extension contexts. Locking the vault removes that key and blocks access to personal records; ending the browser session also requires a new unlock. Attention must decrypt data to evaluate articles, show relevant context on the page and make your chosen AI or source requests. This protection covers stored copies; it does not encrypt the website you are reading, your original source files, downloaded exports or information processed by external providers. External API requests use HTTPS.

On first setup in an existing installation, Attention copies older local records and source databases into encrypted storage and verifies the copy before removing the older stored data and folder handles. A failed migration keeps the vault locked and retains remaining original data so migration can be retried.

There is no password recovery service. If you forget the password, the reset option irreversibly deletes Attention’s local vault and allows you to create a new, empty one. It does not restore the previous profile, reading history or imported records.

Access to ordinary HTTP and HTTPS pages allows article extraction, material-link previews and reading feedback on the page. Script access loads Attention’s packaged interface into supported open tabs; storage access preserves your settings and local records. History permission is optional. You can restrict website access in Chrome’s extension settings.

Settings and source indexes remain until you remove them. Reading memory, feedback and diagnostic records have size limits, so older entries may be replaced. Choose Settings → Privacy and data → Delete all Attention data to remove local profiles, keys, saved articles, history-derived data, indexes, pilot records and diagnostics. Unfinished imports are invalidated so they cannot restore deleted data.

Local deletion does not delete your original Obsidian files, Readwise or Notion content, previously downloaded exports, public reports, or data already processed by AI providers. Resetting a locked vault cannot use its encrypted credentials to revoke remote access. Manage third-party data and permissions with those providers.

Limited use and website hosting

Attention uses data only to provide and improve its article-decision features. It does not sell user data, use it for advertising, or use it to determine creditworthiness. Attention’s use and transfer of information received from Google APIs adhere to the Chrome Web Store User Data Policy, including its Limited Use requirements. This commitment applies to raw and derived data.

The extension contains no analytics or advertising trackers. The project website is hosted by GitHub Pages and uses no project-added analytics or tracking cookies. Hosting and external service providers may process ordinary connection information, such as IP addresses and request logs, under their own policies.

Changes and contact

Policy changes will appear here with an updated effective date. Material changes to data handling will also be disclosed in the product before the changed feature is used.

For questions or requests, open an Attention GitHub issue. Issues are public: do not post credentials or private documents. The developer cannot retrieve data that exists only in your Chrome profile.