Privacy Policy
This notice explains what personal data Kwami collects when you use Focus Flow, why we collect it, who we share it with, and the rights you have over it.
1. Who we are
Focus Flow is operated by Kwami. For the personal data you provide directly to Focus Flow — your account information, the goals and contracts you enter, and your session history — Kwami acts as the data controller. For payment data captured at checkout, Paddle.com Market Limited (Paddle) acts as an independent controller as the Merchant of Record.
Contact: support@digikwic.com
2. What we collect and why
Account data
When you create an account we collect your email address and an authentication identifier (a hashed password or, if you sign in with a third-party provider, an opaque provider identifier). We use this to create and secure your account, authenticate you, send transactional messages (password resets, receipts, service notices), and provide support.
Legal basis: performance of a contract.
Product data (Ledger, contracts, sessions)
When you run a session, Focus Flow stores the goals you locked, the session length, the outcome you recorded, and timestamps. This is the core Ledger that powers your history and analytics. If you are signed in, this data is synced to our backend so it is available across devices and preserved long-term.
Legal basis: performance of a contract.
Usage and diagnostic data
We collect a limited amount of technical information — browser type, device type, screen size, referring URL, error stack traces, and coarse timing of requests — to keep the Service reliable and to diagnose bugs. Where possible we use aggregated or pseudonymous identifiers rather than direct identifiers.
Legal basis: legitimate interests in operating a secure and reliable service.
Support communications
If you email us we retain your message, your address, and our reply so we can respond and follow up.
Legal basis: legitimate interests in providing support.
Payment and billing data
When you subscribe, checkout is processed by Paddle.com Market Limited (Paddle) as the Merchant of Record. Paddle collects your billing name, billing address, tax identifiers where applicable, and payment method details directly. Focus Flow does not receive or store your full payment card details. Paddle shares with us the fact that you are a paying subscriber, the product/price you purchased, your subscription status, and an opaque customer identifier so we can grant Premium access and show your subscription in the Command dashboard.
Legal basis: performance of a contract; compliance with a legal obligation (tax and record-keeping).
Paddle's handling of your payment data is governed by the Paddle Privacy Notice.
3. Local-only data
If you use Focus Flow without signing in, your goals, session history, and Ledger entries are stored in your browser's local storage on your device. This data does not leave your device and we cannot see it. Clearing your browser storage will erase it.
4. Cookies and similar technologies
We use the following categories of storage in your browser:
- Strictly necessary — session storage for your logged-in session, CSRF protection, and a local checkpoint that lets an in-progress focus session survive a page refresh. These are required for the Service to work and do not require consent.
- Preferences — small stored values that remember which onboarding hints you have already seen and your last-used session settings.
- Payments — the Paddle checkout overlay sets cookies while it is open to complete a transaction. These are subject to Paddle's own privacy notice.
We do not currently use third-party advertising or cross-site tracking cookies. If we add analytics that require consent in your jurisdiction we will present a cookie banner before those cookies are set.
5. Who we share data with
- Hosting and infrastructure providers — the vendors who run our servers, database, and content delivery. They process data on our behalf under written contracts.
- Paddle.com Market Limited (Paddle) — Merchant of Record for checkout, subscription management, invoicing, and tax compliance.
- Email delivery provider — sends transactional email (password resets, receipts, service notices) on our behalf.
- Support tooling — used to receive and respond to your support emails.
- Professional advisers (legal, accounting) where reasonably required, and authorities where we are required by law to disclose information.
We do not sell your personal data.
6. Retention
- Account & product data: kept for as long as your account is active, plus a short buffer for backups and disaster recovery. Deleted within 30 days of account deletion (or sooner where required).
- Billing records: retained by Paddle and by us for as long as required by tax and accounting law in the applicable jurisdiction (typically 6–10 years).
- Support emails: kept for up to 24 months after the last message in the thread.
- Diagnostic logs: retained for up to 90 days, then rotated.
7. International transfers
The Service is delivered from data centers that may be located outside your country of residence, including the United States and the European Economic Area. Where personal data is transferred out of the UK/EEA, we and our processors rely on the European Commission's Standard Contractual Clauses (or the UK equivalent) and equivalent safeguards.
8. Your rights
Subject to applicable law, you have the right to access, correct, delete, restrict, or object to our processing of your personal data, and the right to data portability. Where processing is based on consent you can withdraw that consent at any time. If you are in the UK or EEA you also have the right to complain to your local data protection authority; if you are in California you have the rights described in the CCPA/CPRA, including the right to know, delete, and opt out of "sale" or "sharing" of personal information (we do not sell or share personal information as defined by those laws).
To exercise any of these rights, email support@digikwic.com. We aim to respond within 30 days.
9. Security
We use industry-standard technical and organizational measures to protect your data, including encryption in transit (HTTPS), encryption at rest for the database, row-level access controls that restrict data to the account it belongs to, and least-privilege access for our team. No system is perfectly secure — please use a strong, unique password and notify us promptly if you suspect unauthorized access.
10. Children
The Service is not directed to children under 13 (or the minimum age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this notice
We may update this Privacy Policy from time to time. Material changes will be communicated by email or an in-product notice before they take effect. The "Effective" date at the top of this page reflects the latest revision.
12. Contact
KwamiPrivacy contact: support@digikwic.com