Privacy policy
Local-first.Clear about activation.
Last updated 19 September 2026 · applies to Stay Unseen 1.4.26
Stay Unseen is a browser extension that controls read receipts, story views and typing indicators on Instagram, Facebook, Messenger, WhatsApp Web and Threads.
The short version
Protection and diagnostics run in your browser. Settings, counters and redacted logs stay local. If you activate Lifetime Pro, the extension sends the licence key and installation identifiers to the Stay Unseen licence service for validation. It never sends message text, social content or browsing history, and it does not use analytics or advertising trackers.
What it stores on your device
All of the following is kept in the browser's local extension storage
(storage.local). This local data is not included in licence-validation requests.
| What | Why |
|---|---|
| Feature settings, site settings and the unread-marker preference | So your switches survive a restart |
| A count of blocked signals per feature | Powers the counters in the popup and the toolbar badge |
| A capped log of recent block/allow decisions — endpoint, which layer decided, timestamp, with message text removed | So a signal that stops being blocked can be diagnosed after a site change |
Stored diagnostic endpoints come only from supported sites. They are capped, overwritten continuously, and readable only by this extension on this device.
Resetting the counters in the popup, or uninstalling the extension, erases all of the above.
Pro licence validation
Core features do not require a licence. When you activate, revalidate, or release a Lifetime Pro licence, Stay Unseen contacts its Cloudflare Worker licence service, which validates the purchase with Lemon Squeezy. The request contains the licence key, a randomly generated installation ID and, after activation, the provider's licence-instance ID. These fields are used only to grant Pro access and enforce the device limit.
The licence request does not contain messages, photos, contacts, posts, social-account credentials, page contents or general browsing history. Lemon Squeezy processes purchase and licence information under its own privacy terms.
Reading request contents
To decide whether a request is a read receipt or a typing notification, Stay Unseen has to look at more than the address: on Instagram and Messenger these signals are sent as GraphQL calls and websocket frames whose addresses are identical to ordinary ones. So the extension inspects the outgoing request body in memory, matches it against a fixed list of patterns, and then either drops it or lets it through.
Two consequences worth stating plainly:
- On a chat site, outgoing bodies include messages you send. Stay Unseen looks at them only to make that block-or-allow decision, and never keeps or sends them.
-
Before anything is written to the local log described above, the fields holding text you typed
are replaced with
<user_text>. This is also what stops a message containing the word “typing” from being mistaken for a typing signal and dropped.
What it does not do
- It does not send browsing content or social-account data to the licence service.
- It does not use analytics, telemetry, crash reporting, or advertising.
- It does not transmit your messages, photos, contacts, posts, or account details, and does not store the text of your messages.
- It does not ask for an account, an email address, or a sign-in.
- It does not build or transmit a browsing history. Its site access is limited to supported web apps.
- It does not sell personal data or use it for advertising.
What it does on the sites it runs on
On supported web apps, Stay Unseen stops the specific network requests that report a story view, a message read, or that you are typing. It does this in two ways: by cancelling those requests through the browser's own blocking API, and by intercepting the equivalent calls made by the page's own code. It does not change the pages you are looking at, except for the optional unread-marker preference, which affects only your own view.
Your control
Every blocking feature has its own switch in the popup and can be turned off at any time; turning
one off restores the site's normal behaviour immediately. Removing the extension from your browser's
extensions page — chrome://extensions, edge://extensions, or
about:addons — stops all of its activity and deletes its stored data.
Children
Stay Unseen is not directed at children under 13 and collects no information from anyone, including children.
Changes to this policy
If the extension's data handling changes, this page will be updated and the date at the top revised before the change ships.
Contact
Questions about this policy: hrrpooh@gmail.com
Affiliation
Stay Unseen is an independent project. It is not affiliated with, endorsed by, or connected to Meta Platforms, Instagram, Facebook, or Microsoft.