Focussed One

Privacy Policy

Last updated: 12 June 2026

This Privacy Policy explains how Focussed One (“the Service”, available at focussed.one) collects, uses, shares, and protects your personal data, and the rights you have over it.

The Service is operated by [YOUR FULL NAME], an individual (sole trader) based in the United Kingdom (“I”, “me”, “my”). I am the “data controller” responsible for your personal data. If you have any questions, you can reach me at [CONTACT EMAIL].

1. Who this policy applies to

The Service is available to people around the world. Depending on where you live, you may have rights under laws such as the UK GDPR (United Kingdom), the EU GDPR (European Economic Area), or the CCPA/CPRA (California). This policy is written to respect those rights, and nothing in it removes any mandatory protection you have under your local law.

2. What data I collect

  • Account data: your email address, which is required to create an account and to sign in.
  • Login codes: the one-time six-digit codes used to sign you in. These are stored only briefly and expire within a few minutes.
  • Profile data: a display name and username, and optionally a title, a short bio, and an avatar image, some of which you may choose to make public (see “Public profiles” below).
  • Activity you create: focus sessions (duration, an optional label, and the time completed), projects (name, colour, status), and tasks (title and status).
  • Preferences: your timezone (detected from your browser so your statistics line up with your day), a reward preference, and your light/dark theme choice (stored in your browser).
  • Technical data: when you use the Service, my hosting provider automatically logs limited technical information such as your IP address, browser type, and request times, for security and to operate the Service.

I do not intentionally collect special-category or sensitive personal data. Although Focussed One is designed to be ADHD-friendly, I do not ask for or require any health, medical, or diagnostic information. Please do not enter sensitive personal data into task titles, session labels, or your bio.

3. Cookies and similar technologies

  • Strictly necessary cookie: a single session cookie holds a signed token that keeps you logged in (for about 30 days). It is httpOnly and the Service cannot work without it.
  • Local storage: your theme preference (light or dark) is stored in your browser, not on my servers.

I do not use advertising cookies, third-party analytics, or cross-site tracking. Because I only use strictly necessary cookies, no consent banner is required.

4. Why I use your data (and my legal bases)

For users in the UK and EEA, I rely on the following legal bases:

  • To provide your account and the Service, including sending login codes and essential service messages (performance of a contract with you).
  • To keep the Service secure and prevent abuse (my legitimate interests).
  • To show a public profile you choose to publish (based on your choice to make that information public).
  • To comply with the law where I am legally required to (a legal obligation).

5. Public profiles

If you set up a profile, it is reachable at a shareable URL (focussed.one/u/your-username). Anyone with that link can see your name, username, title, bio, avatar, your focus statistics and heatmap, and the date you joined. Your email address is never shown publicly. You decide what goes in your profile. Please don’t put anything there you wouldn’t want to be public.

6. Who I share your data with

I do not sell your personal data. I use a small number of trusted service providers who process data on my behalf, under contract and only on my instructions:

  • Neon for database hosting, which stores your account, profile, and activity data.
  • Postmark for sending your login-code emails (it receives your email address and the code).
  • [YOUR HOSTING PROVIDER, e.g. Vercel] for application hosting and the server logs described above.

I may also disclose data if required to by law, or where necessary to protect my rights, your safety, or the safety of others.

7. International data transfers

I am based in the United Kingdom, and some of my providers are located in the United States or elsewhere. Where your data is transferred outside the UK or the EEA, I rely on appropriate safeguards, such as the UK International Data Transfer Agreement (or Addendum), the EU Standard Contractual Clauses, or a relevant adequacy decision.

8. How long I keep your data

  • Account, profile, and activity data: kept for as long as your account is active.
  • Login codes: expire and are removed within minutes.
  • Server logs: kept for a short period by my hosting provider.

If you ask me to delete your account, I will delete your personal data within 30 days, except anything I am required to keep by law.

9. Your rights

Wherever you live, you can ask me to access, correct, or delete your data, or to close your account, by emailing [CONTACT EMAIL].

  • UK and EEA (GDPR): you have the rights of access, rectification, erasure, restriction, data portability, and objection, and the right to withdraw consent. You can also complain to the UK Information Commissioner’s Office (ico.org.uk) or your local data-protection authority.
  • California (CCPA/CPRA): you have the right to know, delete, and correct your personal information, and to opt out of its “sale” or “sharing”. I do not sell or share your personal information, and I will not discriminate against you for exercising your rights.

I will respond within the time your law requires (usually one month under the GDPR).

10. How I protect your data

Data is encrypted in transit (HTTPS), sign-in is passwordless (there is no password to leak), sessions use signed httpOnly cookies, and access to the database is restricted. No online service can be guaranteed 100% secure, but I take reasonable measures to protect your data.

11. Children

The Service is not intended for children under 16 (or the minimum age set by your country’s law). I do not knowingly collect data from children under that age; if I learn that I have, I will delete it.

12. Changes to this policy

I may update this policy from time to time. I will change the “Last updated” date above and, for material changes, take reasonable steps to let you know.

13. Contact

[YOUR FULL NAME], [CONTACT EMAIL].