Privacy Policy
Last updated: 26 September 2026
blockspace is a browser extension that hides web content matching rules you write, such as “Ads”, “Football” or “Cold outreach emails”. This policy explains what data the extension handles, why, who it’s shared with, and your choices. It covers the blockspace Chrome extension, the blockspace server at api.blockspace.com, and this website.
In short: to decide what to hide, blockspace checks short excerpts of the content on the pages you visit against your rules. By default it sends them to our server, which asks an AI model (Jev) whether each item matches. If you choose On this device in the extension’s settings, a model runs inside your browser instead and page content isn’t sent anywhere. We use this data only to decide what to hide. We don’t sell it, we don’t use it for advertising, and we don’t keep page text.
1. What blockspace handles
Content from the pages you visit (“website content”)
When you have at least one rule and blockspace is on for a site, the extension picks out units of content near your screen, such as posts, videos, search results, articles and ad slots. Unless you use the on-device model (see below), for each one it sends our server:
- up to about 500 characters of its visible text;
- the descriptions of its images (alt text);
- the name of the author or account that posted it, and who reposted it or is being replied to, where the page shows this;
- the domains of links it contains that go to other websites (for example
example.org); - up to two of its own link paths on the same site, with IDs removed (for example
sport/football/articles); - the site’s hostname (for example
bbc.co.uk) and the type of item (post, video, email, etc.); - signals the extension works out on your device, such as “labelled Sponsored” or “contains an ad-network frame”.
Full page addresses are not sent. Nothing is sent from what you type into forms or text fields, from sites where blockspace is paused, or when you have no rules.
The on-device model
If you choose On this device (or Use on-device model), the extension downloads a model once from blockspace.com (about 88 MB) and stores it in your browser. From then on, content checks, email checks and rule reading all happen on your computer: page content, emails and rules aren’t sent to our server or to any AI provider. Downloading the model is an ordinary file request, so our host (Cloudflare) sees your IP address and the request, as for any website visit. You can remove the model in the extension’s settings.
Email (“personal communications”), only if you opt in
blockspace does nothing on email sites (Gmail, Outlook, Yahoo Mail, Proton Mail) until you choose Filter this inbox in the extension. Permission is given per account: allowing one Gmail account doesn't allow another. After that, for each email in that inbox list it sends:
- the sender’s display name and the domain of their email address (for example “Docusign (@docusign.net)”), never the full address;
- the subject line and the preview text shown in the list.
Email bodies, attachments, full email addresses, other recipients and labels are never sent. You can stop at any time: choose Stop on that inbox, or remove it from Inboxes you’ve allowed in the extension’s settings. The list of inboxes you’ve allowed is stored only on your device.
Your rules
The rules you write are sent to our server with each check, and once when you add a rule (so we can tell, for example, whether “Cookie banners and ads” is two rules). Rules can be personal, so please avoid putting sensitive information in them.
Install token
When the extension first starts, our server gives it a random token. It isn’t linked to your name, email, Google account or device, and we use it only to apply fair-use limits per install.
Cloud checks have a free daily allowance per install. To apply it, our server counts how much model usage (in tokens) each install token, and each IP address in hashed form, has used today. These counters hold numbers only, never content, and expire within two days.
Technical data
Like any web service, our server, which runs on Cloudflare, receives your IP address and basic request details (time, size, status). We use your IP address only briefly, for rate limits (how many install tokens and checks can come from one address) to prevent abuse. Operational logs (request metadata and errors, never page content) are kept for a few days to keep the service running and secure.
Stored only on your device
Your rules, settings, the inboxes you’ve allowed, your own Jev key if you add one, and a cache of past decisions are stored in your browser’s extension storage. The decision cache holds content fingerprints (one-way hashes) and scores, not page text. It never leaves your device except as described above.
2. How we use it
We use the data above only to provide blockspace’s single purpose: deciding which content to hide for you, and keeping that service working, fast and secure. Specifically, to:
- ask the Jev model whether each item matches your rules, and return the answer to your browser;
- cache answers so that the same content doesn’t need to be checked again (see section 4);
- prevent abuse through per-install and per-IP rate limits and daily allowances.
We do not use your data for advertising, to build profiles of you, to determine creditworthiness or for lending, or for any purpose unrelated to hiding content. We do not sell your data.
3. Who we share it with
| Recipient | What | Why |
|---|---|---|
| Cloudflare, Inc. | All requests to api.blockspace.com and this website | Hosting, security and delivery |
| TypeSafe | Content excerpts and rules | Runs the Jev model that makes each decision |
| OpenRouter, Inc. | Content excerpts and rules, only when TypeSafe is unavailable or slow | Backup route to the same Jev model |
These providers process data on our behalf to deliver the service, under their own terms and privacy policies. TypeSafe states that Jev is not trained on customer requests or responses. We don’t share your data with anyone else, except where required by law or to protect the safety and rights of users and the service.
If you add your own Jev key (TypeSafe or OpenRouter) in the extension’s settings, checks go directly from your browser to that provider under your own account, and our server isn’t involved.
4. How long we keep it
- Page text, email details and rules: processed in memory to answer each check, and not stored on our servers.
- Decision cache: a one-way hash of each item and rule, with a score, kept for up to 7 days so the same content isn’t checked twice. The original text can’t be recovered from it.
- Operational logs: request metadata and errors (no page content), kept for a few days.
- Daily usage counters: a token count per install token and per hashed IP address, kept for up to two days.
- On your device: until you remove the rules, clear the cache (Settings → Clear cache), remove the on-device model (Settings → Remove model) or uninstall the extension.
5. Chrome Web Store User Data Policy
The use of information received from Google APIs and the browser, including website content and personal communications, adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this data only to provide and improve blockspace’s single purpose of hiding content you choose, we don’t transfer or sell it except as needed to provide that purpose, and no humans read it except where you ask us to (for example, in a support request), for security purposes, or where required by law.
6. Your choices and rights
- Pause blockspace for any site, or everywhere, from the extension.
- Email is only ever processed for inboxes you opt in, and you can turn that off at any time.
- Keep content on your device by choosing the on-device model in settings.
- Delete everything stored on your device by clearing the cache or uninstalling the extension.
- Because we don’t store page text, emails or rules, and your install token isn’t linked to you, there’s usually no personal data on our servers for us to return or delete. If you’d like to ask about your data, or exercise rights under data protection law (such as the UK GDPR), contact us at the address below. You also have the right to complain to your local data protection authority (in the UK, the Information Commissioner’s Office).
7. This website
blockspace.com doesn’t use cookies, analytics or third-party trackers, and loads no third-party resources. It’s hosted on Cloudflare, which receives standard request information to deliver the site.
8. Security
All communication between the extension and our server is encrypted (HTTPS). Server credentials are stored as encrypted secrets. No system is perfectly secure, but we design blockspace to hold as little data as possible.
9. Children
blockspace is not directed to children under 13, and we don’t knowingly collect personal information from them.
10. Changes
If we change what data blockspace handles or how we use it, we’ll update this policy and the date above. We’ll ask for your consent where the law requires it, before any new use of your data.
11. Contact
Questions or requests: privacy@blockspace.com