Privacy Policy
OneFocus is designed to collect only what is needed to provide your account, membership, product updates and support.
Information we process
We process your name, email address, inferred country, region and approximate city-level location, account status, trial dates, install/open events, anonymous per-tab session identifiers, subscription identifiers and feedback you choose to submit. Session identifiers are used only for approximate activity counts and do not contain your name, email, IP address or task content. Promotional links may contain non-identifying campaign labels such as source, medium and campaign name. We use those labels to compare aggregate campaign traffic; we do not store the referring page URL. Payment card details are processed by Razorpay and are not stored by OneFocus.
Approximate location is provided by our hosting edge and is used to show aggregate live-audience trends and, when you submit feedback, the approximate city, region and country beside that submission in the protected Owner Dashboard. Map coordinates are rounded to a broad area and city names are approximate. OneFocus does not request GPS permission or store IP addresses, exact coordinates, PIN codes or precise individual locations.
Your task content
Your OneFocus planner database remains on this device in your browser or installed app. OneFocus does not upload it for cloud task sync, and task text and task-completion details are not sent to owner analytics. Backup and restore happen through a file you download and choose yourself. Backups exclude account, payment, authentication, Google OAuth token and operational records. Clearing browser storage can remove device-local planner data, so keep a recent backup somewhere you trust.
Optional Google Calendar connection
Google Calendar access is separate from sign-in and begins only when you choose to connect it. OneFocus requests permission for events on calendars you own. It accesses event identifiers, titles, start dates and times, time zones, all-day and cancellation status, update time, event links, and OneFocus source identifiers used to prevent duplicate events. It also receives your Google account identifier, email address and granted scope list for the connection.
OneFocus uses this information only to send selected OneFocus tasks to Google Calendar, import your Google events into your device-local planner, show changes, and safely match later edits or cancellations. The server stores an encrypted refresh token, connection identity and scopes, incremental sync cursor, sync time zone and timestamps, plus a per-user event/source ledger and the event fields listed above. Tokens are not sent to the browser or included in OneFocus backup files, and each user's connection and Calendar records are isolated by account.
Calendar connection data is retained while the integration is connected. Choosing Disconnect Google Calendar asks Google to revoke the grant when possible and permanently deletes from OneFocus the encrypted refresh token, connection, sync cursor and Calendar event ledger. Events already saved in Google Calendar remain in Google unless you delete them there. If Google is temporarily unavailable, OneFocus still deletes its local connection data and tells you that remote revocation could not be confirmed.
OneFocus's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Read the Google API Services User Data Policy.
How Google user data is shared
OneFocus does not sell, rent or use Google user data for advertising, marketing, credit decisions or unrelated analytics. We do not share, transfer or disclose Google user data to third parties except to the hosting and infrastructure providers that process it only as needed to operate and secure the Calendar integration, when disclosure is required by applicable law, or when you give explicit consent. Those service providers may not use the data for their own purposes.
How sensitive Google user data is protected
Google user data is transmitted over HTTPS. Google refresh tokens are encrypted at rest with a production-only encryption key, remain on the server, and are never exposed to browser JavaScript. OneFocus uses authenticated account access, per-user database isolation and restricted production secrets to limit access. We retain only the fields needed for synchronization and delete the connection, token, cursor and event ledger when you disconnect, as described above.
Service providers
We use infrastructure providers to host the service, Google to verify sign-in identity, and Razorpay to process payments. If the owner enables optional email access codes, an email delivery provider sends those codes. These providers process data under their own privacy terms and our service configurations.
Why we use information
We use it to authenticate you, run the trial, control paid access, provide updates, prevent abuse, understand aggregate product usage, resolve glitches and meet legal or accounting obligations.
Retention and your choices
We retain account and transaction records while your account is active and as required for legitimate legal, fraud-prevention and tax purposes. You may request access, correction or deletion by using the contact page.
International users
OneFocus serves users globally. Your information may be processed in countries other than your own, with safeguards provided by our service providers and applicable law.
Contact
Privacy questions and data requests can be submitted through the contact page or by email at support@onefocus.me.