Privacy policy

What Fokus IO processes, why it is needed, where it is stored, and what choices you have.

Last updated — 9 September 2026

Who operates Fokus IO

Fokus IO is operated by the Fokus IO developer. Privacy questions and data requests can be sent to s.mohsunlu.dev@gmail.com. The Family Sync backend is hosted at fokusio.net on infrastructure located in Germany.

Data that stays on the device

When Fokus IO is used without Family Sync, focus sessions, timer settings, streak and journey progress, Shield configuration, blocked-app selections, schedules, and most usage summaries remain on the device.

Android system APIs provide app-usage information to the app when you grant Usage Access. The accessibility service identifies the currently opened app only to enforce the configured Shield; it is configured not to retrieve screen content and does not read messages, passwords, typed text, or screenshots.

Family Sync account and server data

Family Sync is activated only when a parent creates an account and a child deliberately links a device with the parent’s link code. The self-hosted backend stores the data required to operate the family relationship:

  • Parent email, display name and password hash — account login, email verification and password recovery. Plain-text passwords are never stored.
  • Child identifier and display name — maintain the parent-child link and show the correct child in the dashboard.
  • Focus minutes, sessions, screen-time totals, streak and top apps — show the child’s synced progress to the linked parent.
  • Shield configuration, installed launchable apps and applied status — let the parent select the child’s apps and confirm whether requested controls were applied.
  • Remote commands and family events — deliver parental-control changes and provide transparent join, unlink and deletion notices.
  • Authentication tokens in hashed form — keep signed-in sessions working and revoke them on logout or password reset.

Location

Location is optional and separate from Family Sync. It starts only after the child sees the explanation and grants Android location permission. The linked parent can request the current location.

Each reading carries the coordinates, an accuracy radius in metres, the time the device took the fix, whether it was periodic or requested by the parent, and the child device’s battery percentage. The battery level is there so a parent can tell a phone that is switched off from one that is hiding: it is shown on the same screen as the position and is not kept as a history.

The server keeps only the latest position for that child; a new reading replaces the previous one. Fokus IO does not build a route or location-history timeline. Revoking the Android permission stops future collection. The parent may delete the stored position.

Site-domain history and VPN disclosure

Site history is optional and requires Android’s VPN consent on the child device. While active, Android shows a persistent notification and a VPN indicator.

The local VPN observes DNS requests and records domain names such as example.com, along with a count and time. It does not record full page URLs, page contents, search terms, messages or passwords. Domain summaries are uploaded to the self-hosted backend and are visible only to the linked parent.

If the recorder cannot forward DNS safely, it fails open by turning itself off so it does not intentionally block internet access. Android allows only one active VPN; another VPN may prevent this feature from operating.

Contacts and Friends

For adult solo accounts, contact matching is optional. With permission, phone numbers are normalised and hashed on the device. The backend receives hashes — not the address-book names or raw phone numbers — to discover other opted-in Fokus IO users. Contact matching is unavailable to parent and child family accounts.

Subscriptions and payments

Subscriptions are bought through Google Play. Google is the seller and the payment processor: card numbers, billing addresses and payment methods are handled entirely by Google and never reach Fokus IO, which cannot see them.

What Google Play returns to the app is a purchase token — an opaque string that proves a purchase exists. The app sends that token to the Fokus IO backend, which asks the Google Play Developer API what it actually is and records the answer: which product was bought, the plan and billing period it maps to, the subscription’s status, the start and end of the current period, and whether it renews. A one-way digest of the purchase token is stored as the subscription’s identifier rather than the token itself, and an equally one-way digest of the account identifier is attached to the purchase inside Google’s own record so a receipt cannot be presented by a different account.

Google also sends the backend a notification when a subscription renews, is cancelled, lapses, enters a grace period or is refunded. Those notifications are kept as a dated ledger of what changed and when, for at most 400 days, so a billing dispute can be answered. Deleting an account deletes its subscription record along with the rest of its data; the purchase history held by Google Play is Google’s and is governed by Google’s own policy.

The optional one-off tip is the same Google Play flow and unlocks nothing, so nothing about it is recorded on the Fokus IO backend at all.

Google and other service providers

Fokus IO has no advertising SDK, no analytics SDK and no third-party crash-reporting SDK. Crash reports go to the Fokus IO backend and nowhere else. Everything below is a processor acting for Fokus IO or a service the app talks to for a named purpose:

  • Google Play Billing — subscriptions and the optional tip. Google receives the purchase itself; Fokus IO receives a token and a status. Required only if you choose to buy something.
  • Google Play Developer API and Real-time Developer Notifications — how the backend checks a purchase token and hears about renewals, cancellations and refunds. Server to server; the app is not involved.
  • Google Sign-In — optional. Used only if you choose to sign in with Google, in which case Google knows you signed in to Fokus IO. The app receives an identity token, which the backend verifies against Google’s public keys; Fokus IO holds no Google password and no OAuth client secret.
  • Google Maps — the map on a PARENT’s screen. Loading the map sends the device’s IP address and the map viewport to Google. A child’s device never draws a map.
  • Google Fonts — the app’s three typefaces are downloaded from Google’s font CDN on first run and cached on the device. Google receives the request, which includes the device’s IP address. No account data is involved.
  • Google Gmail SMTP — delivery of verification and password-recovery email, over encrypted transport.
  • Hetzner Online GmbH (Germany) — hosting, storage and backups for the Fokus IO backend.

What is NOT sent anywhere

QR-code scanning during pairing runs entirely on the device: the barcode model ships inside the app, the camera image is never uploaded, and no image or scan result leaves the phone. Notifications, the timer, the streak, the Shield’s own decisions and screen-time accounting are all local. Fokus IO does not sell personal data and does not use Family Sync data for advertising.

Retention and deletion

  • Verification codes expire after 10 minutes.
  • Executed remote commands and site-domain history are removed automatically according to server retention limits (site history: 14 days).
  • Only the latest child location is stored.
  • Signing out revokes the account’s active sessions.
  • A parent can permanently delete the parent account and linked family data in the app.
  • A linked child’s deletion request has a 48-hour visible and cancellable delay before deletion.
  • Unlinking removes the child’s family profile, synced statistics, location, site history and pending commands.
  • A subscription record is kept while the account exists and is deleted with it.
  • Billing notifications from Google Play are kept for at most 400 days as a dated record of what changed.

Security

Connections to fokusio.net use HTTPS. Passwords use a memory-hard password hash; verification and refresh credentials are not stored on the server in plain text. The database and backups use restricted filesystem permissions.

No security system can guarantee absolute protection, but access controls, rate limits, isolation tests, encrypted transport and regular backups are used to reduce risk.

Children and parental transparency

Family Sync is designed to be set up with the child’s awareness. Monitoring features use visible permission screens and persistent Android indicators. A parent cannot silently grant Android location, VPN, accessibility, usage access or overlay permissions from another device. Parents should review these controls and this policy with their child.

Your choices

You can decline optional permissions, turn off site history, revoke location access, unlink Family Sync, sign out, or request account deletion from the app. See the account deletion page for exact steps, including for a device the app is no longer installed on. For an access, correction, deletion or other privacy request, contact s.mohsunlu.dev@gmail.com.

Changes

If data collection, providers or Family Sync behaviour materially changes, this policy and its effective date will be updated. Material privacy changes will also be communicated in the app where appropriate.

Back to the home page