Privacy
Privacy Policy
Last updated: August 27, 2026 · v2.1
This page explains in plain language which data Focus Garage and the focusgarage.app website collect, why each item is needed, and what we do not do with it.
Who controls the data
The data controller is the developer responsible for Focus Garage, identified as the seller on the app's official App Store page. The service is operated from Brazil. You can send requests about your data to the email address at the end of this page.
No formal data protection officer (DPO) has been appointed. You can contact the developer directly at the same address.
In short: the app collects the minimum required for your account to exist and for your garage to follow you across devices. It does not sell your data, use it for advertising, read your health history, or see the content of apps you block during a focus session.
Account
You sign in with Sign in with Apple or Google. We store the identifier returned by the provider, your email address, and the name you enter during onboarding. This lets us recognize you if you reinstall the app or change devices.
If you use Sign in with Apple and choose “Hide My Email,” we receive Apple’s relay address and never receive your real email address.
Accounts are stored in Supabase, our database and authentication provider, which processes this data on our behalf.
If you choose a profile photo, we store the image in a private Supabase Storage area. It is used only to display your profile in the app, and you can remove it.
Subscription
Payment itself is processed by the App Store. The subscription is managed through RevenueCat, which processes the following data on our behalf:
- your Supabase account identifier, used as the RevenueCat App User ID so the subscription stays connected to the correct account;
- the App Store receipt issued by Apple for the purchase;
- the products you purchased and the dates of purchase, renewal, expiration, and cancellation;
- technical app and device data: model, operating-system version, app version, country, and time zone.
This information answers the question the app needs to ask continuously: whether your subscription is active and which plan it belongs to.
We do not see your payment information. Card numbers, billing addresses, and payment processing stay with Apple. Neither we nor RevenueCat can access them. We retain only the transaction history described above, meaning what was purchased and when. This is the minimum needed to keep the subscription working.
Focus sessions
We store each session’s duration, when it took place, whether it was completed, and which car it earned. Your garage, streak, and statistics are built from these records. Without them, there is no collection.
We do not record what you were doing during the session: not the app you had open, what you typed, audio, or your screen.
Health (optional)
If you allow it, the app writes each completed session to Apple Health as mindful minutes. This permission is write-only.
The app never reads anything from your health history. It does not know your weight, sleep, heart rate, or anything else stored in Health. The permission works in one direction, and refusing it does not remove any Focus Garage feature.
App blocking (optional)
If you enable blocking during focus, the app uses Apple’s Screen Time framework to prevent the apps you choose from opening. Your choices are made inside a system component: we cannot see which apps you selected or what happens inside them.
Usage and diagnostic data
The app uses Firebase Analytics to measure events such as onboarding completion, session starts and outcomes, paywall source, subscription starts, selected plan, and feature use. Firebase may also generate technical events such as first open, session start, engagement, and screen view.
Firebase Crashlytics receives crash reports, stack traces, app and operating-system versions, device model, and the technical state needed to diagnose a problem. Recent Analytics events may accompany a crash report as diagnostic context.
We do not configure a name, email address, or account identifier in Firebase. We do not use IDFA, request tracking permission, use this data for advertising, or track you across other companies' apps and websites.
The focusgarage.app website
The website consists of static files, with no analytics installed in your browser, cookies, tracking pixels, identifiers, or forms. There is nothing to type and nothing to submit.
Hostinger, which hosts the site, creates ordinary server-side technical logs for each request. They may include an IP address, timestamp, requested path, response or error code, and device and browser information supplied by the user agent. hPanel may also show us aggregate reports for requests, approximate distinct IPs, countries, devices, bandwidth, and errors. We do not connect these records to app accounts or use them for advertising or cross-site tracking.
A “let me know when it launches” form once existed here and stored the email address of anyone who asked to be notified. It was removed before the app launched, and the list it created was deleted: the active table and its contents no longer exist. As with any deleted data, residual copies may remain in the database provider’s backups until its retention cycle ends. The same rule applies to other data in the retention section. Backups are used only to restore the service after a failure, and they do not restore the list as an active table.
Legal basis for each use of data
Brazil’s LGPD requires a legal basis for every processing activity. Ours are:
- Account, profile photo, and focus sessions: performance of a contract (Article 7, V). This data provides sign-in, the profile, the garage, and collection recovery across devices.
- Subscription and transaction history: performance of a contract (Article 7, V) and compliance with legal and regulatory obligations (Article 7, II), including tax and consumer records that must be retained.
- Health data (mindful minutes): consent (Article 11, I), because health data is sensitive. This occurs only if you authorize it in Health, and you can withdraw permission at any time in iPhone Settings without losing any app feature.
- App blocking: consent (Article 7, I), given through the Screen Time permission. Because the selection stays inside Apple’s system component, we do not receive the names of the apps you choose.
- Analytics, diagnostics, and fraud prevention: legitimate interests (Article 7, IX), to understand whether flows work, fix failures, and protect subscriptions. We do not use this basis for advertising or to collect the content of what you do.
When processing relies on consent, you can always withdraw it. The only consequence is losing the feature that required that consent.
International transfers
Our providers operate outside Brazil, so your data leaves the country:
- Supabase: account, profile, photo, sessions, and collection in the region configured for the project.
- RevenueCat: subscriber identifier, receipts, and transaction history, on servers outside Brazil.
- Google Firebase: usage events, crashes, and technical diagnostics processed through Google's global infrastructure.
These providers act as processors: they process data on our behalf and under our instructions, not for their own purposes. The transfers are necessary to perform our contract with you (Article 33, VI of the LGPD) and are covered by the data-protection contract terms each provider maintains with its customers.
Apple and Google also act as independent controllers when they provide sign-in, store, or payment services under their own policies. We receive only the data needed to authenticate the account and confirm the subscription.
What the app does not do
- We do not sell or rent your data.
- We do not use your data for advertising or advertiser profiles.
- We do not track you across other companies’ apps and websites.
- We do not read your health history.
- We do not see the content of blocked apps.
How long we keep data
We keep the account, profile, photo, sessions, and collection while your account exists. When you delete the account, we remove this data from active systems, except for records we must keep to comply with law, resolve disputes, prevent fraud, or protect the service.
- Backups. The database has automatic backups, and deleted data can remain inside them until our database provider’s retention cycle ends. The retention period belongs to the provider, so we do not state a fixed number here. Backups are used only to restore the service after a failure, and deleted data is not restored as active data from them.
- Purchase records. Transaction history is kept for as long as Brazilian tax and consumer law require, even after an account is deleted, because the law prevents earlier deletion.
- Technical logs. Server-side access and error logs stay with Hostinger for its configured operational period and are used to deliver and measure site operation and investigate failures or abuse.
Security
We use Apple or Google authentication, encrypted communication in transit, account-scoped database access rules, and private photo storage. No system is invulnerable, but we limit access and review controls when the service changes.
Account deletion
You can delete your account under Profile → Account → Delete account. Deletion removes the account and associated data from active systems, including the profile, photo, sessions, and collection. We also request deletion of the linked RevenueCat customer.
Deleting your account does not cancel your subscription. Cancel it in App Store settings. These are separate flows: we manage the account and Apple manages billing. Deleting one does not affect the other. If you delete an account with an active subscription, it continues to renew and charge you until you cancel under iPhone Settings → your name → Subscriptions.
Your rights
Article 18 of Brazil’s LGPD gives you the rights below. They are free to exercise and require no justification:
- Confirmation and access. Learn whether we process your data and, if so, receive a copy.
- Correction. Correct incomplete, outdated, or inaccurate data.
- Anonymization, blocking, or deletion. Apply these measures to unnecessary, excessive, or unlawfully processed data.
- Portability. Move your data to another provider in a usable format.
- Deletion of consent-based data. If you ask us to delete it, we do, except for anything the law requires us to retain. In that situation, we tell you what must remain.
- Information about sharing. Learn which public or private entities receive your data. The international-transfer section above is currently the complete list.
- Information about withholding consent. Learn what happens if you say no. For Health and app blocking, only that feature becomes unavailable; every other part of the app continues to work.
- Withdrawal of consent. Withdraw it at any time through iPhone Settings for Health and Screen Time.
- Objection. Object to processing based on legitimate interests for diagnostics and fraud prevention. We review the request and provide a reasoned response.
We do not make automated decisions that affect you. There is no profiling, scoring, or machine-made decision about your account.
Submit a request by email using the address at the end of this page. We may ask only for the information needed to confirm that the request belongs to the correct account. We respond within the time required by applicable law.
If our response does not resolve your request, you may petition Brazil’s ANPD, the National Data Protection Authority, at gov.br/anpd. You do not have to contact us first, though doing so is often faster.
Children
Focus Garage is not intended for children under 13, and we do not knowingly collect data from anyone below that age.
Changes to this policy
If something changes, we update this page and the date above. Material changes are also announced inside the app.
Contact
For privacy questions or requests about your data, email contato@focusgarage.app.