ש Shomer Filter

Shomer Filter extension — privacy policy

Last updated: 28 July 2026

What Shomer Filter is

Shomer Filter is a content filter. You install it, activate it with a code tied to a Shomer Filter subscription, and it then filters the pages you visit in this browser: it forces SafeSearch, refuses searches for flagged terms, blurs or hides images, and blocks pages whose content trips its word list.

It is supervision software, bought deliberately by the person or household being supervised. This policy sets out exactly what it does and does not send anywhere.

Before you activate

Nothing. Until you enter a valid activation code the extension registers no content scripts, enables no rules, reads no pages and sends no network requests. An installed-but-unactivated Shomer Filter is inert.

What leaves your device once activated

WhatWhere it goesWhy
Your activation code, onceapi.shomerfilter.comto exchange it for a session token
Your session token, periodicallyapi.shomerfilter.comto check the subscription is still active
Domain pairs — “page on site A needed a resource from domain B, and could not reach it”api.shomerfilter.comso the allow-list learns which behind-the-scenes domains a permitted site needs
A liveness messagethe Shomer Filter program on your own computer, over a local channel that never touches the networkso the filter knows the extension is running

That is the complete list.

What never leaves your device

The one thing that touches domains you visited

To keep permitted sites working, the extension reports domain pairs: “a page on example.com needed cdn.example.net”. By default it reports these only when the resource failed to load — which is precisely the signal that the allow-list is missing an entry. It records the two domain names, the resource type and the network error. It does not record the page URL, the path, the query string, the page content, or a timestamp of your visit.

A subscription administrator can turn on a broader mode that reports successful dependencies too. Where a device is centrally managed, whoever administers the subscription decides this — as they already decide the filtering policy for that device.

Data we do not collect at all

We do not collect names, email addresses, passwords, payment details, location, health data, keystrokes, form contents, or the contents of your communications through this extension. (An account and payment exist on the Shomer Filter website; those are covered by the website’s own policy, not this one.)

Selling and sharing

We do not sell your data, and we do not share it with third parties for advertising, analytics or any purpose unrelated to running the filter. There are no third-party analytics, advertising or tracking libraries in the extension. The only server it contacts is api.shomerfilter.com.

Permissions, and why each is needed

PermissionWhy
<all_urls> host accessa filter that only works on some sites is not a filter
declarativeNetRequestforce SafeSearch and YouTube Restricted Mode
webNavigationsee a navigation in time to refuse a blocked search
webRequestobserve which dependency domains failed (observation only — this extension cannot read or alter request bodies)
scriptingregister the filtering content script, and unregister it when not activated
tabssend a refused navigation to the block page
storagekeep the session token and settings
nativeMessagingtalk to the Shomer Filter program on the same computer
alarmsre-check the subscription on a schedule

Retention

Session tokens live until the session is revoked or the subscription ends. Reported domain pairs are kept as part of the shared allow-list; they are domain names, not records of a person’s browsing.

Your choices

Uninstalling the extension stops all of it. On a centrally managed device the extension is installed by policy and cannot be removed by the user of that device — that is the point of a managed device, and it is disclosed at purchase. On such a device, extended access to certain sites is granted only while the filter is running, so removing it removes access rather than granting it.

Contact

[email protected]