Privacy notice
Last updated: 2026-05-10 · v1 (private beta)
What we collect
- Email address — for sign-in (magic links). Stored as plaintext on our server; we need it to send you mail.
- Tasks, time events, and presence states you create or sync. We never read these for analytics.
- Integration tokens (Slack OAuth access token, etc.) when you connect them. Application-layer encryption is not yet implemented; we plan to add it.
- IP address and User-Agent on each request — for rate limiting and to populate the audit log.
What we don't do
- No advertising trackers. No third-party analytics.
- No selling, renting, or sharing your data.
- No reading your task contents for marketing or training models.
Sub-processors
A summary appears below; the full list with operating regions is on its own page.
- Brevo (sendinblue.com) — sends magic-link and account-action emails. Receives your email address and the link content. EU-based, GDPR-compliant.
- OpenRouter (openrouter.ai) — when you use the AI summary feature, we send the task title and description to OpenRouter, which routes to OpenAI/Anthropic models. The summary comes back to us; we store it. We do NOT send your name or email along with the prompt.
- Stripe (stripe.com) — when configured, processes Pro plan payments. Stripe sees your email and payment details directly; we never see card numbers.
- Slack (slack.com) — when you connect Slack presence sync, we send your status text to Slack on your behalf. Slack stores its own copy.
- Cloudflare — DNS, edge proxy (TLS termination, DDoS protection), and Cloudflare Access for the admin console. Sees request metadata (IP, User-Agent, path); request bodies are not retained beyond TLS termination.
Data export and deletion
Settings → Your data lets you download your tasks and time events as CSV at any time. Settings → Danger zone lets you delete your account; we soft-delete immediately, hard-delete after 30 days.
Where data lives
Production servers are in the United States (Hostkey VPS). Brevo and Stripe operate their own infrastructure (EU and US respectively).
Cookies
One cookie: focus_session — a JWT used to keep you signed
in. HttpOnly, Secure, SameSite=Strict. Expires after 30 days. No
analytics cookies, no advertising cookies.
Contact
Questions or data requests: open an issue at the project's GitHub repo (or email the address you got the magic link from — same person on the other end during the private beta).