Privacy Policy

Last updated: February 2025

This Privacy Policy is designed to comply with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.

1. Introduction

Focuh ("we", "our", or "the Service") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our productivity application.

2. Data Controller

Focuh acts as the data controller for the personal data processed through the Service. For any questions regarding your data, you can contact us through the application.

3. Data We Collect

We collect and process the following categories of personal data:

3.1 Account Information

  • Email address (provided via authentication provider)
  • Name (if provided via authentication provider)
  • Profile picture (if provided via authentication provider)
  • Authentication identifiers

3.2 User-Generated Content

  • Tasks and to-do items you create
  • Goals, including the notes you write about what is blocking them
  • Journal notes (daily free-form text)
  • Scheduled events and time blocks
  • Focus session data and productivity metrics
  • Your blocked websites and apps preferences (sites/apps you choose to block during focus sessions)

Journal notes and goal text are encrypted in our database with a key that is unique to your account and is itself protected by a key stored outside the database. Database exports, backups and administrative tools see only ciphertext. See section 10.

3.3 Third-Party Integration Data

  • Google Calendar data (if you connect your calendar). Calendar events are fetched when you use the app and cached in your browser; they are not stored in our database. Refresh tokens are stored encrypted.
  • Spotify playback preferences (if you connect Spotify)

3.4 Technical Data

  • Browser type and version
  • Device information
  • IP address
  • Usage analytics (via Vercel Analytics)

4. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases:

  • Contract: Processing necessary for providing the Service you requested
  • Consent: For optional features like third-party integrations
  • Legitimate Interest: For improving the Service and security purposes

5. How We Use Your Data

We use your data to:

  • Provide and maintain the Service
  • Authenticate your identity
  • Sync your tasks with Google Calendar (if enabled)
  • Play music during focus sessions (if Spotify is connected)
  • Improve and optimize the Service
  • Ensure the security of the Service

6. Website & App Blocking (Desktop App)

The Focuh desktop app includes optional website and app blocking during focus sessions. This feature requires macOS Accessibility permission to function. Here is exactly what happens with your data:

  • What we store: Only the list of websites and apps you choose to block (your preferences). This is stored on our servers so your settings sync across devices.
  • What we do NOT do: We do not track, log, monitor, or store your browsing history, the websites you visit, or the apps you use. We have no visibility into your browsing activity.
  • How blocking works: When you start a focus session, your blocklist is sent to the desktop app on your device. All blocking happens locally on your Mac — no browsing data ever leaves your device.
  • Accessibility permission: macOS Accessibility permission is used solely to detect and close blocked apps during focus sessions. It is not used for any form of monitoring or data collection.

7. Data Sharing and Third Parties

We may share your data with the following third-party service providers:

  • Clerk: Authentication and user management
  • Convex: Database and backend services
  • Vercel: Hosting and analytics
  • Google: Calendar integration (only if you connect your account), and favicon lookups for the domains of links you attach to tasks
  • Resend: Transactional email (welcome email)
  • Spotify: Music playback (only if you connect your account)

AI assistants you connect. If you connect Focuh to an AI assistant (for example Claude, ChatGPT or Grok via the MCP integration), that assistant can read and write your tasks, goals, calendar, focus statistics and journal notes on your behalf. That data is then processed by the assistant's provider under their terms. You can disconnect any assistant at any time in Preferences → MCP.

Community visibility. If you opt in to the community leaderboard, your display name, profile picture, focus minutes and streaks are visible to other users and on public pages. New accounts take part anonymously by default: your focus time is shown as "Anonymous" with no name or picture until you turn on "Show my name and photo", and you can leave the leaderboard entirely, in Preferences → Community. Your task names are never shown to other users.

We do not sell your personal data to third parties.

8. Data Retention

We retain your personal data for as long as your account is active. You can export everything you have created and delete your account, including all of your data, from Preferences → General at any time; deletion is permanent and completes within minutes. Short-lived sign-in and authorization records are removed automatically within minutes of expiring, and leaderboard rank history older than two years is deleted automatically.

9. Your Rights (GDPR)

Under GDPR, you have the following rights:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Request limitation of how we use your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time

To exercise these rights, please contact us through the application.

10. Data Security

All data is transmitted over TLS and stored on infrastructure that is encrypted at rest. In addition, your journal notes and goal text are encrypted at the application level with a data key unique to your account (AES-256-GCM). Each user's key is itself encrypted with a master key that is held in the application runtime, not in the database, so a copy of the database alone cannot reveal these fields. Google refresh tokens are encrypted with a separate key that the database never holds. API keys are stored only as one-way hashes, expire after a year, and can be revoked individually.

No system is perfectly secure and we cannot guarantee absolute security. If you believe your account has been compromised, revoke your API keys in Preferences → MCP and contact us (section 16).

11. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

12. Cookies and Local Storage

We use local storage to save your preferences and cache data for performance. This includes:

  • Authentication session (managed by Clerk)
  • User preferences (audio settings, calendar preferences, theme)
  • Cached task data and recently viewed calendar events, so the app opens instantly. These caches are cleared when you sign out.

Desktop app journal folder. If you enable the Journal feature in the macOS app and choose a folder, your notes are also written to that folder as plain Markdown files so you can edit them with other tools. Those files are stored unencrypted on your computer under your control; delete the folder or turn the feature off to stop the mirroring.

13. Children's Privacy

The Service is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a child, please contact us immediately.

14. Changes to This Policy

We may update this Privacy Policy at any time. We will notify you of significant changes by posting a notice in the application. Your continued use of the Service after changes constitutes acceptance of the updated policy.

15. Supervisory Authority

If you are in the EU/EEA and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local Data Protection Authority.

16. Contact

For any questions about this Privacy Policy or to exercise your data protection rights, please contact us through the application.