Exit Friction
Counts the clicks a cancellation flow actually makes you take, and flags every retention trick along the way.
ExitFriction
Counts the clicks a cancellation flow actually makes you take, and flags every retention trick along the way.
Date: 2026-09-28
Form factor: Browser extension (Manifest V3)
Browser surface: toolbar popup, on-demand content script (via activeTab + scripting), chrome.storage
Status: Prototype
What it is
ExitFriction sits in the toolbar while you cancel something. On every page of the flow — the account settings screen, the retention modal, the "are you sure" pop-up, whatever comes next — you click Log this step, and it scans that page for the specific moves that make cancellation harder than sign-up: buried cancel links, "wait, before you go" offers, pre-checked "keep my plan" boxes, guilt-trip copy, countdown timers, and pages that tell you cancellation requires a phone call. Each flag adds points to a running friction score. At the end, you export a plain-text log of exactly what you clicked through and what was flagged at each step.
Why it has to be an extension
The dark patterns ExitFriction looks for live in the rendered page: text size, checkbox state, modal copy, computed styles. None of that is visible to anything outside the tab, and a cancellation flow usually spans several pages on a domain you don't control, so there's no API to query it from the outside. Reading it means running inside the tab, scanning the live DOM with the actual computed font sizes and checked states, right as you click through — which is what a content script does and a website cannot.
Who it serves
Anyone in the middle of canceling a subscription, membership, or trial who wants a record of what the company made them do to leave — not a general phone-and-fine-print advice article, but a log built from the specific flow they just sat through. It's most useful the moment a cancellation goes sideways: a hidden link, a surprise "call us" screen, a checkbox that was checked before you read it.
Why it could be profitable
Free tier: everything in this prototype — manual, step-by-step tracking and a plain-text export. Paid tier ($3–4/month): automatic tracking that follows you through the flow without a click per page, a saved history across every service you've canceled, and a formatted complaint packet pre-filled with the logged evidence and citations. A second, likely steadier line is B2B — consumer-rights clinics and plaintiffs' firms already build cancellation-friction cases one flow at a time; a tool that logs the flow as evidence while it happens is worth more to them than a screenshot taken after the fact.
The regulatory backdrop is current and moving: Adobe settled with the DOJ and FTC for $150 million in March 2026 over exactly this pattern — hidden termination fees and a cancellation flow that took multiple steps and phone calls to complete. The FTC's 2024 click-to-cancel rule was vacated on procedural grounds in 2025, but the agency opened an Advance Notice of Proposed Rulemaking in March 2026 to revive it, and it's still bringing cases under Section 5 of the FTC Act in the meantime. What's untested is whether an individual user cancelling one subscription will pay for a tracker rather than just calling their bank for a chargeback — the demand case here rests on the B2B and complaint-evidence angle more than on casual consumer use.
How to load it in Chrome
- Open
chrome://extensionsand turn on Developer mode. - Click Load unpacked and select this folder's
extension/directory. - Visit a subscription's cancellation flow, click the ExitFriction icon, and click Log this step on each page as you go. (This prototype ships without a custom icon, so Chrome shows its default puzzle-piece badge for the toolbar button.)
How to try the demo
- Open
index.htmldirectly in a browser — the mock flow's data is also embedded inline in the page, so it works straight fromfile://with no server. - Click the ExitFriction icon in the mock toolbar to open the popup.
- On each mock page, click Log this step in the popup first, then click the flow's own exit link (e.g. "Cancel Membership," "No thanks, continue canceling") to move to the next page.
The demo simulates content.js's DOM scan with pre-computed findings for each mock step, since there's no live tab for chrome.scripting to inject into — the popup's scoring, step log, and export logic is the same extension/popup.js that ships in the real extension.
Permissions, and why each one
| Permission | Why it's needed |
|---|---|
activeTab |
Lets the popup ask for the tab you're currently viewing, but only for the instant after you click Log this step — no standing access to your browsing. |
scripting |
Injects content.js into that one tab, on that one click, to scan the current page. |
storage |
Keeps the running session log per hostname, so closing and reopening the popup mid-flow doesn't lose your progress. |
There's no host_permissions entry and no <all_urls>. ExitFriction never touches a page until you click Log this step on it.
What's in this prototype
- Six detection heuristics: retention offers, guilt-trip language, phone-only cancellation, pre-checked retention checkboxes, de-emphasized ("buried") cancel links, and countdown/urgency timers.
- A running friction score with three risk bands (clean, low/moderate friction, high friction) shown live as you log steps.
- On-page outlining and labels pointing at each flag, in the real extension.
- A plain-text evidence export listing every step, every flag, and the total score, with a paragraph citing the relevant FTC rule and precedent.
- A five-step demo flow (StreamFlix mock cancellation) with all six pattern types planted across it.
Roadmap
- Automatic tracking as you navigate, instead of one click per page
- Saved history across every service you've tried to cancel
- A formatted, ready-to-file complaint packet for the paid tier
- A shared, anonymized pattern library built from real flows instead of a hand-written heuristic set
- A Firefox-compatible build
Sources
- Jones Day: FTC Revives Click-to-Cancel Rule — New Risks for Subscription Businesses — the rule's 2025 vacatur and the March 2026 rulemaking to revive it
- Bloomberg: Adobe Subscription Cancellation Lawsuit Settled for $150 Million — the settlement this README cites as precedent
- MLex: Adobe settles US FTC's hard-to-cancel subscription case for $150 million — case background on the obscured fees and multi-step cancellation flow
Requirements
ExitFriction — Requirements
Goals
- Let a user score any cancellation flow for dark patterns as they click through it, without needing to know the site in advance.
- Turn that scoring into a portable, plain-text evidence log a user can attach to a chargeback dispute or a regulatory complaint.
- Keep the permission footprint minimal enough that the extension only ever touches a page the user explicitly asked it to scan.
Primary user
Someone actively canceling a subscription, membership, or free trial who wants proof of what the cancellation flow made them do. They are mid-task, not researching in the abstract — they land on ExitFriction because the flow they're in already feels manipulative and they want a record before they close the tab.
Functional requirements
- FR1: The popup shows the current session's friction score, risk label, and hostname on open.
- FR2: Clicking "Log this step" scans the current page for dark-pattern signals and adds the result to the session as a new step.
- FR3: In the real extension, the scan runs via an on-demand content script injected through
chrome.scripting.executeScript, scoped to the active tab only. - FR4: The scanner detects at minimum: retention-offer language, guilt-trip language, phone-only cancellation notices, pre-checked retention checkboxes, de-emphasized ("buried") cancel controls, and countdown/urgency timers.
- FR5: Each detected pattern carries a point value; a step's score is the sum of its flagged patterns.
- FR6: The session's total friction score is the sum of all logged steps' scores, updated live as steps are added.
- FR7: The popup displays a risk band derived from the total score (clean, low/moderate friction, high friction) with distinct visual treatment for each.
- FR8: The popup lists every logged step with its label, per-step score, and the pattern tags found on it.
- FR9: "Export report" produces a downloadable plain-text file listing the session's host, step count, total score, per-step findings, and a paragraph citing the relevant regulatory context.
- FR10: "Reset" clears the current session's logged steps and score without requiring a new tab or reload.
- FR11: The real extension persists the session per hostname via
chrome.storage.local, so closing and reopening the popup mid-flow does not lose progress. - FR12: The extension requests no permission it does not use in code, and declares no
host_permissionsor<all_urls>match pattern. - FR13: The demo harness reproduces the same popup markup, styling, and scoring logic as the real extension, sourced from the same
popup.html/popup.css/popup.jsfiles. - FR14: The demo's mock cancellation flow plants at least one example of every detection heuristic across its steps.
User stories
- As someone canceling a subscription, I want to log each page of the cancellation flow as I go, so that I have a record of what happened without reconstructing it from memory afterward.
- As someone who just hit a "call us to cancel" wall, I want that flagged automatically, so that I don't have to know in advance that it counts as a dark pattern.
- As someone filing a complaint, I want a plain-text export with the specific flagged language and a citation to the relevant rule, so that I don't have to write the framing myself.
- As a privacy-conscious user, I want the extension to only read a page when I click a button on it, so that it isn't silently watching every tab I open.
- As someone comparing this tool to a paid one, I want the free tier to be genuinely useful on its own, so that I can decide whether the paid tier is worth it after using the basics.
Extension surfaces
- Toolbar popup — the only UI surface; shows the running score, step log, and export/reset controls.
- On-demand content script (
activeTab+scripting) — runs once per "Log this step" click, scans the current page, and outlines flagged elements in place. chrome.storage.local— persists the per-hostname session between popup opens.
Non-functional requirements
- Privacy: no network calls, no analytics, no data leaves the browser. The content script only runs on user-initiated clicks.
- Permission minimalism:
activeTab,scripting, andstorageonly — no standing host access. - Performance: a scan of a typical cancellation page (well under 1,000 DOM nodes) should complete in well under a second.
- Accessibility: popup controls are keyboard-reachable buttons with visible focus states; risk bands are distinguished by both color and text label, not color alone.
Out of scope (for the prototype)
- Automatic, click-free tracking as the user navigates (paid-tier roadmap item).
- Cross-device session sync or a saved history across multiple past cancellation attempts.
- A pre-filled, submission-ready FTC or state AG complaint form.
- Any server-side component; everything in this prototype runs client-side.
Open questions
- Whether font-size and checkbox-state heuristics generalize well enough across real sites, or whether they need per-site tuning once used against live flows.
- Whether a consumer will pay for this directly, versus the tool being more valuable as evidence-gathering infrastructure sold to consumer-rights organizations.
- Whether Manifest V3's activeTab model is permissive enough for a "continuous tracking" paid tier, or whether that requires optional host permissions requested per session.