Privacy Policy
ADHD-Focus has no backend server and no user account. Your tasks, routines, focus sessions, check-ins, notes and questionnaire answers are stored only on your device. We do not collect them, we cannot see them, and we never sell or share them. The only information that leaves your device is what is strictly necessary to process a subscription purchase, which is handled by Apple, Google and our subscription processor — and it does not include the contents of anything you write in the app.
- Who we are
- What we do not collect
- Information stored on your device
- The only information that leaves your device
- Mental health information
- Third parties
- Why we may process information
- Retention and deletion
- Security
- Your rights
- United States
- Canada (PIPEDA)
- Quebec (Law 25)
- Mexico (LFPDPPP)
- Children
- International transfers
- Changes to this policy
- Contact us
1. Who we are
ADHD-Focus (“ADHD-Focus”, “we”, “us”) publishes the ADHD-Focus mobile application, a wellness and organization tool for adults with ADHD. For the limited processing described in this policy, we act as the data controller (the “responsible party” under Mexican law, the “organization” under Canadian law).
You can reach us at any time at [email protected] for privacy matters, or [email protected] for general help.
2. What we do not collect
To be explicit, because these are the things people reasonably worry about:
- We do not require or offer a user account, and we do not collect your name, email address, phone number or date of birth.
- We do not collect the contents of your tasks, routines, notes, reminders, mood or focus check-ins, habits, or self-assessment questionnaire answers.
- We do not use analytics, advertising, attribution or telemetry software development kits. There is no Google Analytics, no Firebase Analytics, no Meta SDK, no advertising identifier collection, and no crash-reporting service in the app.
- We do not collect your precise or approximate location.
- We do not access your contacts, photos, microphone, camera or calendar.
- We do not serve advertising, and we do not build advertising or marketing profiles.
- We do not sell, rent, trade or share personal information, and we never have.
- We do not receive your payment card number or bank details. Payment is handled entirely by Apple or Google.
3. Information stored on your device
The app is offline-first. Everything you create is written to local storage on your phone, in the app’s private storage area, protected by your device’s own operating-system protections. This includes:
- Tasks, subtasks, routines, due dates and recurrence settings;
- Reminders, which are delivered as local notifications scheduled by your device — they are not sent from any server of ours;
- Focus sessions you start and complete;
- Daily check-ins (mood, focus, energy) and habits;
- Answers to and results of any optional self-assessment questionnaire;
- Your preferences: language, theme, notification settings, and the record that you acknowledged the health notice.
This information is not transmitted to us. We have no server that stores it and no mechanism to retrieve it. If you delete the app, this information is deleted with it. Note that if you have enabled a device-level backup service — such as iCloud Backup or Google’s Android Backup — your device’s operating system may include the app’s local data in that backup. That backup is governed by Apple’s or Google’s privacy policy and your own settings, not by us; you can turn it off in your device settings.
4. The only information that leaves your device
If, and only if, you start a free trial or purchase a subscription, a transaction is processed. That process necessarily involves information leaving your device:
| Who | What is processed | Why |
|---|---|---|
| Apple (App Store) or Google (Google Play) | Your store account, payment method, and the purchase itself. We never see your payment details. | To take payment and manage the subscription. Required by the platforms; digital subscriptions must use their billing systems. |
| RevenueCat, Inc. (our subscription processor, acting on our behalf) | A randomly generated, pseudonymous app user identifier; the store receipt or purchase token; subscription status (trial, active, expired); and basic technical data such as device platform, app version, country and IP address associated with the request. | To validate the purchase receipt with Apple or Google and tell the app whether the subscription is active. Without this, we cannot honour what you paid for. |
The identifier used for this purpose is generated at random and is not linked to your name or email address. None of the content you create in the app is transmitted in this process. The subscription status is cached on your device so the app keeps working offline.
If you never purchase and never start a trial, the app functions without transmitting anything.
5. Mental health information
Information related to attention, mood, energy and self-assessment is sensitive personal information, and we treat it as such. It is “sensitive personal information” under California law, information warranting a high level of protection under Canadian and Quebec law, and sensitive personal data (datos personales sensibles) under Mexican law, which ordinarily requires express written consent to process.
Our approach to this category is structural rather than promissory: we do not collect it at all. It is created on your device, stored on your device, and deleted on your device. Because we never receive it, it cannot be disclosed by us, breached at our end, sold, or used to profile you. No consent to transfer it is sought, because no transfer takes place.
6. Third parties
The app integrates a deliberately small number of third parties, listed here in full:
- Apple Inc. and Google LLC — app distribution and payment processing. Their handling of your store account is governed by their own privacy policies.
- RevenueCat, Inc. — subscription receipt validation and entitlement management, acting as our processor (service provider) under our instructions and contract.
That is the complete list. We do not embed any other third-party service in the app. This website is static: it sets no cookies, runs no analytics, loads no third-party fonts or scripts, and does not track visitors.
We may disclose information if we are legally required to do so by a valid order of a competent authority, or where necessary to establish or defend legal claims. In practice, the content you create in the app cannot be produced by us in response to such a request, because we do not hold it.
7. Why we may process information
Where a legal basis or purpose must be stated, the limited processing described in section 4 is carried out because it is necessary to perform the agreement with you — that is, to deliver the subscription you purchased and to prevent fraudulent or duplicate entitlements — and, where applicable, to comply with tax and accounting obligations of the platforms. We do not rely on consent for advertising or profiling purposes, because we do not engage in them.
8. Retention and deletion
- On-device data: retained until you delete it. You can export or permanently erase all of it from Settings → My data in the app, at any time, without a subscription. Deleting the app also removes it (subject to any device backup you have enabled).
- Subscription records: retained by our processor for as long as the subscription is active and afterwards for the period required to meet legal, tax, accounting and dispute-resolution obligations, after which they are deleted or anonymized.
- Correspondence: if you email us, we keep the message and our reply for as long as needed to resolve the matter and to keep a record of it, and then delete it.
9. Security
The strongest security measure in this product is data minimization: an architecture with no user database cannot suffer a breach of a user database. Beyond that, app data is stored in the application’s protected storage area and inherits your device’s encryption and access controls (passcode, Face ID, Touch ID or equivalent). All communication with our subscription processor is encrypted in transit using TLS.
We recommend that you protect your device with a passcode or biometric lock, as anyone with access to your unlocked device can open the app. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security.
If a confidentiality incident occurred that presented a risk of serious injury, we would notify the affected individuals and the competent regulator where required, and record the incident, as required by applicable law.
10. Your rights
Depending on where you live, you have some or all of the following rights: to know what personal information is processed about you; to access it; to have it corrected; to have it deleted; to obtain a portable copy; to withdraw consent; to object to or restrict certain processing; to opt out of the sale or sharing of personal information; not to be discriminated against for exercising a right; and to complain to a regulator.
How to exercise them. For the information stored on your device, you do not need to ask us: the app gives you direct and immediate access, export and deletion under Settings → My data. That is the fastest and most complete route, and it is free.
For the subscription information described in section 4, write to [email protected]. We will respond within the period required by the law that applies to you, and in any event within 30 days. Because we do not hold identifying information about you, we may need to ask for the store receipt or order identifier associated with your purchase in order to locate the relevant record; if we cannot verify the request, we may not be able to act on it, and we will tell you why. We do not charge for these requests, and exercising a right will never degrade the app for you.
11. United States
If you are a resident of California, or of another U.S. state with comprehensive privacy legislation (including Colorado, Connecticut, Texas and Virginia, among others), the following applies to you.
In the preceding twelve months, we have not sold personal information and have not shared it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act as amended by the CPRA. We do not use or disclose sensitive personal information for purposes beyond those permitted without an opt-out, and, as described above, we do not receive the sensitive information created in the app in the first place.
The only category of personal information we process is commercial information (the fact of a subscription transaction) together with limited internet or other electronic network activity information and a pseudonymous identifier, as described in section 4. It is collected from Apple, Google and our processor when you make a purchase, it is used only to deliver and validate that subscription, and it is disclosed only to the processor that performs that service.
You may exercise your rights to know, access, correct, delete and limit by writing to [email protected]. You may use an authorized agent, and you may appeal a decision by replying to our response. California residents may also contact the California Privacy Protection Agency or the Office of the Attorney General.
We are not a covered entity or a business associate under HIPAA, and the app does not create HIPAA-regulated records.
12. Canada (PIPEDA)
For users in Canada, we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act and its ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, individual access, and the ability to challenge compliance.
Our collection is limited to what is necessary for the identified purpose in section 4, and we do not use it for any secondary purpose. You may request access to the personal information we hold about you and challenge its accuracy by writing to [email protected]. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice; withdrawing consent to the processing necessary for billing means ending the subscription, which you do through your App Store or Google Play account.
If you are not satisfied with how we have handled a matter, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca).
13. Quebec (Law 25)
If you are in Quebec, the Act respecting the protection of personal information in the private sector, as amended by Law 25, applies, and the following specific commitments are made to you.
- Person in charge of the protection of personal information. We have designated a Privacy Officer responsible for compliance, reachable at [email protected]. Address a request to “Privacy Officer” and it will reach them.
- Privacy by default. The app’s settings are, by default, the ones that provide the highest level of confidentiality without your intervention. There is no profile to make public, no social feature, no sharing enabled by default, and no cloud storage of your content at all.
- Transparency about collection. Sections 3 and 4 identify what is collected, why, by what means, and to whom it may be communicated, at or before the time of collection.
- No automated decision-making. We do not use your personal information to render a decision about you based exclusively on automated processing, and we do not use profiling, identification or location technologies.
- Portability. You may obtain the computerized personal information you have provided, in a structured, commonly used technological format. For on-device content this is built into the app (Settings → My data → Export); for subscription records, write to us.
- De-indexing and cessation of dissemination. You may ask us to cease disseminating personal information or to de-index it where the conditions in the Act are met. In practice, we disseminate nothing.
- Confidentiality incidents. We keep a register of confidentiality incidents and, where an incident presents a risk of serious injury, we notify the Commission d’accès à l’information and the persons concerned promptly.
- Transfers outside Quebec. Before communicating personal information outside Quebec, we assess whether it would receive adequate protection, in particular in light of generally accepted data protection principles, and we frame the communication in a written agreement. See section 16.
You may lodge a complaint with the Commission d’accès à l’information du Québec (cai.gouv.qc.ca).
The app interface, including this notice’s subject matter, is available in French.
14. Mexico (LFPDPPP)
This section constitutes the privacy notice (aviso de privacidad) required by the Ley Federal de Protección de Datos Personales en Posesión de los Particulares, its Regulations and the Privacy Notice Guidelines, for users in Mexico. It is available in Spanish on request.
- Responsible party (responsable): ADHD-Focus, contactable at [email protected]. This address is also the designated point of contact (departamento de datos personales) for ARCO requests.
- Personal data processed: only the identification and commercial data associated with a subscription transaction described in section 4. No sensitive personal data (datos personales sensibles) is collected by us; health-related information you record remains on your device.
- Purposes: the primary and necessary purposes are to process and validate your subscription, to provide access to the paid features, and to comply with legal obligations. There are no secondary purposes; we do not use your data for marketing, and we do not transfer it for such use.
- Transfers: we make no transfers requiring your consent. The communication of data to Apple, Google and our processor constitutes a remisión to service providers acting on our behalf, which is necessary to perform the service you requested.
ARCO rights. You may at any time exercise your rights of Access, Rectification, Cancellation and Opposition (derechos ARCO), and revoke your consent, by writing to [email protected] with your request, the means by which you wish to receive the reply, the documents that accredit your identity or that of your representative, a clear description of the data concerned, and any element that helps locate it. We will reply within 20 business days and, if the request is well founded, give effect to it within the 15 business days that follow. Because we do not hold identifying data, we may ask for the store receipt or order identifier to locate the record.
Limiting the use or disclosure of your data is achieved directly and immediately by deleting it in the app or by ending your subscription. If you consider that your right to the protection of personal data has been infringed, you may file a complaint with the competent national data protection authority.
15. Children
ADHD-Focus is intended for adults aged 18 and over. It is not directed to children, is not marketed to children, and we do not knowingly collect personal information from anyone under the age of majority. Consistent with this policy, the app does not collect personal information from any user, regardless of age. If you believe a minor has provided us with personal information, contact [email protected] and we will delete whatever we hold.
16. International transfers
Our subscription processor and the app stores operate infrastructure in the United States and other countries. The limited subscription information described in section 4 may therefore be processed outside Canada, Quebec and Mexico, where it may be subject to the laws of those jurisdictions, including lawful access by their authorities.
Where we make such a communication, we assess the protection the information will receive, we frame the arrangement in a written agreement that binds the recipient to process it only on our instructions and to protect it appropriately, and we transfer only what is necessary. The content you create in the app is never transferred anywhere — it does not leave your device.
17. Changes to this policy
If we change this policy, we will update the “last updated” date above and publish the new version at this address. If a change is material — for example, if we ever began collecting information we do not collect today — we will give notice inside the app before the change takes effect, and where the law requires it, we will obtain your consent. We will not apply a materially different practice to information collected under an earlier version without a lawful basis for doing so.
18. Contact us
Privacy matters, data requests, and questions about this policy:
[email protected]
General help and technical support:
[email protected] — see also the Support page.
For Quebec residents, requests addressed to the “Privacy Officer” at the privacy address above will reach the designated person in charge of the protection of personal information.