Legal
Privacy Policy
Effective July 12, 2026 · Version 1.0 · Publisher: AZAD Consulting
FocusFlow Focus Timer (“FocusFlow”, “we”, “us”, or “our”) is a Pomodoro-style focus timer for iPhone and Apple Watch, published by AZAD Consulting. This policy explains what data the app collects, what it doesn’t, who we share it with, and how you can exercise your rights.
We built FocusFlow with a “collect the minimum viable amount” mindset. If a feature can work on-device, it works on-device.
Short version
- Session stats stay on your device.
- We collect anonymous, aggregate usage counts to fix bugs and prioritize features — no name, no email, no user ID.
- The apps you shield during focus sessions never leave your device.
- Purchase state is handled by Apple, not us.
- We do not sell, share for advertising, or track you across other apps and websites.
What we collect
Session statistics — on-device only
Focus session length, session type (work / short break / long break), completion timestamps, and streak counters are stored locally on your device using Apple’s SwiftData framework. This data:
- never leaves your device,
- is not backed up to our servers (only your own iCloud backups, if you have those enabled),
- is deleted when you delete the app.
Anonymous analytics — TelemetryDeck
We send anonymous, device-level “signal” events to TelemetryDeck — a privacy-first analytics service based in Germany. Examples of signals: app_launched, session_started, paywall_shown, purchase_completed.
Each signal contains:
- the signal name,
- a hashed, non-reversible device identifier that changes at least every 24 hours,
- coarse app metadata (app version, iOS major version, device model class).
Signals do not contain: your name, email, precise device identifier, IP address (TelemetryDeck strips it before storage), location, contacts, task content, or any identifier we can link back to you.
You can opt out of analytics entirely in Settings → Privacy → Share anonymous analytics.
Family Controls selections — on-device only
If you enable Focus Shield (a FocusFlow Plus feature), you pick which apps to block via Apple’s system-provided app picker. Apple returns opaque tokens — even we can’t see which apps you picked. The tokens are stored in an on-device Keychain entry and used only to activate the shield during a focus session. They are never uploaded.
The shield itself is applied by Apple’s ManagedSettings framework, on-device, and cleared automatically when the session ends.
Purchases — via Apple StoreKit
If you subscribe to FocusFlow Plus, the transaction is handled by Apple’s StoreKit. We receive a signed receipt confirming your subscription state — nothing more. Apple’s privacy policy applies to the payment flow. Refunds and cancellations happen through your Apple ID subscription page, not through us.
Crash reports — Apple’s opt-in mechanism
If you have opted in to sharing analytics with app developers in iOS Settings → Privacy & Security → Analytics & Improvements, Apple sends us anonymous crash reports. We use them to fix bugs. If you have not opted in, we get nothing.
What we do not collect
We do not collect, at any time, in any place:
- Your name, email address, phone number, or Apple ID
- Contacts, calendar, or photos
- Location (precise or coarse)
- Health data
- Web browsing history
- The names of specific apps you shield
- Message content, task content, or notes you type
We have no server-side user database. There is no login. There is no account.
Third-party services
- Apple StoreKit / App Store — purchase state, in-app purchases and subscription management. Privacy policy.
- TelemetryDeck (Telemetry Deck GmbH, Germany) — anonymous signal names and rotating device hash, for product analytics. Privacy policy.
- Apple crash reporting — opt-in, anonymous crash traces, for bug fixing. Privacy policy.
- Vercel Analytics (this landing page only) — aggregate, cookieless page-view counts for
getfocusflow.io. No cross-site tracking. Privacy policy.
We do not integrate with Facebook, Google, ByteDance, X, Snap, or any other advertising or tracking SDK.
How long we keep data
- Session stats: kept on your device until you delete them or the app.
- TelemetryDeck signals: retained for up to 90 days in aggregate. The rotating device hash prevents linking signals across days.
- Purchase state: retained as long as your subscription is active, per Apple’s rules.
Your rights
Depending on where you live, you have specific rights over your data.
GDPR (European Economic Area & UK)
- Access — Since we don’t store personal data on our servers, we can only confirm this in writing. Your on-device data can be inspected inside the app itself.
- Erasure — Delete the app to erase local session data. Email us to have any historical TelemetryDeck aggregate excluded from analysis.
- Portability — Session stats can be exported as CSV from Settings → Data → Export (v1.1).
- Object / restrict — Turn off analytics in-app to stop future signals.
CCPA / CPRA (California)
- Right to know — This policy is the disclosure. We do not sell or share personal information for advertising.
- Right to delete — Same as GDPR erasure above.
- Right to opt-out of sale/sharing — Not applicable — we do not sell or share personal information.
- Right to non-discrimination — We will not treat you differently for exercising your rights.
To exercise any right, email hello@getfocusflow.io with the subject line “Privacy request”. We respond within 30 days.
Children’s privacy
FocusFlow is rated 4+. We do not knowingly collect personal data from children, and the analytics we do collect are anonymous and cannot identify a specific person of any age. If you are a parent and believe your child has provided us with data through a bug or misfeature, please contact us and we will delete it.
Security
We rely on Apple’s on-device sandboxing and Keychain for stored data. Transport to TelemetryDeck and Apple is over TLS 1.2+ only. There is no server-side user account for an attacker to compromise.
International transfers
TelemetryDeck operates servers in the European Union. Apple operates worldwide. When you use FocusFlow, anonymous analytics data may transit through these locations. No user-identifying data is transferred.
Changes to this policy
If we change how we collect data, we will publish a new version of this policy at getfocusflow.io/privacy and bump the version number and effective date at the top of this document. Material changes will be surfaced in-app on next launch.
Contact
For any question, exercise of rights, or bug report about privacy:
Email: hello@getfocusflow.io
Publisher: AZAD Consulting