Privacy Policy
Last updated: September 1, 2026
The short version. Sunda Spotless blocks adult sites, and it decides what to block on the computer it is installed on. No page your child opens — no address, no page title, no page wording — is ever sent anywhere, to us or to anyone. There is no account, no sign-up, no analytics and no ads. Two requests do go out, and both are listed further down: a check on your Pro licence, and, in the build that does not carry its model inside it, a one-time download of that model. The record of what Sunda stopped is sealed on the computer with your parent word. And Sunda reports to nobody: there is no email, no message and no alert to anyone, because there is nothing on the other end to send one.
What Sunda does
Sunda Spotless stops adult sites from opening. It works in two layers, and they read very different amounts.
The built-in list reads nothing at all. A list of about 47,600 known adult sites ships inside the extension. When an address on that list is opened, Chrome turns it away before the page starts loading, so there is no page to read and nothing to write down. This layer needs no licence, and it reads nothing — but it does need one thing from you: access to the sites you visit. Chrome only lets an extension turn a page away like this once you have granted that access, so nothing is blocked until you do. The popup asks for it the first time you open it.
The page check reads the page. New sites appear faster than any list can follow, so for everything that is not on the list Sunda can take a peek: the address, the page title, and a little of the wording on the page. Not the whole page — a short sample, enough to form an opinion. If there is barely any wording there at all (a bare sign-in box, say), it is skipped rather than guessed at.
What Sunda reads
That peek only ever happens on ordinary web pages, the http:// and https:// kind. Files on your own computer, Chrome's own settings pages, and other extensions' pages are off-limits — always, with no setting that can change it. And none of it happens until you have granted Sunda access to the pages you visit yourself (see the permissions below). Before you do, nothing is blocked and nothing is read: the same access that lets the page check see a page is what lets the built-in list turn one away.
The reading happens inside your browser, by a small language model that lives on your computer. The words it looks at are used in the moment and then let go: they are never written down and never leave the machine. Sunda does remember its answer for a site while the browser is open, so it needn't look twice — that memory is cleared when you close Chrome. Sites where one address covers many unrelated pages, search engines and AI chats among them, are never remembered that way; each page is looked at on its own.
Sunda takes no screenshots of your pages, and it doesn't watch which tab you're on. Pages that are allowed through leave no trace in Sunda at all — only the ones it stopped are written down, and only in the sealed form described below. It also isn't reading pages to build a profile of anybody: there is nowhere for such a thing to go.
What is stored, and where
Not a great deal, and all of it on your own computer:
- Your settings — whether the “block as they browse” switch is on, and how eager the page check should be (Low, Medium or High).
- Your two site lists — the sites you have told Sunda to always allow, and the ones to always block. Each entry is sealed with your parent word, so only you can read the lists back. Beside each one Sunda also keeps a scrambled fingerprint of the site name, because it has to be able to match a site while you are nowhere near the popup. Being honest about the limit of that: a fingerprint cannot be turned back into a site name, but somebody who can read the files on your computer and already has a particular site in mind could confirm a guess.
- The “recently stopped” list — the short list of blocked pages you see in the popup. Each row's site name is sealed with your parent word before it is written. If you have not set a parent word, no site name is written at all: a row is then a time and which of the two layers acted, and nothing else. The full address is never stored either way — only the site name, and only sealed.
- Sites your child has asked you to allow — when a child taps the button on a block page, that site is queued for you on the same computer, sealed the same way. Up to twenty at a time, and only if a parent word has been set.
- The sealed bundle for your parent word — the small guarded package everything above is sealed against. It lives in device-local storage and is never synced to another machine.
- Your Pro licence key, if you have bought one — kept sealed on this computer.
- A diagnostic log — a rolling record of what Sunda itself did: it woke up, it checked something, it ran into a snag. Addresses, site names and page wording are stripped out before a line is ever written, so what's left describes Sunda's behaviour rather than anybody's browsing. It's there for one reason: if something goes wrong, there needs to be something to look at. It's capped at 5,000 lines — the oldest fall off the end — it stays on your computer, and it is never sent anywhere.
Your settings, and the date your 14-day trial started, are ordinary Chrome settings, so if you're signed into Chrome they may ride along with your other browser settings to your other computers. That is a handful of small preferences and one date; they say nothing whatsoever about where anybody has been. Everything else in the list above stays on this computer and is never synced anywhere.
The camera and microphone switches store nothing at all. Sunda asks Chrome what the current setting is every time the popup is drawn, so what you see is the browser's own answer rather than a copy Sunda kept.
How the sealing works, for anyone who wants the detail. Each entry is encrypted with an RSA-OAEP-2048 key, and the private half of that key is itself wrapped with AES-GCM under a key stretched from your parent word (PBKDF2-SHA256, 310,000 rounds). Only the wrapped bundle is stored, in device-local storage that is never synced to your other machines. Your parent word itself is never stored anywhere, in any form — a wrong word simply fails to open the lists, because there's no password on file to check it against. That also means a forgotten word cannot be recovered: the way back is to remove Sunda and set it up again, which starts everything from scratch.
Unlocking happens inside the popup. The key that unlocks it exists only while that popup is open and vanishes the moment you close it; it is never saved and never sent anywhere, not even to Sunda's own background worker. A locked row shows you a time and a hatched bar of fixed width — a stack of them doesn't even leak how long the names behind them are. And because each entry is sealed with fresh randomness, the same site looks different every time: the list gives away no “that one again” pattern.
Nothing is removed from your browsing history
Sunda used to be a history cleaner. It is not one any more, and it could not be one if it wanted to: the browsing-history permission has been taken out of the extension altogether, so Chrome would refuse. Sunda blocks a page instead, which means the page never opens and so never becomes an entry in the first place. Your bookmarks, your downloads, your saved passwords and your browsing history are all untouched, and Sunda has no way to reach any of them.
If you are setting Sunda up on a child's computer
That is what Sunda is for, so it is worth being exact about what you will and will not be able to see.
What you can see, once you enter your parent word in the popup:
- The “recently stopped” list — the times pages were blocked, the site names, and which layer stopped each one.
- Any sites your child has asked you to allow, queued from the block page.
- Your own allow and block lists, and the settings.
What Sunda does not do:
- It does not record what your child reads. Pages that are allowed through are not written down anywhere. There is no browsing report, no timeline, no screenshots and no history of what was read — only the short list of what was stopped.
- It does not send anything anywhere. There is no account and no server of ours. What is on that computer stays on that computer.
- It does not inform anybody of anything. No email, no message, no alert, no notification — not to you, not to anyone. Not when a page is blocked, not when Sunda is switched off, not when it is removed. The only way to see what has been stopped is to open the popup on that computer and enter your parent word. That is by construction: there is nothing on the other end that could reach you.
- It cannot stop somebody removing it. Anyone who can reach Chrome's extensions page can remove Sunda, and Sunda has no way to prevent that or to say afterwards that it happened. A parent word seals the settings, not the browser.
- It covers one Chrome profile on one computer. Not a phone, not a tablet, not a different browser, and not a second Chrome profile on the same machine.
The blocking is real, and the privacy is real, and neither one is supervision. Sunda closes a door; it does not watch anybody through it.
What leaves your computer
Nothing about anybody's browsing. Not the addresses, not the titles, not the page wording, not what was blocked, not even a count of how many pages were stopped. There is no server on our side that could receive it.
Two requests do go out, and this is all of them:
- The Pro licence check. Sunda Spotless is free to try for 14 days, and after that the page check needs a paid licence. If you have bought one, the extension asks Lemon Squeezy — the payment provider that sold it — whether your licence key is still valid: once when you enter the key, and roughly twice a day after that. What goes out is the licence key itself and a fixed label naming the browser it was activated on. No address, no page, no page wording, nothing about your family travels with it. During the 14-day trial there is no key to check, so nothing is sent.
- The model, once. The first time Sunda needs to read a page, it downloads the model it reads with from Hugging Face and keeps it on your computer. That request carries nothing of yours in either direction — it only fetches the model file. After it lands, the reading is entirely offline. In the fully bundled build, where the model ships inside the extension, this request does not exist at all.
That's the whole list. No analytics, no telemetry, no crash reports, no usage statistics, no advertising, no tracking code of anybody's. The one piece of outside code Sunda carries is the open-source runtime that lets the model think in your browser at all; it ships inside the extension and makes no network requests of its own. Nothing about you is sold, shared, rented or handed to anyone, because nothing about you is ever collected in the first place.
The permissions Chrome asks about
Each one is there for a specific job, and there are no spare ones:
- Blocking pages before they load — Sunda hands Chrome the built-in list of known adult sites, plus your own two lists, and Chrome turns those addresses away itself. Chrome does the refusing, so the page is never fetched and never read. All Sunda learns is which site was turned away, and that is exactly what it seals into the “recently stopped” row.
- Storage — to keep your settings, your two lists, the “recently stopped” list and the sealed bundle on your computer.
- Alarms — Chrome's little kitchen timer. Sunda uses it to shut its own reading workspace down again when it has been idle rather than leaving it running, and to re-check a Pro licence twice a day.
- Offscreen — to open that hidden workspace, a private page inside the extension where the model does its thinking. It has no view of your tabs.
- Scripting — to collect the title and a little of the wording from a page that has just opened, so the page check has something to read.
- Access to Hugging Face's download hosts — the three addresses Sunda's own model is served from, which Chrome does show you at install time. They are used for exactly one thing: fetching that model the first time, and never for anything else. In a fully bundled build, where the model ships inside the extension, they're dropped from the manifest altogether.
- Access to the sites you visit — optional, and yours to give. Both layers need it: the page check to read a page, and the built-in list because Chrome only lets an extension turn a page away once that access is granted. Sunda still doesn't take it at install time, so the Web Store listing carries no “read all your data on all websites” warning — the popup asks for it instead, Chrome puts up its own prompt, and until you say yes nothing is blocked and no page is read. You can take it back whenever you like, from Chrome's own extension settings, and both layers stop when you do.
- Seeing which site was turned away — optional, and yours to give. Asked for together with access to the sites you visit. A blocked page is turned away by the browser before Sunda's own code runs, so the only trustworthy source for the site's name is Chrome's own navigation event. Without it the record still says a block happened and when, but cannot say where. It is never used to build a browsing history: the name goes straight into the sealed record and nowhere else.
- The camera and microphone switches — optional, and yours to give. Asked for the first time you use one of those switches, never at install. It lets Sunda set Chrome's own site-wide camera and microphone setting. Sunda keeps no copy of it.
There is no longer a browsing-history permission, and that is worth saying out loud: the old version of Sunda asked for one, this one does not have it, and Chrome will not let an extension touch what it has not asked for.
What you're in control of
- Turn “block as they browse” on and off. Turning it on takes no parent word; turning it off needs one. While it is off, no page is read — and the built-in list of known adult sites, plus your own block list, go on blocking regardless.
- Change how eager the page check is. Low, Medium or High, any time, behind your parent word. It only affects what happens from that moment on.
- Allow a site. Your allow list beats everything else, the built-in list included. It is the fix when Sunda has stopped a page it should not have — in testing the pages most often wrongly stopped were sexual-health clinics, LGBTQ+ charities, breast-cancer charities and sex education.
- Take the page access back. Revoke it in Chrome and the page check stops entirely: nothing is read, until you grant it afresh. Your settings, your lists and your sealed list stay as they were, and the built-in list keeps blocking throughout.
- “Reset & erase all.” This wipes the parent word, both of your site lists and the “recently stopped” list together, in one go. It is only reachable once the parent word has been entered. Nothing readable survives — without the private key the sealed entries could never have been opened again anyway.
- Uninstall. Chrome removes the extension and everything it kept: the settings, the parent word, both lists, the sealed list, the diagnostic log and the downloaded model. Nothing of it is left behind anywhere, here or elsewhere.
Children
Sunda Spotless is a parental control. It is bought and set up by an adult, and it is designed to run on a computer a child uses — blocking sites is now its entire purpose.
It collects no personal information from anybody, of any age. A child using the computer is never asked for a name, an email address, an age or anything else, and nothing a child does on that computer is sent anywhere. The block page a child sees does one thing beyond explaining itself: its “ask a parent to allow this” button queues the site for the parent, on that same computer, sealed with the parent word. It carries no message to anybody, here or outside.
Which leaves the one clause worth putting plainly, as a privacy property rather than as an absence of supervision: Sunda reports to no one. It blocks, and the record of what it blocked is sealed on that computer and readable only by whoever holds the parent word. It is not a channel to us, and there is nobody else on the other end of it.
Chrome Web Store limited use
Sunda Spotless's use of information received from Chrome APIs follows the Chrome Web Store User Data Policy, including its Limited Use requirements. In practice that promise is an easy one to keep: the information is used on your computer, for the one purpose of deciding whether a page should be blocked, and it is never transferred, sold, or used for advertising, profiling, credit assessment or anything else. No human — us included — ever reads it, because there is nowhere for it to go.
Changes to this policy
If anything here changes in a way that matters, it will be updated on this page, with the date at the top, before the change takes effect. Sunda is not going to start collecting things quietly.
Contact
Sunda Spotless is published on the Chrome Web Store, and the store listing carries the support contact under its Support tab — that is the place to reach us about this policy or the extension. There is also less to ask about than usual: we hold nothing of yours to look up. There is no account to close and no data to request or delete, only what is on your own computer, which is yours to clear at any time.