Pomodoist

Chrome extension privacy policy

Effective September 7, 2026

FinchForge operates Pomodoist. This policy describes the Pomodoist Chrome extension and supplements our service privacy policy. Questions or deletion requests: support@pomodoist.com.

Information the extension uses

The extension uses your account email and identifier, authentication tokens, subscription status, tasks, project names, labels, completion history and workflow assignments to show and synchronize your Pomodoist account. Random device and operation identifiers help synchronize changes reliably.

Clicking Add current tab immediately creates a task from the active page's title and complete URL, including its query and fragment, and synchronizes it to your account. This happens only when you click the button. The extension does not read page contents, request browsing history, or monitor other tabs.

Authentication and service providers

Passwords are sent over HTTPS to Pomodoist's Supabase authentication service and are not saved by the extension. Google or Apple handles sign-in when you choose that provider. Cloudflare Turnstile may verify a sign-in request on a Pomodoist web page; the extension receives only a short-lived verification token from that page. Passwords and account tokens do not cross that page.

Account and task data is processed by Pomodoist and its Supabase backend to provide authentication, synchronization and account access. We do not sell this information or use it for advertising, creditworthiness or lending. The extension contains no advertising or analytics code.

Our use and transfer of information from Google APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

Storage and retention

Authentication tokens, cached account data and unsynchronized edits are stored locally in Chrome, accessible only to trusted extension contexts. They are not saved in Chrome's cross-device storage.sync. The extension relies on browser and operating-system protection for local storage and uses HTTPS for communication with the production backend.

Synchronized tasks remain in your Pomodoist account until removed under the service's retention and deletion practices. The service privacy policy explains account retention and purchase-record retention.

Your choices

Signing out clears local credentials and cached account data. If edits have not synchronized, the extension asks before discarding them. Sign-out also requests revocation of the current server session. It does not delete synchronized tasks. Removing the extension removes its local storage.

You can manage your account in Pomodoist or contact support@pomodoist.com to request access, correction or deletion of your data. We will update this page and its effective date if these practices change.