Privacy Policy
This Privacy Policy explains how Tomo handles information when you use the Tomo mobile application and related services.
Effective and last updated: August 18, 2026
1. Scope and who we are
Tomo is operated by Benjamin Liang (“Tomo,” “we,” “us,” or “our”). This Policy applies to the Tomo mobile application, its cloud services, and support communications that refer to this Policy. It does not apply to third-party websites, applications, or services that have their own privacy policies.
2. Privacy at a glance
- We collect the account and productivity information needed to provide and sync Tomo.
- We use service providers for authentication, cloud storage, app functionality, and subscription management.
- We do not sell personal information or use it for third-party advertising or cross-app tracking.
- Tomo does not request access to your contacts, photos, microphone, or precise location.
- You can delete your Tomo account and associated cloud data from the Profile screen in the app.
3. Information we collect
Account and identity information
When you create or use an account, we process your email address, Firebase user ID, account creation date, authentication provider, and, when available from you or your sign-in provider, your name and profile image. If you use Sign in with Apple or Google Sign-In, Apple or Google provides the information you authorize it to share. Apple may provide a private relay email address instead of your personal email address. If you use email and password, Firebase Authentication processes the password credential; Tomo does not receive or store your password in readable form.
Tasks, categories, and focus activity
We store content you create in Tomo, including task names, categories and category icons, due dates, completion status, optional focus-session titles, linked task identifiers, session duration, session completion time, and aggregated focus statistics. We may also store your time zone so dates, summaries, and account features work correctly.
Subscription and purchase information
If you use Tomo Plus or another paid feature, we process a user identifier linked to your Tomo account, product and entitlement identifiers, subscription status, expiration and grace-period dates, purchase environment, and synchronization time. Apple or Google processes payment details. RevenueCat processes store receipts or purchase tokens and purchase history to validate purchases, prevent fraud, restore purchases, provide subscription reporting and analytics, and determine which features you can access. We do not receive your full payment-card number.
Information stored on your device
Tomo stores app preferences, such as theme, sound, notification settings, and selected animation, on your device. Active timer and stopwatch state, scheduled-notification identifiers, and account-deletion recovery credentials may also be kept locally so those features survive an app restart. Local notifications are scheduled through your device’s operating system. Tomo does not use notification permission to access the content of unrelated notifications.
Technical and operational information
Our infrastructure providers may process IP addresses, user-agent strings, device or operating-system information, application identifiers, request times, and similar technical data to deliver requests, authenticate users, secure the service, prevent abuse, and diagnose failures. Operational logs for account deletion are designed to contain request IDs and sanitized error codes rather than emails, authentication tokens, authorization codes, or raw provider responses.
4. How we collect information
We collect information:
- directly from you when you create an account, create content, change settings, make a purchase, or contact us;
- automatically from the app and device when necessary to operate, sync, secure, and troubleshoot Tomo;
- from Apple or Google when you choose a third-party sign-in method or complete a store transaction; and
- from RevenueCat when it validates a purchase or sends us a subscription-status update.
5. How we use information
We use information to:
- create, authenticate, secure, and maintain your account;
- store and synchronize tasks, categories, focus sessions, and progress summaries;
- run timers and stopwatches and deliver notifications you enable;
- process, validate, restore, and manage subscription access;
- provide support and respond to privacy or account requests;
- detect fraud, abuse, security incidents, and technical problems;
- enforce our Terms of Use and protect users, Tomo, and others; and
- comply with law and establish, exercise, or defend legal claims.
6. When we disclose information
We disclose information only as described below:
- Google Firebase. Firebase Authentication, Cloud Firestore, and Cloud Functions provide authentication, cloud storage, synchronization, and backend processing. See Firebase Privacy and Security and the Google Privacy Policy.
- RevenueCat. RevenueCat processes user identifiers, technical information, store transaction information, and purchase history on our behalf to manage subscriptions, entitlements, and subscription reporting. See the RevenueCat Privacy Policy.
- Apple and Google. Apple and Google process sign-in and store transactions when you use their services. Their handling is governed by their own terms and privacy policies.
- Legal and safety reasons. We may disclose information if reasonably necessary to comply with law or valid legal process; enforce agreements; investigate fraud, abuse, or security issues; or protect the rights, property, and safety of users, Tomo, or others.
- Business transfers. If Tomo is involved in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, information may be disclosed as part of that transaction, subject to this Policy and applicable law.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use advertising SDKs. We require service providers that process personal information for us to protect it and use it only to provide contracted services or as permitted by law.
7. Legal bases for processing
Where applicable law requires a legal basis, we process information as necessary to perform our contract with you, including providing your account and requested app features; to comply with legal obligations; with your consent, such as when you enable notifications; and for legitimate interests such as securing, maintaining, and improving Tomo, preventing fraud, and protecting legal rights, provided those interests are not overridden by your rights. You may withdraw consent at any time, but withdrawal does not affect processing already completed lawfully.
8. Retention and account deletion
We generally retain account information and cloud-stored Tomo content while your account is active. We may retain limited information longer when reasonably necessary for security, fraud prevention, dispute resolution, legal compliance, or the establishment, exercise, or defense of legal claims.
You can request deletion in Tomo under Profile → Delete account. Tomo reauthenticates you, immediately locks the account against further cloud access, and begins an asynchronous process that deletes your Firestore user document and subcollections, your Firebase Authentication account, and your RevenueCat customer record. Tomo also attempts to revoke the relevant Apple or Google sign-in authorization. Completed deletion-job records are scheduled to expire after 30 days, and a temporary access-blocking record is scheduled to expire 72 hours after authentication deletion succeeds.
We retain a minimal suppression record keyed by a cryptographic hash of the former Firebase user ID. It does not contain the original user ID and is used only to prevent delayed store events from recreating a deleted account. Our providers may retain deleted data in backups or as required by law; Firebase states that covered authentication data is removed from live and backup systems within up to 180 days after deletion is initiated.
Deleting your Tomo account does not cancel an App Store or Google Play subscription. You must cancel recurring billing in your store account. Apple, Google, and other providers may retain transaction records under their own policies and legal obligations.
9. Your choices and privacy rights
Depending on where you live, you may have the right to:
- request access to or a copy of personal information we hold about you;
- correct inaccurate personal information;
- request deletion of personal information;
- restrict or object to certain processing;
- receive certain information in a portable format;
- withdraw consent; and
- appeal our response or complain to your local data-protection authority.
You can update some account information through your sign-in provider, change notification and sound preferences in Tomo, revoke notification permission in device settings, manage social sign-in access through Apple or Google, and delete your account in the app. You may also submit a request to support@tomofocus.com. We may need to verify your identity before completing a request. We will not discriminate against you for exercising a privacy right.
10. Children’s privacy
Tomo is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If local law requires a higher age for a person to consent to processing, a user below that age may use Tomo only with valid authorization from a parent or legal guardian. If you believe a child has provided personal information contrary to this section, contact us at support@tomofocus.com so we can investigate and delete it where required.
11. International data transfers
Tomo and its providers may process information in the United States and other countries where they operate. Those countries may have privacy laws different from those where you live. Where required, we rely on recognized transfer mechanisms and contractual protections for international transfers.
12. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. These include authenticated access controls, per-user database rules, encrypted network transport, provider security controls, and reauthentication before account deletion. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
13. Changes to this Policy
We may update this Policy to reflect changes to Tomo, our practices, or applicable law. We will update the date above and, when required, provide additional notice in the app or through another appropriate channel. If a change requires consent, we will request it before the change applies to you.
14. Contact us
Benjamin Liangsupport@tomofocus.com