Privacy Policy
Last Updated: January 15, 2026
Introduction
Focuzen is a digital productivity application designed to help users improve focus, consistency, and efficiency through features such as AI Coaching, productivity reports, and dedicated focus modes.
We respect user privacy and are committed to safeguarding personal data in accordance with high security standards. All data is collected solely to support service improvement and enhance user experience.
Information We Collect
We collect only data that is relevant and necessary for the optimal functioning of the Application.
Personal Data: Information provided directly by You, including full name and email address, login information (email and encrypted password), and optional profile photo, short bio, or username. This data is used to create and manage user accounts and personalize the user experience.
Usage Data: Focuzen records in-app user activity to provide personalized feedback, including duration and number of focus sessions, focus modes or features used, and daily reflections, habits, and productivity statistics.
Technical Data: We automatically collect certain technical data, including device type and operating system, IP address and application version, and error logs to improve system stability and security.
Payment Data: For users subscribing to premium features, transaction data is processed by third-party payment providers such as Google Play or the Apple App Store. Focuzen does not directly store credit card or financial information.
Purpose of Data Processing
Personal data is used to operate and maintain the Application, provide personalized experiences through AI Coaching features, improve features, quality, and overall performance, send updates, notifications, and important service-related information, and manage transactions, subscriptions, and customer support.
Focuzen does not sell or share user data with third parties beyond what is necessary for operational purposes.
Application Permissions
The Application may request certain permissions to support functionality, such as access to camera or gallery (for uploading reflection photos), access to notifications (for focus session reminders), and access to local storage (for saving productivity reports).
All permissions are optional and may be managed through device settings.
Cookie and Analytics Policy
Focuzen uses internal cookies and analytics technologies to understand usage patterns. Such data is anonymized and used solely to enhance user experience, not for advertising tracking or data sales.
Data Sharing with Third Parties
Focuzen collaborates with selected third-party service providers to operate, maintain, and improve its services. These providers are granted limited access to user data strictly for operational and technical purposes and are contractually obligated to maintain data confidentiality and security.
Our third-party partners include: Clerk (user authentication and account management), Google Sign-In (login via Google accounts), Apple Sign-In (login via Apple accounts), RevenueCat (subscription and in-app purchase management), Google Play Store (Android subscription payments), Apple App Store (iOS subscription payments), and Google Gemini 2.0 Flash (AI-based features such as chatbot interactions and productivity analysis).
Focuzen does not directly store users' credit card or payment details. All payment transactions are processed through official platform payment systems. Each third-party service operates under its own privacy policy and terms of service. Focuzen only shares data necessary to provide core functionality and enhance user experience.
Data Security and Retention
Focuzen implements a modern, token-based security architecture to protect user data.
Mobile authentication (Expo) is handled through Clerk using email/password and OAuth providers. User sessions and tokens are fully managed by Clerk. JWT tokens are not stored in AsyncStorage. Instead, they are securely stored using Expo SecureStore as a tokenCache, with getToken(key) using SecureStore.getItemAsync(key) and saveToken(key, value) using SecureStore.setItemAsync(key, value). On the backend, every API request is protected by authentication middleware. Tokens must be sent in the request header as Authorization: Bearer <token>.
The backend verifies JWTs using a JWKS (JSON Web Key Set) mechanism with RSA public keys provided by Clerk. The verification process validates Audience, Issuer, Subject (sub, representing the user ID), Expiration (exp), and Token signature. JWKS keys are cached for approximately 10 minutes to ensure both efficiency and security. After successful verification, the user identity is extracted from the sub claim and injected into the request context. At the gateway level, the verified user ID is forwarded to internal services through the X-User-ID header.
All backend data operations strictly rely on the user ID obtained from the verified token — never from request body or query parameters. Profile data is stored in Firestore at profiles/{userID}. Productivity records are stored under users/{userID}/productivities/.... Progress data, streaks, and recovery quotas are queried and processed using the authenticated user ID from the request context. This architecture ensures that one user cannot access or modify another user's data.
All communication between the client application and backend servers is conducted over HTTPS. The production API gateway uses an HTTPS endpoint, ensuring that all data transmitted between client and server is encrypted in transit.
Personal data is retained for as long as the user account remains active and is necessary for service operation. If a user deletes their account, associated data will be removed from production systems in accordance with internal data deletion procedures and applicable operational policies.
User Rights
Users have the right to access and review stored personal data, update or delete personal information, withdraw consent for certain data processing activities, delete their account through the Application, and submit inquiries or complaints regarding privacy matters.
Requests may be submitted through the 'Settings > Privacy' menu within the Application or via Our official email.
Children's Privacy
Focuzen is not intended for children under the age of 13. We do not knowingly collect personal data from children. If data from a minor is identified without parental consent, such data will be promptly deleted.
International Data Transfers
Data may be processed on servers located within or outside Indonesia, subject to appropriate security standards. All processing complies with applicable data protection regulations, including the GDPR and the Indonesian Personal Data Protection Law.
Policy Updates
This Privacy Policy may be updated from time to time to reflect changes in services, legal requirements, or technological developments.
Any changes will be communicated through the Application or via user email. The most current version will always be available in the 'Privacy Policy' section of the Focuzen Application.
External Links
The Focuzen Application may contain links to external websites, such as social media pages or payment support portals. We are not responsible for the privacy practices of such third-party websites.
Consent
By using Focuzen, You consent to the collection and use of personal data as described in this Privacy Policy.
Contact Us
For questions or complaints, Users may contact Focuzen at:
Address: Bandung, Indonesia
Email: hello@focuzenapp.com
Focuzen