Privacy Policy

1. Overview

FocusGrove (“we,” “our”) respects your privacy. This Privacy Policy describes what data we collect when you use the FocusGrove Chrome extension and related services, how we use it, and your choices.

2. Data We Collect

Data you provide

  • Account information: If you sign in (e.g., with Google), we receive your email, name, and profile picture from the provider to identify you and provide sync and paid features.
  • Tasks and usage: Task titles, completion status, focus time, and similar data are stored when you use the extension. When you use cloud sync or our backend, this data may be stored on our servers.

Data we collect automatically

  • Usage and errors: We may collect anonymous or aggregated usage data and error reports to improve the Service.
  • Extension storage: The extension may store data locally in your browser (e.g., Chrome storage) for tasks, settings, and sync state.

3. How We Use Your Data

We use the data we collect to:

  • Provide, operate, and improve the FocusGrove extension and backend services.
  • Authenticate you and manage your account and subscription.
  • Sync your tasks and state across devices when you use sync.
  • Process payments and enforce our Terms of Service and Refund Policy.
  • Send important service or policy updates where appropriate.
  • Comply with legal obligations and protect our rights.

We do not sell your personal data to third parties.

4. Data Sharing

We may share data only in these cases:

  • Service providers: With vendors that help us run the Service (e.g., hosting, payment processing), under strict confidentiality and data-processing terms. This includes:
    • Google OAuth: For authentication (email, name, profile picture, Google ID)
    • Anthropic (Claude AI): For AI Pro users, task context and titles are sent to Anthropic's API in the United States for AI task generation. Anthropic processes this data under their Privacy Policy.
    • Dodo Payments: For payment processing (if you subscribe to paid tiers). Dodo Payments processes this data under their Privacy Policy.
  • Legal: When required by law, court order, or government request, or to protect our rights, safety, or property.
  • Consent: Where you have given explicit consent for a specific use.
  • Cross-border transfers: Data may be transferred to and processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place.

5. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service, resolve disputes, and comply with legal obligations. Specific retention periods:

  • Account data: Retained while your account is active
  • Tasks and settings: Retained while your account is active
  • Audit logs (IP addresses, user-agents): Retained for 90 days for security purposes, then automatically deleted
  • Refresh tokens: Retained for 7 days or until logout

You may request deletion of your account and all associated data through the extension settings ("Delete Account" button). Upon deletion, all your personal data will be permanently removed within 48 hours, except where retention is required by law.

6. Security and Data Breach Notification

We use industry-standard measures to protect your data, including:

  • HTTPS encryption for data in transit
  • JWT-based authentication with token versioning
  • API key validation
  • Rate limiting to prevent abuse
  • Audit logging of security-sensitive operations

No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

Data Breach Notification: In the event of a personal data breach that may result in risk to your rights and freedoms, we will notify affected users via email within 72 hours of becoming aware of the breach. We will also notify the relevant data protection authorities as required by law (including the Data Protection Board of India for users in India).

If you discover a security vulnerability, please report it to security@focusgrove.xyz.

7. Your Rights

Depending on your location, you may have the right to access, correct, delete, or port your personal data, or to object to or restrict certain processing. You can exercise these rights as follows:

  • Right to Access: Contact us via our contact form to request a copy of your data
  • Right to Export: Use the "Export My Data" button in extension settings to download all your data in JSON format
  • Right to Delete: Use the "Delete Account" button in extension settings to permanently delete your account and all data
  • Right to Correct: Update your information through your Google account or contact us
  • Right to Withdraw Consent: You can withdraw consent by signing out or deleting your account

For users in India: You have the right to nominate another individual to exercise your rights in case of death or incapacity, file a grievance with our Data Protection Officer (contact below), and request restriction of processing. We will respond to your requests within 7 business days.

Data Protection Officer: For privacy concerns or to exercise your rights, contact us via our contact form or email privacy@focusgrove.xyz

8. Children and Minors

The Service is not intended for users under 18 years of age. We do not knowingly collect personal data from individuals under 18 without verifiable parental consent. By using the Service, you confirm that you are 18 years of age or older.

If you are a parent or guardian and believe your child under 18 has provided us with personal data without your consent, please contact us immediately at privacy@focusgrove.xyz so we can delete it.

For users in India: In compliance with the Digital Personal Data Protection Act, 2023, we require explicit consent confirmation for users under 18. If we discover that a user is under 18 and verifiable parental consent was not obtained, we will delete their data immediately.

9. Changes

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the “Last updated” date. Continued use of the Service after changes constitutes acceptance. Significant changes may be communicated via email or in-product notice where appropriate.

10. Contact

For privacy-related questions or requests, use our contact form.