Privacy Policy
This document is published in English; the English version is authoritative. Contact us with any questions.
1. Who we are
FocusFlow is operated by Fatih Çolak, an individual developer based in Istanbul, Türkiye ("we", "us"). This policy explains what data the FocusFlow mobile app and its backend services process, why, and what controls you have. For any privacy question or request, contact us at support@focusflowmobile.com.
2. Guest-first by design
FocusFlow works without an account. On first launch the app creates a random identifier (UUID) that is not linked to your name, email, or any real-world identity. The timer and planner never ask for an email. Creating an account (adding an email and password) is only needed for cross-device sync recovery and PRO purchases.
3. Data we process
- Random user identifier (UUID): created automatically for sessions, sync, co-working rooms, and subscription entitlement mapping. Deleted when you delete your account.
- Email address: only if you link a permanent account; used for login, recovery, and verification. Deleted with account deletion.
- Password: never stored in plain text; we keep only a bcrypt hash.
- Session tokens: the raw refresh token stays in your device's secure storage; our servers store only a SHA-256 hash, with rotation and revocation.
- Your content: tasks, subtasks, tags, due dates, routines, rewards, brain-dump entries, and focus sessions — processed to provide the product and, for synced data, stored in our database. Deleted with account deletion.
- Focus statistics: session logs and optional state ratings used for your insights screens. Deleted with account deletion.
- Co-working room presence and chat: processed in memory only for live rooms; we keep no permanent chat history. Room data is discarded when the room ends.
- Subscription status: received from Apple/Google via RevenueCat to unlock PRO features, handle restores, and support you. Deleted with account deletion.
- Usage analytics: off by default. Only if you opt in, normalized product events are sent to Firebase Analytics. Task titles and email addresses are never sent as event parameters. You can turn this off at any time in Settings.
- AI task-splitting input: when you actively use the AI task splitter, the goal title you typed is sent to NVIDIA's AI gateway to generate micro-steps. Only that title is sent — no account identifier, email, or other task is included. We do not otherwise store the prompt or response. If the AI is unavailable, the app says so and falls back to a list of micro-steps built into the app itself — in that case nothing is sent anywhere at all.
- Family Mode data: if you pair a child's account with a guardian, we store the link between the two accounts, the guardian's current shield wish (on/off, an optional end time, and a version counter), and the child device's brief status report: the platform (iOS/Android), whether the shield is applied, how many apps are selected, whether the protection is still intact, and a timestamp. Invite codes are stored only as SHA-256 hashes and expire after 15 minutes. We never receive which apps were chosen — on iOS the selection is an opaque token Apple does not let apps read, and on Android the chosen app names never leave the device. We collect no app-usage data, no screen-time reports, no location, and no message or browsing content, from any device. Family Mode data is deleted when the link is removed or the account is deleted.
- Push notification token: if Family Mode is in use, the device's Firebase Cloud Messaging token is stored so a guardian's change can wake the child's device promptly. The pushes are silent and carry no content beyond "synchronize now". Tokens are removed on logout and pruned automatically when they stop working.
- Technical logs: standard network logs processed for security and debugging.
4. Third parties
- Apple App Store / Google Play: payment and subscription management. We never see your payment details.
- RevenueCat: converts store transactions into entitlements using your random UUID; your email is not used as the identifier.
- Firebase Analytics (Google): only with your explicit opt-in, for product quality measurement.
- NVIDIA (AI gateway): only the goal title you actively submit to the AI task splitter, with no identifier attached.
- Hosting, PostgreSQL, Redis, and off-site backups: to run the service securely and recover from disasters.
- Transactional email provider: only for email verification, password reset, and security messages.
We do not sell your data, and we do not show ads.
5. Your controls
- Use without an account — the default experience.
- Export: download your data as JSON in-app (Settings → Data) or via the account export API.
- Delete: delete your account in-app (Settings → Account → Delete account), including as a guest. Deletion permanently removes your server data, including entitlement and subscription records, via database-level cascade. A self-service deletion page for password-backed accounts is available at focusflowmobile.com/account-deletion.
- Analytics toggle: opt in or out at any time in Settings.
- Subscriptions: manage or cancel through your App Store / Google Play account; use Restore Purchases in-app.
6. Security
We use industry-standard measures: bcrypt password hashing, strict separation of access and refresh tokens with rotation and replay protection, parameterized SQL, HTTPS/WSS-only transport in production, short-lived room tickets, and webhook signature verification for subscription events.
7. Data retention
Synced data is kept while your account exists and deleted upon account deletion. Live room data exists only in memory for the duration of a room. Backups are retained for disaster recovery and expire on a rolling schedule.
8. Children and Family Mode
FocusFlow's general product is directed at adults and teens. Family Mode is the one exception: it lets a parent or legal guardian pair FocusFlow on a child's phone with their own account so they can quiet the apps chosen on the child's device. Because children can use FocusFlow through Family Mode, this section explains exactly what that involves.
Parental consent is built into the pairing itself. A child device cannot enter Family Mode on its own: the guardian creates a short-lived invite code inside their own FocusFlow and enters or dictates it on the child's phone — a setup designed to happen with the guardian present. On iOS, Apple additionally requires a parent in the Family Sharing group to approve Screen Time control on the child's device before anything can be enforced. Removing the link, from either device, ends the arrangement and deletes the shield data.
What we process about a child: the minimum needed to run the feature, listed in full under "Family Mode data" in section 3 — the account link, the guardian's shield wish, a count of selected apps, and a yes/no protection status. A child account does not need an email address; it can remain a guest account with only a random identifier. We never receive which apps the child uses or has selected, no screen-time or usage reports, no location, and no message or browsing content.
What we never do with children's data: no advertising, no selling, and no profiling — the same as for every other account. Usage analytics is off by default on every device and is never a condition of using Family Mode.
Parents' rights: a guardian can review the pairing at any time in the app, remove the link, or delete the child's account entirely (in-app or via focusflowmobile.com/account-deletion); deletion removes the server data by database-level cascade. For any question or request about a child's data — including under COPPA, the GDPR's provisions on children, or KVKK — contact us at support@focusflowmobile.com and we will respond as the law requires.
Outside Family Mode, FocusFlow remains not directed at children under 13 (or the higher minimum age required in your region), and we do not knowingly collect personal data from them. If you believe a child provided us personal data outside a guardian-paired setup, contact us and we will delete it.
9. International transfers
The third parties listed above may process data in other countries. Where required, appropriate safeguards under applicable data-protection law (including KVKK and, where applicable, GDPR) are relied upon.
10. Changes
We will update this policy when the product changes and revise the effective date above. Material changes will be announced in the app.
11. Contact
Data controller: Fatih Çolak (individual developer), Istanbul, Türkiye.
Email: support@focusflowmobile.com