Privacy Policy
FocusAlly is a focus companion. It keeps your sessions, intentions and reflections — which are personal notes — so this policy describes exactly what stays on your device, what leaves it, and when.
Who we are
FocusAlly is developed and operated by Individual Entrepreneur Aleksandr Senin, registered in Georgia under identification number 336055413, at Georgia, Mtskheta region, Tskvarichamia. We are the controller of the data described below.
You can reach us at support@withally.app.
Scope
This policy covers the FocusAlly app for macOS and iOS and the FocusAlly backend service
at focus-api.withally.app. It does not cover Apple's services, which are
governed by Apple's own privacy policy.
What we collect, why, and where it lives
On your device
Everything you create in FocusAlly is written to a local database on your device first. This works with no account and with no network connection.
| Data | Purpose | Leaves the device? |
|---|---|---|
| Focus sessions — start and end time, planned duration, and your free-form intention text | The core function of the app | Only when you are signed in |
| Reflections — an emoji rating and a free-form note | Reviewing how a session went | Only when you are signed in |
| Tasks, task↔session links, categories, task statuses and status changes, daily priorities | Planning and history | Only when you are signed in |
| Settings and preferences, including which calendars you selected (their identifiers only) | Remembering how you set the app up | Reminder preferences are sent to the server when signed in, so scheduled insights fire at the right time |
Account data
| Data | When | Purpose |
|---|---|---|
| Email address | Only if you sign in with a one-time code | Delivering the code and identifying your account |
| Apple account identifier | Only if you use Sign in with Apple | Identifying your account. If you choose to hide your email, we receive Apple's relay address, not your real one |
| A user identifier issued by our server, and a device identifier generated on your device | When you sign in | Routing your data to the right account and device |
| Authentication tokens | When you sign in | Keeping you signed in. Stored in the system Keychain |
| Apple Push Notification device token | If you allow notifications | Delivering reminders and insights |
Content synchronised when you are signed in
Signing in turns on synchronisation between your devices. From that point your sessions (including the intention text and the reflection note), tasks, task↔session links, categories, task statuses and status change history, daily priorities, and the insights generated for you are stored on our server so your devices can share them. Text you write in the app leaves your device when you are signed in.
If you use the FocusAlly plugin for an AI coding agent, the agent's reported work sessions are also stored on your account.
Analytics
The app sends product analytics to Amplitude: app launch and foreground/background events, sign-in outcomes, screen views, session start and stop, reflections submitted, overflow and rest, task events, and paywall and purchase events. Along with them we send a device identifier, the platform, the app version and the environment.
Amplitude also attaches its own standard context to each event: your device model, its operating system version, and — on a cellular iPhone or iPad — your mobile carrier.
Approximate location
Amplitude derives an approximate location — roughly city and country — from the IP address your analytics events arrive from, and records it alongside them. We use it only to understand where FocusAlly is used, as part of the product analytics described above.
This is coarse and inferred, not measured. FocusAlly does not use location services and never asks you for location permission — the app declares no location usage at all, and your device's precise location is never available to it or to us. If you reach our servers through a VPN, the location inferred is the VPN's.
Analytics never contain the text you write. This is enforced by the
shape of the code rather than by policy: an intention becomes
has_intention and intention_length, a reflection note becomes
has_note, and a category becomes its identifier — never its name. The only text
values in an analytics event are fixed, machine-controlled values such as a screen name, a
stop reason, or a product identifier.
Diagnostics
FocusAlly contains no crash-reporting or logging SDK, and we receive no crash reports or performance traces from the app itself. If Apple's own crash reporting is enabled in your system settings, Apple may share crash data with us in aggregated form through App Store Connect; that is Apple's mechanism, not ours.
The device model, operating system version and carrier that ride along with analytics events, described above, are the only device diagnostics we receive.
Using FocusAlly signed out
FocusAlly is fully usable without an account. When you are not signed in, none of your sessions, intentions, reflections, tasks or categories are sent anywhere — they exist only in the local database on your device. Analytics events are still sent — with the device context and the IP-derived approximate location described above — and they still contain none of the text you write.
AI features
FocusAlly can generate insights about your focus patterns and nudges that help you stay on track. This generation happens on our server, which sends a prompt to a third-party large language model provider (see the list below). That prompt can include your own FocusAlly data — sessions, intentions, tasks and their titles — because that is what an insight about your work is derived from.
Some AI features let the model read your FocusAlly data directly through our MCP interface, using a token that is scoped to your account and to the specific operations the feature needs.
You can turn scheduled insights off: the daily, weekly and monthly insight switches in the app's Reminders settings are sent to the server, and a disabled schedule is not generated.
Model providers are accessed through their business APIs, which they operate under terms that do not use API content to train their models.
Subscriptions and payments
FocusAlly subscriptions are sold through Apple. Apple processes the payment; we never see or receive your payment card details. We receive from Apple whether your subscription is active and the transaction identifiers needed to keep your entitlement in sync across your devices.
Calendar access
If you grant calendar permission, FocusAlly reads events from the calendars you select so it can show them on your timeline, and can create or edit events when you ask it to. Those events are read from the system calendar into memory each time the timeline needs them. Calendar events are not stored in FocusAlly's database and are not sent to our server. Only the identifiers of the calendars you selected are stored, locally.
You can revoke calendar access at any time in your system settings.
Notifications
With your permission FocusAlly sends notifications: local reminders such as idle nudges and unnamed-session prompts, generated entirely on your device, and — when you are signed in — pushed insights delivered through Apple's Push Notification service. Delivering a push requires the device token described above. You can revoke notification permission at any time in your system settings.
Who else processes your data
We use the following service providers. Each one processes only what its function requires.
- Apple — app distribution, subscription payments, push notification delivery, Sign in with Apple.
- Amplitude — product analytics, as described above.
- Resend — sending the one-time sign-in code to your email address.
- OpenAI and Anthropic — generating insights and nudges.
- Hetzner — hosting the FocusAlly backend and its database.
- Cloudflare — hosting this website.
We do not sell your data. We do not use it for advertising, and FocusAlly contains no advertising or tracking SDK. We do not track you across other companies' apps or websites.
Retention
Data on your device stays there until you delete it or remove the app.
When you are signed in, the data described above is kept on our server for as long as your account exists, so your devices can keep synchronising it. Deleting a session, a task or a category in the app deletes it on the server too; a small deletion marker is retained afterwards so that your other devices learn about the deletion and do not restore it.
Analytics events are retained by Amplitude under its own retention schedule.
Your rights
You can ask us for a copy of the data associated with your account, ask us to correct it, ask us to delete it, or object to a particular use. Write to support@withally.app from the email address you signed in with, or tell us the sign-in method you used so we can confirm the request is yours. We answer requests within 30 days.
Deleting your account
You can delete your account from inside the app: open Profile, open your account details, and choose Delete account. No email to us is needed.
The account is signed out and gone from every device immediately, and the data held on our server is erased seven days later. You cannot sign back in during those seven days — the account is already gone. Deleting your account does not cancel an Apple subscription; subscriptions are managed in your Apple account settings.
Data in the local database on a device is removed by deleting the app from that device.
If you would rather not use the in-app flow, or you cannot sign in to reach it, write to support@withally.app and we will delete the account for you.
Children
FocusAlly is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has given us their data, write to us and we will delete it.
International transfers
Our servers are located in the European Union. Our service providers may process data in other countries, including the United States. Wherever your data is processed, it is processed for the purposes described here and nothing else.
Changes to this policy
If this policy changes we update this page and the date at the top. The date tells you whether what you read last is still current.