FinnFocus Privacy Policy
Effective date: 24 August 2025 App: FinnFocus (mobile application for productivity / Pomodoro timer) Controller: Eventstream Limited, Guinness Enterprise Centre, Taylors Lane. Dublin 8 D08ET2R Contact: info@eventstream.tech This policy explains what personal data we collect when you use FinnFocus, why we collect it, how we use it, and the rights you have. It is written to meet the requirements of the EU GDPR and the UK GDPR.1) Who we are
FinnFocus is a mobile productivity app. For the purposes of data protection law, Eventstream is the data controller of your personal data processed in and through the app. If we use trusted third parties to process data on our behalf, they act as processors (see §7).2) What this policy covers
This policy applies to your use of the FinnFocus app on iOS and Android and to any support you request from us by e‑mail. It does not cover third‑party websites or services you may access via external links.3) The data we collect
We aim to collect and process only what is necessary to deliver and improve the app.A. Data you provide
- Account details (if you create an account): e‑mail address, display name (optional), authentication provider.
- Support messages: the content of any e‑mails you send us and your contact details so we can reply.
B. Data generated on your device (stored locally by default)
- Tasks, sessions and settings you create in the app (e.g., Pomodoro sessions, task names/colours, preferences). By default these remain on your device in local storage (SQLite) and are not uploaded to our servers.
C. Data collected automatically
- Identifiers: authentication identifiers (e.g., Firebase UID if you sign in), and a push notification token if you opt‑in to notifications.
- Diagnostics & performance: basic crash logs and performance data provided by your device and/or platform services to help us keep the app reliable.
- Usage analytics (limited): high‑level, aggregated events (e.g., feature usage) to help us understand what works and improve the app. These events are not used for advertising or profiling.
We do not intentionally collect sensitive categories of data, location data, payment information, or user‑generated content beyond your task names and settings. FinnFocus contains no in‑app advertising.
4) Purposes & legal bases
We process your data for the following purposes and under these legal bases:| Purpose | Legal basis |
|---|---|
| Provide core app functionality (authentication, settings, notifications) | Performance of a contract (Terms of Use) |
| Keep the service secure, prevent abuse, and debug issues | Legitimate interests |
| Send push notifications you enable (e.g., session reminders) | Consent (which you can withdraw at any time via device settings) |
| Respond to support enquiries | Legitimate interests / Performance of a contract |
| Improve app quality and user experience via anonymous/aggregated insights | Legitimate interests |
5) Optional features & future changes
- Cloud sync (optional): If/when we introduce an opt‑in cloud synchronisation or backup service, we will clearly explain what additional data would be uploaded (e.g., tasks/sessions) and update this policy before you choose to enable it.
- Marketing: We do not send marketing communications from the app. If this changes, we will ask for your consent first.
6) Your choices
- Account creation is optional. You can use FinnFocus without an account; your data stays on your device.
- Notifications: You can enable/disable app notifications at any time in your device settings.
- Access & export: You can view your tasks and sessions in the app. If you require an export, contact us (see §12).
- Account deletion: If you created an account, you can delete it in Settings → Account → Delete account (or contact us). Deleting your account removes authentication data we control and de‑links your device. Local data stored on your device remains until you uninstall the app or delete it in app settings.
7) Sharing & recipients
We do not sell your personal data. We share data only with trusted service providers acting under a contract with us and solely for the purposes in §4:- Authentication (Firebase Authentication): to manage sign‑in via e‑mail/password, Google Sign‑In, or Sign in with Apple.
- Push notifications (Apple/Google push services): to deliver notifications you enable.
- Analytics/Crash reporting (platform services; limited scope): to maintain reliability and app performance.
8) International transfers
Some processors may store or access data outside the EEA/UK. Where this occurs, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and UK Addendum, or an adequacy decision, as applicable.9) Retention
- Account data: kept while your account is active and for up to 24 months after last activity to manage queries and security, unless you request earlier deletion.
- Support e‑mails: retained for up to 24 months for audit and quality purposes.
- Diagnostics/analytics: retained in aggregated/non‑identifiable form where possible and typically for no longer than 24 months.
- On‑device data: remains on your device until you delete it or uninstall the app.
10) Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, hardened authentication flows, and access controls. No method of transmission or storage is 100% secure; we continually work to improve our safeguards.11) Your rights (EEA/UK)
You have the right to request: access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time. You also have the right to lodge a complaint with your supervisory authority:- Ireland: Data Protection Commission — www.dataprotection.ie
- United Kingdom: Information Commissioner’s Office — www.ico.org.uk
12) Contact us
For any privacy questions or requests, please contact: E‑mail: [privacy@yourdomain.com] Postal: [Data Protection, Your legal entity name, full address]13) Children
FinnFocus is not intended for children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps.14) Changes to this policy
We may update this policy to reflect changes to the app or legal requirements. We will indicate the latest effective date at the top and, where appropriate, notify you in‑app or by e‑mail.15) Store disclosure summaries (for your listings)
Apple App Privacy (summary)
- Data linked to you: Contact info (e‑mail, if you create an account); Identifiers (auth UID, push token); Diagnostics (crash data); Usage data (basic interactions).
- Not collected: Precise location, financial info, health data, contacts, browsing history, purchases, photos/videos (beyond what you create as text tasks), or other sensitive data.
- Data use: App functionality, analytics, diagnostics. No tracking for advertising.
Google Play Data Safety (summary)
- Collected: E‑mail (account), app interactions (aggregated), crash logs, device or other IDs (auth UID/push token).
- Shared: Not sold or shared for advertising. Disclosed only to processors for app functionality and diagnostics.
- Security: Data is encrypted in transit; you can request deletion of account data.
- Optional: Most collection occurs only if you sign in or enable notifications.
Implementation note for your team: keep this policy aligned with the app. If you introduce cloud sync or additional analytics, update §3–§5 and the store summaries before release.
Version history
- v1.0 (24 Aug 2025): Initial publication aligned to current feature set (local storage by default; Firebase Authentication; optional notifications; limited diagnostics/usage analytics).
