focusguardian-legal

Focus Guardian — Privacy Policy

Last updated: 2026-04-24

This Privacy Policy describes how the Focus Guardian mobile application (“Focus Guardian”, “the app”, “we”, “our”, or “us”) collects, uses, stores, and shares information when you use it. It applies to the Android application published under the package name com.focusguardian.app and its supporting backend services.

If you do not agree with this policy, please do not install or use Focus Guardian.


1. Who we are

Focus Guardian is developed and operated by an independent developer based in Uzbekistan (“we”). You can contact us at:


2. Summary (plain English)


3. Information we collect

3.1 Information you provide directly

Data When Why
Email address Sign-up, login, password reset Account identification, sending verification and reset emails
Password Sign-up, login Authenticating you. Stored only on the server as a salted hash; never logged, never transmitted to third parties
Display name (optional) Sign-up, Google Sign-In Personalising the app UI
Profile picture URL (optional) Google Sign-In Display purposes only; we do not copy or re-host the image
Reflections, notes, trigger tags When you write a reflection inside the app Kept locally so you can review your own patterns. Never uploaded

3.2 Information collected automatically on your device

The following data is generated by your use of the app and stored only on your device in an encrypted database:

This data never leaves your device unless you explicitly export it using the in-app export feature (Section 7).

3.3 Information collected on our servers

When you use your account, our backend API receives and retains:

3.4 Information we do not collect

Focus Guardian does not collect:

We do not ship any third-party analytics, advertising, attribution, or crash-reporting SDK. There are no tracking pixels or fingerprinting libraries in the app.


4. Android permissions and why we ask for them

Focus Guardian requests the following Android permissions. You can revoke any of them at any time in Android Settings; some features will stop working if you do.

Permission Why it is required What is sent off-device
Accessibility Service (BIND_ACCESSIBILITY_SERVICE) To detect in real time which app has come to the foreground, so we can show the friction/pause screen before you open a distracting app. The service only reads the package name of the foreground window and basic window events — it does not read on-screen text, form fields, passwords, or messages. Nothing. Used purely on-device.
Usage Access (PACKAGE_USAGE_STATS) To show your “time spent per app today” dashboard and enforce daily limits you configure. Nothing. Read locally, stored locally.
Display over other apps (SYSTEM_ALERT_WINDOW) To show the friction screen on top of the distracting app. Nothing.
Foreground service (FOREGROUND_SERVICE, FOREGROUND_SERVICE_SPECIAL_USE) To keep the monitoring service reliably running during a focus session. Android shows a persistent notification while this is active. Nothing.
Post notifications (POST_NOTIFICATIONS) To send you session reminders, streak nudges, and update prompts. Nothing.
Ignore battery optimisations So the monitoring service is not killed mid-session by Doze. Nothing.
Receive boot completed To restart the monitoring service after you reboot your device, if you had an active session. Nothing.
Wake lock To keep the screen/CPU active during a strict session timer when required. Nothing.
Query all packages (QUERY_ALL_PACKAGES) To show you the list of installed apps during setup so you can choose which ones to monitor. The full list of package names is held in memory and never transmitted. Nothing.
Biometric / fingerprint (USE_BIOMETRIC, USE_FINGERPRINT) Optional: to require biometric confirmation before bypassing a Commitment session. Authentication is handled entirely by Android’s BiometricPrompt; we never see your biometric data. Nothing.
Internet To authenticate your account, sync subscription status, and check for updates. See Section 5.

4.1 Accessibility Service disclosure

Focus Guardian uses the Android Accessibility API exclusively for its stated purpose: detecting which app has just come to the foreground so that an intentional-use prompt (“friction screen”) can be shown. The service is declared with typeWindowStateChanged and typeWindowContentChanged events. It does not record keystrokes, scrape screen text, log passwords, or capture screenshots. It does not transmit anything over the network. Using the Accessibility API is the only reliable way on current Android versions to deliver this core feature.


5. Third-party services that receive data

5.1 Google Sign-In

If you choose to sign in with Google, the Google Sign-In SDK returns an ID token containing your email, name, profile picture URL, and Google account ID (sub). We send that ID token to our backend at POST /auth/google to create or identify your account. Google’s use of your data is governed by the Google Privacy Policy.

5.2 RevenueCat (subscription management)

When you purchase a subscription, we use RevenueCat (operated by RevenueCat, Inc.) to manage entitlements on top of Google Play Billing. RevenueCat receives:

RevenueCat does not receive your email, password, on-device behavioural data, or any content from your reflections. See the RevenueCat Privacy Policy.

5.3 Google Play Billing

Payments are processed by Google Play Billing. We never see your payment card or billing address; we only receive the purchase token and entitlement. See the Google Play Terms.

5.4 Google Play Core (in-app updates)

We use the Play Core library to prompt you to install updates. This communicates only with Google Play and does not send personal data.

5.5 Our backend API

Our own backend, hosted under api.focusguardian.app, handles account registration, authentication, password reset, email verification, and /me profile lookup. It is the only first-party server that receives your data.


6. How we store and protect your data

No system is perfectly secure. If we become aware of a breach that affects your personal information, we will notify affected users in accordance with applicable law.


7. Your rights and controls

Regardless of where you live, Focus Guardian gives you these controls directly inside the app under Settings → Privacy:

To exercise the following rights, email us at anvar0142@gmail.com from the email address associated with your account:

If you are in the EU/EEA or UK, the legal basis for processing is (a) performance of a contract (providing the account you signed up for), (b) our legitimate interest in operating the service, and (c) your consent for optional features.

If you are in California, we do not “sell” or “share” personal information as those terms are defined under the CCPA/CPRA.

If we cannot resolve your concern directly, you have the right to complain to your local data protection authority.


8. Retention


9. International transfers

Our backend may be hosted outside of your country of residence. Where your data is transferred internationally, we rely on appropriate safeguards (such as standard contractual clauses) as required by applicable law.


10. Children

Focus Guardian is intended for general audiences and is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal data, please contact us and we will delete it.


11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top. Material changes will be announced inside the app or by email before they take effect. Continued use of the app after changes take effect constitutes acceptance of the updated policy.


12. Contact

Questions, requests, or concerns about this policy or your data:

Email: charlsjonson2704@gmail.com

We aim to respond within 14 days.