Privacy Policy 

Privacy Policy for Bodo Focus
Effective Date: February 10, 2026

This Privacy Policy explains what personal data is collected when you use the mobile application “Bodo Focus” (the “App”) and the services provided through it (together with the App, the “Service”), how such personal data is processed, and for what purposes.

Bodo Focus helps users reduce excessive screen time and build healthy focus habits by using Apple Screen Time and Family Controls APIs to allow users to voluntarily limit access to selected applications on their own devices.

If you create an account, we may collect and store your phone number solely for the purpose of authentication via one-time password (OTP). Phone numbers are used only to verify your identity and enable secure access to the Service and are not used for marketing or shared with third parties for advertising purposes. Authentication services are provided via third-party providers such as Firebase or Auth0.

If you decide to purchase a subscription, payments are processed by Apple (In-App Purchases) or by third-party payment processors (such as Stripe via RevenueCat). We do not collect or store full payment card details. Depending on the payment method, we may receive limited transaction-related information, such as subscription status, purchase date, renewal status, and anonymized identifiers.

We may automatically collect certain technical and usage information from your device, including language settings, IP address, time zone, device type and model, operating system version, application version, and anonymized identifiers (such as IDFV). This data is used strictly to operate and improve the Service, ensure security, diagnose errors, and analyze aggregated usage trends.

For analytics and service improvement purposes, we use third-party tools and services provided by Amplitude, Firebase, RevenueCat, and Stripe. As a result, some data may be processed and stored on the servers of these providers in accordance with their respective privacy policies. We use these tools to understand how users interact with the App, improve functionality, and measure subscription performance.

The App does not use Apple’s App Tracking Transparency framework and does not track users across apps or websites owned by other companies.

We do not sell personal data. We do not knowingly collect or process personal data of children under the age of 17. The App is intended for users aged 17 and older.

Please read this Privacy Policy carefully to understand what data we collect, how it is used, what rights you have, and who is responsible for processing your personal data. If you have any questions, please contact us at: legal@bodofocus.app

1. Personal data controller

Khyu Tkhan Nguyen Unit
a private entrepreneur registered in Poland,
registered address: ul. Warowna 3, 02-654 Warsaw
contact email: ktn.unit@gmail.com

(“we”, “us”, or “our”) is the controller of your personal data for the purposes described in this Privacy Policy.

2. Categories of personal data we collect

We collect only the personal data necessary to provide and operate the Service.

2.1. Data You Provide Voluntarily

  • Phone number — collected solely for one-time password (OTP) authentication via Firebase/Auth0.
    We do not use phone numbers for marketing purposes.

  • Email address — collected if you purchase a subscription, contact support, or request account-related communication.

We do not use email addresses for unsolicited marketing.

  • Support communications — if you contact us, we may process the information you provide in your message.

2.2. Data Collected Automatically

2.2.1. Device and Technical Data

We may collect:

  • language settings

  • IP address

  • time zone

  • device type and model

  • operating system and version

  • device settings

  • mobile carrier and Internet service provider

This data is used solely to operate, secure, and improve the Service.

2.2.2. Usage Data

We collect information about how you interact with the App, such as:

  • features used

  • focus sessions started or completed

  • time spent in the App

  • interaction with in-app content

This data is used in aggregated form to improve functionality and user experience.

2.2.3. Identifier for Vendor (IDFV)

We may collect the Identifier for Vendor (IDFV) for internal analytics and app functionality purposes.
IDFV is not used for cross-app tracking, advertising profiling, or shared with third parties for advertising purposes.

2.2.4. Transaction Data

When you make a purchase:

  • payments are processed by Apple (In-App Purchases) or authorized third-party payment providers (e.g. RevenueCat, Stripe);

  • we do not collect or store full payment card details;

  • we may receive limited transaction-related information (e.g. purchase status, date, amount, subscription type).

2.2.5. Account and App Data

We may store additional information related to your use of the Service, including:

- user identifiers (user ID, device ID)

- in-app progress (e.g. streaks, focus sessions, coins, rewards)

- profile information (e.g. username, buddy name)

- referral data (e.g. referral count)

- app settings and preferences

- push notification token (FCM token)

This data is used solely to provide app functionality, maintain user progress, and improve the Service.

2.3. Data Collection & Use Summery

The following table summarizes what personal and device-related data we collect, why we collect it, and the legal basis for processing under applicable law (e.g., GDPR for EEA users):

Data Type

Purpose

Legal Basis / Justification

Phone number

One-time password (OTP) authentication via Firebase/Auth0

Performance of contract / enabling access to Service

Email address

Account registration, subscription, and customer support

Performance of contract; consent for communication

Device information (device type, model, OS, language, time zone, IP, hardware ID, mobile carrier)

Enable app functionality, troubleshoot errors, improve Service, and provide analytics

Legitimate interest / performance of contract

Usage data (app interactions, features used, time spent)

Analyze and improve Service, personalize user experience

Legitimate interest

Identifier for Vendor (IDFV)

Device identification for analytics and app usage tracking

Legitimate interest

Transaction data (purchase date, amount, payment type)

Process subscription payments via RevenueCat/Stripe

Performance of contract

Crash reports & performance metrics

Diagnose issues and improve app stability

Legitimate interest

Family Controls / Screen Time API data

Enable app-based restrictions and track user-defined screen time limits (local device only)

Performance of Service; strictly local processing; user consent implicitly given by using feature

3. App functionality and family controls

Although Family Controls APIs are often associated with parental tools, Apple explicitly allows their use for self-regulation and personal productivity applications. Bodo Focus uses these APIs exclusively for voluntary, self-imposed limits by adult users on their own devices.

Bodo Focus uses Apple’s Screen Time and Family Controls APIs to help users manage and reduce excessive use of selected applications on their own devices.

The App allows users to voluntarily select specific apps or categories of apps (such as social media applications) and define time limits or blocking periods for their personal use. These restrictions are fully controlled by the user and can be modified or removed at any time through the App or system settings.

Bodo Focus does not access, monitor, log, store, or transmit the content of other applications, communications, messages, browsing activity, or personal files. The App does not track what users do inside restricted apps, nor does it collect screenshots, keystrokes, or detailed usage history of third-party applications.

Information obtained through Screen Time and Family Controls APIs is used solely to enable the App’s core functionality — applying user-defined app usage limits and reflecting progress through in-app feedback (such as visual reactions of the focus mascot). This information is processed locally on the device whenever possible and is not used for advertising, profiling, or behavioral targeting.

Bodo Focus does not provide parental monitoring of other users’ devices and is not intended to surveil children or other individuals. The App is designed for self-management of screen time by the user on their own device.

We do not share Screen Time or Family Controls data with third parties, except as strictly necessary to provide the Service and in accordance with this Privacy Policy and Apple’s requirements.

4. Purposes of processing personal data

We process personal data for the following purposes:

4.1. To Provide and Operate the Service

Including authentication, feature functionality, error prevention, and performance monitoring.

4.2. Customer Support and Communication

To respond to support requests and send service-related communications (e.g. security notices, subscription confirmations).

4.3. Service Improvement and Analytics

To understand how users interact with the App and improve features, usability, and stability.
We use analytics tools such as Firebase Analytics and Amplitude strictly for internal analysis and service improvement.

We do not use analytics data, identifiers (including IDFV), or usage information obtained through the App to build behavioral profiles, track users across apps or services, or for targeted advertising purposes.

Analytics data is used strictly in aggregated and anonymized form for internal service improvement and stability monitoring.

4.4. Payments and Subscriptions

To enable subscription management and confirm payment status via authorized payment providers.

4.5. Legal Compliance and Protection

To comply with legal obligations, enforce our Terms of Use, and prevent fraud or misuse.

5. Legal bases for processing (EEA users)

We process personal data based on:

  • Performance of a contract — to provide the Service and subscriptions;

  • Consent — where required (e.g. push notifications);

  • Legitimate interests — improving the Service, ensuring security and reliability;

  • Legal obligations — compliance with applicable laws.

6. Data Sharing

We share personal data only with trusted service providers acting on our behalf, including:

  • Firebase (Google) — authentication, analytics, crash reporting;

  • Amplitude — aggregated analytics;

  • RevenueCat — subscription management;

  • Stripe / Apple — payment processing.

We do not sell personal data and do not share data for third-party advertising purposes.

7. International data transfers

Personal data may be processed outside your country of residence.

Where required, we apply appropriate safeguards, including Standard Contractual Clauses approved by the European Commission.

8. Data retention

We retain your personal data only for as long as necessary to provide the services described in this Privacy Policy, including:

  • Maintaining your account and subscriptions.

  • Enabling app functionality, including Family Controls and Screen Time features.

  • Providing customer support.

  • Fulfilling legal obligations and resolving disputes.

Retention periods:

Data Type

Retention Period

Notes

Phone number (OTP authentication)

Until account deletion or deactivation

Used solely for authentication

Email address

While account/subscription is active + 1 year after termination

Used for subscription management and support

Purchases / Payment info

As required for financial and tax reporting

Stored by Stripe / RevenueCat only, not on our servers

Identifiers (IDFV, device IDs)

Up to 36 months

Used for analytics, engagement, and feature optimization

Usage Data / Analytics

Up to 36 months

Aggregated or anonymized wherever possible

Family Controls / Screen Time data

Locally on the device

Processed and stored locally; not shared externally

9. Apple app store privacy labels alignment

All data categories disclosed in this Privacy Policy are consistent with the information provided in App Store Connect under the App Privacy section.

No additional data is collected beyond what is disclosed.

10. Your privacy rights

You have the following rights regarding your personal data:

  • Access & correction – You may review, update, or correct any personal data you provided.

  • Deletion / erasure – You can request deletion of your personal data. Note that some data may need to be retained for legal obligations or dispute resolution.

  • Restriction / objection – You can request that we restrict processing or object to certain uses of your personal data.

  • Data portability – You may request your personal data in a structured, machine-readable format.

How to exercise your rights:

To exercise any of your privacy rights, contact us at legal@bodofocus.app. We will respond to your request in accordance with applicable law.

EEA users also have the right to lodge a complaint with a supervisory authority.

11. Age limitation

The Service is intended for users 17 years of age and older.
We do not knowingly process personal data of persons under 17.

12. Changes to this policy

We may update this Privacy Policy from time to time.
Material changes will be communicated through the App or by email.

13. Contact us

For questions about this Privacy Policy, contact:
Bodo Focus Support
Email: legal@bodofocus.app

Link for App Store Connect: https://bodofocus.app/privacy