Privacy policy
Introduction
FocusCurve ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how FocusCurve handles information when you use our mobile application ("the App").
The short version: your medication data stays on your device. We use anonymous crash reporting to fix bugs and privacy-focused website analytics to understand how visitors interact with this marketing website — neither contains health information or personally identifiable data.
1. Information we do not collect
FocusCurve is designed with a local-first architecture. The following data is stored exclusively on your device and is never transmitted to us or any third party:
- Medication dose records (type, amount, timing)
- Caffeine intake records
- Personalization settings (body weight and metabolism preferences)
- Onboarding questionnaire responses
- Sleep prediction data
- Notification preferences and schedules
- Any other health-related information you enter into the App
We have no servers that receive your health data. We cannot access, view, or recover your data. If you delete the App, your data is permanently deleted from your device.
2. Information we may collect
2a. Crash reports and diagnostics
FocusCurve uses Sentry (Functional Software, Inc.) to collect anonymous crash reports and performance data. This helps us identify and fix bugs. The data collected includes:
- Crash stack traces (technical error information)
- Device type and operating system version
- App version and build number
- Performance metrics (app startup time, screen load times)
This data does not include:
- Your medication records, doses, or timing
- Your health data or onboarding responses
- Your name, email address, or any personal identifiers
- Advertising identifiers or persistent device IDs
Crash data is transmitted encrypted (TLS) to Sentry's servers and cannot be linked to your identity. We actively scrub any health-related data from error reports before they are sent. For more information, see Sentry's Privacy Policy.
2b. Website analytics (PostHog)
Our marketing website (focuscurve.app) uses PostHog (PostHog, Inc.) to understand how visitors interact with the website. This helps us improve the website experience and measure the effectiveness of our content. PostHog is configured to use their EU data residency (eu.i.posthog.com), meaning all analytics data is processed and stored within the European Union.
The data collected by PostHog includes:
- Pages visited and navigation patterns on the marketing website
- Button clicks (e.g., App Store download link)
- Referring website (how you found us)
- Browser type, operating system, and screen size
- Country-level geographic information (derived from IP address)
This data does not include:
- Any data from within the FocusCurve mobile app
- Your medication records, doses, or health data
- Your name, email address, or other personal identifiers
- Cross-site tracking or advertising profiles
PostHog uses cookies and localStorage on the marketing website to distinguish unique visitors and maintain session continuity. These are first-party identifiers set by our domain (focuscurve.app) and are not shared with third parties. PostHog is configured in anonymous mode (identified_only person profiles), meaning no personal profiles are created for website visitors.
Website analytics data is processed under our legitimate interest (GDPR Article 6(1)(f)) in understanding website performance. For more information, see PostHog's Privacy Policy.
2c. Apple-provided diagnostics
If you have opted in to sharing diagnostics with app developers through your device settings (Settings > Privacy & Security > Analytics & Improvements), Apple may share anonymized crash reports and performance metrics with us. These reports do not contain your health data, personal information, or App usage content.
You can disable this at any time in your device settings.
2d. App Store analytics (Apple-provided)
Apple provides us with aggregated, anonymized App Store analytics including download counts, device types, and geographic regions. This data is collected and anonymized by Apple and cannot be used to identify individual users.
2e. Support communications
If you contact us via email for support, bug reports, or feature requests, we receive and store the information you voluntarily provide (your email address and the content of your message). We use this information solely to respond to your inquiry. We do not add support emails to marketing lists, and we do not share your contact information with third parties.
3. How your data is stored
All App data is stored locally on your device using an on-device database. The data is protected by your device's built-in security features, including device passcode, Face ID / Touch ID, and iOS data encryption.
We do not use cloud storage, cloud sync, remote databases, or any server-side infrastructure for user data.
Backup behavior: If you use iCloud Backup or iTunes/Finder backup, your FocusCurve data may be included in your device backup according to Apple's backup policies. These backups are governed by Apple's privacy policy and your iCloud settings, not by FocusCurve.
4. Third-party services
FocusCurve does not integrate with any advertising networks, data brokers, or social media platforms.
The third-party services we use are limited to:
- Sentry (Functional Software, Inc.) — anonymous crash reporting and performance monitoring, as described in Section 2a. Sentry acts as a data processor under a signed Data Processing Addendum. No health data is transmitted to Sentry.
- PostHog (PostHog, Inc.) — privacy-focused website analytics on our marketing website (focuscurve.app), as described in Section 2b. PostHog is configured with EU data residency (eu.i.posthog.com), meaning all data is processed and stored within the European Union. PostHog uses first-party cookies and localStorage for session tracking on the marketing website. No health data or mobile app data is transmitted to PostHog. For more information, see PostHog's Privacy Policy.
- Apple App Store — processes your purchase and provides us with aggregated, anonymized analytics as described in Section 2d.
- Cloudflare Web Analytics (Cloudflare, Inc.) — privacy-first website analytics on our marketing website (focuscurve.app). Cloudflare Web Analytics does not use cookies, does not collect personal information, does not track visitors across sites, and does not collect or process any health data. It measures basic website performance metrics such as page views, referral sources, and visitor counts. No consent banner is required as no personal data is collected. For more information, see Cloudflare Web Analytics.
We do not use Google Analytics, Firebase, Facebook SDK, Google Ads, or any other advertising or cross-site tracking tools. No third-party service receives your health data.
5. Data sharing
We do not share your health data with anyone. Specifically:
- We do not sell your personal or health information
- We do not share data with advertisers
- We do not share data with data brokers
- We do not share health data with any third parties for any purpose
The only data that leaves your device is anonymous crash and performance diagnostics sent to Sentry (see Section 2a) and anonymous website analytics collected by PostHog on the marketing website (see Section 2b). Neither contains health information or personally identifiable data.
The only scenario in which data leaves your device is if you actively choose to share a report (e.g., exporting a PDF to email to your healthcare provider). This sharing is initiated and controlled entirely by you through your device's standard sharing functionality.
6. Children's privacy
FocusCurve is not intended for use by children under the age of 17. We do not knowingly collect information from children. ADHD medication management should be supervised by a healthcare provider and, for minors, by a parent or guardian.
7. Your rights
Because your data is stored exclusively on your device, you have complete control over it at all times:
- Access: All your data is visible to you within the App at any time.
- Export: You can export your data from within the App at any time.
- Deletion: You can delete individual records within the App, or delete all data by deleting the App from your device.
- Portability: Export features allow you to download your data in standard formats.
For users in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws:
Your health data never leaves your device — you are the sole data controller of that data. For the anonymous crash and performance data sent to Sentry (Section 2a), we rely on legitimate interest (GDPR Article 6(1)(f)) as the legal basis: maintaining app stability and fixing crashes. Sentry acts as our data processor under a signed Data Processing Addendum that includes EU Standard Contractual Clauses for international data transfers. For website analytics via PostHog (Section 2b), we also rely on legitimate interest (GDPR Article 6(1)(f)): understanding website performance and improving the visitor experience. PostHog is configured with EU data residency, so all analytics data remains within the European Union.
If you have questions about your rights or our privacy practices, please contact us at the address below.
8. Data retention
Your health data exists only on your device for as long as you choose to keep the App installed. We do not retain any health data because we do not collect any.
Anonymous crash and performance data sent to Sentry is retained for 90 days, after which it is automatically deleted. Website analytics data collected by PostHog is retained in accordance with PostHog's data retention policies and is automatically deleted after the configured retention period.
If you contact us for support, we retain your email correspondence for a reasonable period to provide ongoing support and then delete it. We do not retain support correspondence indefinitely.
9. Security
While we do not receive or store your data, we take the security of your on-device data seriously by:
- Storing all health data in the App's sandboxed container, protected by iOS security
- Encrypting all crash report and analytics transmissions using TLS (transport layer security)
- Scrubbing health-related data from crash reports before transmission
- Using EU data residency for website analytics (PostHog) to keep data within the European Union
- Not including any remote access or remote data retrieval capabilities
- Following Apple's security best practices for on-device data storage
10. Changes to this privacy policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App or by updating the "Last updated" date at the top of this policy. We encourage you to review this Privacy Policy periodically.
11. California privacy rights (CCPA)
Under the California Consumer Privacy Act, California residents have specific rights regarding their personal information. FocusCurve does not sell or share personal information for cross-context behavioral advertising. The anonymous crash data processed by Sentry and the anonymous website analytics processed by PostHog are handled under service provider agreements and are not considered a "sale" or "sharing" under the CCPA.
12. Contact us
If you have questions about this Privacy Policy or FocusCurve's privacy practices, please contact us at:
Email: privacy@focuscurve.app
Website: https://focuscurve.app/privacy