Privacy Policy
Last updated: August 2026
Who is responsible for your data
Fokuzen is operated by Paul Pérez, an individual established in Uruguay, acting as the data controller. You can reach the controller at support@fokuzen.com for any question or request concerning your personal data. Processing is governed by Uruguayan Law No. 18.331 on the Protection of Personal Data, and — where you are located in the European Economic Area or the United Kingdom — by the GDPR and UK GDPR.
Beta notice
Fokuzen is currently in closed beta, available by invitation only and free of charge. Features, data structures, and this policy will change as the product develops. We will not silently reduce your privacy protections: material changes are announced by email before they take effect.
What we collect
Account and identity
Your email address, display name, and profile photo, taken from your sign-in provider when you create an account. If you joined through the waitlist or answered the beta survey before signing up, we also hold the email address you gave us there, the answers you submitted, and the IP address the submission came from (used only to rate-limit abuse of those public forms).
Content you create
Everything you put into the product: tasks and their content, due dates, priority, subtasks, tags and projects; notes; calendar events; and the notifications pulled in from the integrations you connect. We also generate and store vector embeddings of your task content so the AI engine can find related work.
How you use the product
Focus session events (duration, task worked on, outcome), in-app usage events (task created, focus started, notification dismissed, and similar), the daily and weekly metrics our engine derives from them (focus score, completion rate), and the attention profile the engine builds to model when and how you work best.
Technical and diagnostic data
Error and crash reports including stack traces, the route you were on, a per-tab session identifier, and a correlation identifier. Authorization headers are stripped before an error report leaves your browser. We also keep audit log entries for sensitive operations — account deletion, connecting or disconnecting an integration, entitlement changes — recording your user identifier and what happened, not the content involved.
Integration credentials
OAuth access and refresh tokens for each service you connect (GitHub, Gmail, Google Calendar, Slack, Jira). These are encrypted with Google Cloud KMS before being written to the database and are never exposed to the browser. We never ask for, receive, or store the password of any connected service.
What we do not collect
We do not collect payment or card data — there is no paid plan during the beta and no payment processor is connected. We do not record your screen or session, we do not use advertising or cross-site tracking technologies, and we do not buy data about you from third parties.
Why we process it, and on what legal basis
If you are in the EEA or the UK, the GDPR requires us to have a legal basis for each purpose. This is ours:
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and running your account | Email, display name, profile photo | Performance of a contract |
| Providing the core product | Tasks, notes, projects, calendar events, notifications | Performance of a contract |
| Focus scoring, analytics dashboard, attention profile | Focus sessions, usage events, derived aggregates | Performance of a contract |
| AI briefs, suggestions, prioritization, embeddings | Task and notification content | Performance of a contract (you can switch AI off) |
| Syncing with the tools you connect | OAuth tokens, data returned by the provider | Consent for the authorization, contract for the sync |
| Understanding which features are used | Pseudonymous user ID, tier, connected providers, event names | Consent |
| Finding and fixing crashes | Stack traces, route, pseudonymous user ID | Legitimate interest in a working, secure service |
| Preventing abuse of public forms and our backend | IP address, device and browser signals | Legitimate interest in preventing abuse |
| Transactional email (invites, resets, digests) | Email address, message content, delivery events | Performance of a contract |
| Waitlist and beta survey | Email address, survey answers, IP address | Consent |
| Audit trail for sensitive operations | User ID, action, timestamp | Legitimate interest in security and accountability |
How long we keep it
| Data | Purpose | Retention |
|---|---|---|
| Email, display name, profile photo | Account identity | Until account deletion |
| Tasks, notes, projects | Core product | Until you delete them, or account deletion |
| Notifications | Core product | Until dismissed, or account deletion |
| Calendar events | Calendar feature | Until account deletion |
| Focus session and usage events | AI engine and analytics | 90 days, then auto-deleted |
| Daily/weekly aggregates, attention profile | AI engine and analytics | Until account deletion |
| Task embeddings | Finding related work | Until the task is deleted, or account deletion |
| AI suggestions | AI feature | 14 days, then auto-deleted |
| AI daily briefs | Morning/evening digest | Current day only, then overwritten |
| Integration OAuth tokens (KMS-encrypted) | Provider sync | Until disconnected, or account deletion |
| Plan tier, AI credits, usage counters | Enforcing plan limits | Until account deletion |
| Waitlist entry, invite, survey response | Running the closed beta | Until account deletion or withdrawal of consent |
| Feedback and error reports you submit | Support and product improvement | Until account deletion |
| Crash and error reports (Sentry, PostHog) | Bug fixing | Up to 90 days |
| Product analytics (PostHog, GA4) | Product improvement | Up to 12 months |
| Audit log entries (Google Cloud Logging) | Security and accountability | 30 days |
| Aggregated beta-funnel snapshots | Measuring whether the beta works | Indefinitely (counts only, no identifiers) |
Retention periods marked "until account deletion" mean the data is removed when you delete your account, as described under "Deleting your data" below.
Who we share it with
We do not sell your personal data, and we do not use it for advertising. We share it only with the service providers needed to run Fokuzen, each acting as a processor under contract with us:
| Provider | What it does for us | What it receives | Location |
|---|---|---|---|
| Google Cloud / Firebase | Hosting, authentication, database, functions, key management | All application data | United States |
| Google Gemini API | AI generation and embeddings | Task, notification, and survey text sent for processing | United States |
| reCAPTCHA Enterprise / Firebase App Check | Bot and abuse prevention | IP address, device and browser signals | United States |
| PostHog | Product analytics and browser exception capture | Pseudonymous user ID, tier, connected providers, event names | United States or European Union, per our configuration |
| Google Analytics 4 | Aggregate usage measurement | Pseudonymous user ID, event names | United States |
| Sentry | Error monitoring and performance tracing | Stack traces, route, pseudonymous user ID; no credentials | United States |
| Resend | Transactional email delivery | Email address, message content, delivery events | United States |
Beyond the processors above, the integration providers you choose to connect — GitHub, Gmail, Google Calendar, Slack, and Jira — receive requests from us only after you have explicitly authorized that integration, and only within the OAuth scopes it needs. Each of them handles your data under its own privacy policy, not this one.
AI processing
When you use an AI feature — task breakdown, rewriting, prioritization, daily briefs, notification triage, suggestions — the relevant task or notification content is sent from our servers to the Google Gemini API (models gemini-2.5-flash and gemini-2.5-flash-lite) to produce the output. Task content is also sent to Google's text-embedding-004 model to generate embeddings. Under Google's Gemini API terms, this content is not used to train Google's models. Requests are made server-side; your browser never talks to the AI provider directly.
AI-generated suggestions are deleted automatically after 14 days. Daily briefs are overwritten each day. You can disable AI features entirely under Settings → Brief & AI, and you can reset the profile the engine has built about you.
Google is our only AI provider today. Our system is built so that a different provider could be configured in the future; if we ever route your content to a provider outside the Google Cloud stack, we will update this policy and notify you by email before doing so.
Google API Services — Limited Use
Fokuzen's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: data obtained from Gmail and Google Calendar is used only to provide and improve the user-facing features you connected them for; it is never transferred to others except as needed to provide those features, for security purposes, or to comply with applicable law; it is never used for advertising; and no human reads it except with your explicit consent, to resolve a specific support issue you raised, or where required by law. Gmail and Google Calendar data is never used to train generalized AI or machine-learning models.
Cookies and similar technologies
We use two categories of browser storage. Strictly necessary storage keeps you signed in, remembers your theme, accent color, language, and sidebar state, and holds the per-tab session identifier used to correlate error reports. This category cannot be switched off, because without it the product does not work; it does not require your consent.
Analytics storage is set by PostHog, and by Google Analytics if we enable it, to recognise your browser across visits. This category is optional and is off until you accept it. Nothing is written and no analytics request is sent before you consent. You can accept or refuse from the banner shown on your first visit, and change your mind at any time under Settings → Privacy — withdrawing consent is exactly as easy as giving it.
Analytics requests are routed through fokuzen.com/ingest rather than going to PostHog's domain directly. This is a reverse proxy: it improves reliability, but it does not change who ultimately receives the data, which is stated in the processors table above.
Analytics and error monitoring, precisely
We want to be exact about identifiers, because "anonymous analytics" is a claim that is almost never true. Product analytics events are linked to your Firebase user identifier, which is a pseudonym: it is not your name or email, but we can link it back to you, so under the GDPR it is personal data. We also attach your subscription tier and the names of the integrations you have connected. We do not send your email address, your task content, or your notes to any analytics provider.
Error monitoring runs through Sentry. Error reports carry the same pseudonymous user identifier, the route you were on, and the stack trace; in production we also sample 10% of page loads for performance tracing. We rely on our legitimate interest in keeping the service secure and working for this, rather than consent, because it is not tracking and cannot be used to profile you — but you can object at any time by writing to us. PostHog additionally captures uncaught browser exceptions, and that part only runs if you accepted analytics storage.
How we protect it
All traffic is encrypted in transit with TLS, and data is encrypted at rest by Google Cloud. Integration OAuth tokens are additionally encrypted with Google Cloud KMS before being stored, so a database read alone does not expose them. Database access rules scope every read and write to the owning account. Requests to our backend are attested with Firebase App Check, and public forms are protected by reCAPTCHA Enterprise and rate limiting. No system is perfectly secure; if a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the competent authority within the deadlines the law sets.
Staff access
A small number of administrator accounts can, using administrative tooling, list users by email address and inspect the AI-generated profile and preferences the engine has built for a user. This exists to diagnose whether the engine is modelling people correctly and to answer support requests. It is read-only, it is restricted to accounts holding an administrator claim, and it does not extend to reading the content of your tasks, notes, or emails.
Where your data goes
Fokuzen's infrastructure runs on Google Cloud in the United States, and the processors listed above are established in the United States unless stated otherwise. If you are in the EEA or the UK, this means your personal data is transferred outside your region. Those transfers rely on the Standard Contractual Clauses adopted by the European Commission, which are part of our agreements with each processor. The controller itself is established in Uruguay, a country the European Commission has recognised as providing an adequate level of protection, so transfers to us require no additional safeguard.
We are working on appointing a representative in the European Union under Article 27 GDPR. Until that is in place, EEA and UK users can exercise every right described below by writing to support@fokuzen.com, and we will respond within the statutory deadline.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider in a portable format. Where we rely on your consent — analytics storage, the waitlist, the beta survey — you can withdraw it at any time, without affecting what we did lawfully before you withdrew it. Some of these you can do yourself, immediately: delete your account under Settings → Account, disconnect an integration under Settings → Integrations, turn AI features off under Settings → Brief & AI, and accept or refuse analytics under Settings → Privacy.
For anything you cannot do in the app — a data export, a correction, an objection — write to support@fokuzen.com. We answer within 30 days, and we do not charge for it. We do not make automated decisions that produce legal effects about you: the AI ranks and suggests, it does not decide anything binding.
If you think we have handled your data badly, we would rather you told us first — but you have the right to go straight to a supervisory authority. In Uruguay that is the Unidad Reguladora y de Control de Datos Personales (URCDP). In the EEA or the UK it is the authority for your country of residence.
Deleting your data
Deleting your account under Settings → Account triggers an immediate cascade. It removes your profile and every subcollection under it — tasks, notes, projects, calendar events, notifications, focus and usage events, aggregates, attention profile, AI suggestions and briefs, embeddings, entitlements and credits — plus your encrypted OAuth tokens, the feedback you submitted, and any waitlist, invite, or survey record keyed to your sign-in email. Where a Google integration is connected, we also ask Google to revoke our refresh token. Your Firebase authentication record is deleted last. This normally completes in seconds.
What deletion does not reach
We would rather state the limits than overpromise. Deletion runs step by step and tolerates a partial failure so that one stuck step cannot leave your account half-deleted — if any step fails it is logged and we finish the rest, and you can write to us to have the remainder removed by hand. Copies already held by our processors follow their own retention: analytics and error-monitoring records expire on the schedule in the retention table, and we will pass on a deletion request to them if you ask. Audit log entries containing your user identifier persist in Google Cloud Logging for 30 days, because we need them to investigate security incidents. Aggregated beta-funnel snapshots contain only counts, hold no identifier of any kind, and cannot be linked back to you, so they are not deleted.
Children
Fokuzen is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, write to support@fokuzen.com and we will delete it.
Changes to this policy
We will update this policy as the product grows — in particular when paid plans launch, which will add a payment processor and billing records with their own retention. Material changes are announced by email and by updating the date at the top of this page. If a change requires your consent, we will ask for it before it takes effect rather than assume it.
Contact
Questions or requests about your data go to support@fokuzen.com. Fokuzen is operated by Paul Pérez, Uruguay.