Privacy Policy — Mimosa Timer
Last updated: 2026-08-29
Mimosa Timer ("the extension") is a break-reminder Chrome extension. We collect as little as we can, and only on our own site.
What stays on your device
Reminder mode, interval, fixed times, pause state, sound on/off, custom greeting, wishlist choices, and (after the first feedback submit) a random install_id are stored with chrome.storage.sync. If Chrome Sync is on, those values copy across your own browsers through your Google account. We do not receive a copy of your settings from Google.
A custom reminder sound, if you upload one, stays in chrome.storage.local on that device and is never uploaded.
A cached copy of our remote configuration (landing-page URL and wishlist labels) is also kept in chrome.storage.local so a reminder click does not wait on the network.
What leaves the device
Remote configuration. On install, when Chrome starts, and when a reminder fires, the extension fetches https://mimosareset.com/remote-config.json over HTTPS. That file tells the extension which page to open and which wishlist tiles to show. Only https: URLs are accepted; anything else is ignored. This request does not include your settings or an install_id.
Feedback you choose to send. If you type a message and/or change wishlist tiles on the settings page and click Confirm, that content is POSTed over HTTPS to mimosareset.com (WordPress + Fluent Forms). The payload is: the message text, the selected wishlist ids, and an install_id. The install_id is a random UUID created the first time you submit feedback, stored in chrome.storage.sync, and reused so one person saving twice is not counted as two people. It is not derived from your name, email, Google account, or browsing. Anyone who never submits feedback never gets one. Submitting is the only time this id is sent.
Opening our pages. Clicking a reminder, the popup action, or the brand icon opens a tab on our sites:
- Break content on mimosareset.com, with your current wishlist ids as
?want=(for example?want=stretch,play) so the page can show what you asked for. - The brand site mimosatimer.com, with
utm_source=extand autm_mediumnaming which button was clicked, so we can tell the popup apart from the settings page. No settings orinstall_idride on that link.
Those tabs are ordinary website visits. We do not read other sites you have open.
What we never do
- No analytics SDKs, tracking pixels, advertising, or third-party cookies in the extension.
- We do not collect browsing history, page content, or data from websites you visit.
- We do not sell, rent, or share this data with third parties.
- We do not change notification text from the network. Greeting copy ships inside the extension.
Permissions
alarms/notifications: schedule and show break reminders.offscreen: play the reminder chime. Service workers cannot use the Web Audio API, so a hidden document plays the sound.storage: save preferences, the sound file, and the remote-config cache.host_permissionsforhttps://*.mimosareset.com/*: fetch remote-config.json and submit the feedback form. The wildcard coversmimosareset.comandwww.mimosareset.com. mimosatimer.com is opened as a tab only and needs no host permission.
Contact and deletion
Questions or a request to delete a feedback entry: https://mimosareset.com/contacts/