Privacy Policy

Effective: May 14, 2026 · Last updated: August 6, 2026 (v7)

Student Focus ("we", "our", "us", or the "Service") is operated by an individual developer based in Quebec, Canada. This Privacy Policy explains, in plain language, what personal information we collect, why we collect it, how it is used and shared, and the rights you have over it. It is written to comply with Canada's PIPEDA, Quebec's Law 25 (the Act respecting the protection of personal information in the private sector, as amended), California's CCPA/CPRA, and the U.S. federal COPPA.

The short version: We collect your school email for sign-in. The setup choices needed to restore your account, including selected app identifiers, time windows, daily limits, and override mode, are stored in our backend. On Android, a selected identifier is the app's package name. Apple's app-selection tokens stay on the device. If you allow notifications, we store an Expo push token and a random installation identifier so we can deliver Friend Control and account notices. Usage samples, focus history, and block-attempt counters stay on your device. We do not show ads, sell personal information, run analytics, or track you across other apps for advertising.

1. Who We Are & Privacy Officer

The data controller is the developer of Student Focus, based in Quebec, Canada.

Under Quebec Law 25 we are required to designate a person responsible for the protection of personal information. That person is:

You can use this address for any privacy-related request, complaint, or question.

2. What Personal Information We Collect

We collect only what is needed for the Service to work. Categories (CCPA §1798.110 framing):

CategoryExamplesWhere it lives
IdentifiersYour school email addressSupabase (US) + your device
Authentication stateSession tokenEncrypted secure storage on your device
Android app and usage informationPackage identifiers and display labels for launchable apps, package identifiers selected for blocking, recent foreground-usage totals, and package identifiers reported in window-change events after you grant the relevant permissions. The Accessibility Service is configured not to retrieve window content.Processed on your device. Selected package identifiers and their configured limits and schedules are also stored in Supabase for account restoration. App labels and usage totals are not uploaded.
iOS app-selection informationOpaque application, category, or web-domain tokens returned by Apple's Family Activity PickerNative storage on your device and its app extension. The tokens and selected app names are not available to our server. A generic selection marker may be stored with your server setup.
Setup preferencesSelected app identifiers, daily limits, time windows, override method, enforcement mode, and setup-completion timeSupabase (US) and your device, so supported setup choices can be restored after sign-in
Friend Control pairing dataA SHA-256 hash of a random 10-character invite code, the Supabase user IDs of the two participants, and creation, approval, revocation, and expiry timestamps. The raw invite code is sent over HTTPS to server functions for registration or matching but is not stored in the database.Supabase (US). Raw invite codes you generate or accept are kept in encrypted secure storage on the participating devices.
Notification delivery informationAn Expo push token, a random per-installation identifier, platform, Expo project identifier, app version, notification event type, delivery status, and limited provider error details. Friend Control events may reference the related pairing and participating account IDs.Supabase (US), Expo's push service, and the operating-system push service after you allow notifications. A cached copy of your token and installation identifier is kept in encrypted secure storage on your device.
Local activity and safety stateFocus sessions, daily focus totals, any locally retained usage baseline, block-attempt counters, override grace time, and failed Friend Control code lockout stateYour device only

3. Sources of Information

The age entered during onboarding is used in memory for the eligibility check and is not stored in your profile or uploaded.

4. Why We Collect It (Purposes & Legal Bases)

DataPurposeLegal basis
School emailVerify your identity, create your account, sign you back inNecessary to perform our contract with you
Setup preferencesRestore supported setup choices after sign-in and configure blockingNecessary to perform our contract with you
Android app and usage informationPopulate the on-device app picker, show an onboarding usage comparison, and enforce the limits and schedules you setYour explicit OS-level permission and our legitimate interest in delivering the feature
iOS app-selection tokensApply Apple's shields and activity schedules to the apps or categories you selectYour explicit OS-level authorization and our legitimate interest in delivering the feature
Friend Control pairing dataRequire explicit approval, validate current access, revoke access, enforce expiry, and limit repeated invite-claim attemptsYour choice to enable the feature and our legitimate interest in preventing unauthorized overrides
Notification delivery informationDeliver the Friend Control and account updates you choose to receive, prevent duplicate sends, rate-limit abuse, and troubleshoot delivery failuresYour notification permission and our legitimate interest in reliable, secure delivery

If you ever gave consent that you want to withdraw, email the Privacy Officer. Withdrawing consent will end your ability to use parts of the Service that depend on that data.

5. Who Else Sees Your Data (Third-Party Service Providers)

Student Focus relies on the following third-party services. Each receives only what is necessary for its narrow job:

ServiceWhat it receivesWhere it processes
SupabaseYour email, authentication records, session handling, setup profile, selected Android package identifiers or generic iOS selection marker, configured limits and schedules, Friend Control rows, and notification registration and delivery records. Friend Control server functions receive raw invite codes over HTTPS to hash or compare them, but the database stores only the hash. Usage totals, focus history, block-attempt counters, Apple selection tokens, and Android app labels are not uploaded.United States. See privacy policy
ExpoUsed for the app's build toolchain, notification library, and push-delivery service. Over-the-air updates are disabled in this version. After you allow notifications, Expo receives an Expo push token and the fixed notification content and routing data needed to deliver relevant Friend Control or account notices.United States. privacy policy
Apple Push Notification service or Firebase Cloud MessagingThe operating-system notification service receives the delivery token and notification content needed to show a notification on your iOS or Android device.Handled under Apple's privacy policy or Google's privacy policy, depending on your device.

We do not work with any analytics SDKs, trackers, or advertising networks, and the App contains no advertising SDK. The Self Control override includes a fixed waiting period before a block can be lifted; this is a timer only, not an advertisement.

6. What We Do Not Do

7. Cross-Border Transfer of Personal Information

Supabase and Expo operate in the United States. Supabase processes the account, setup, and notification-delivery information listed above, while Expo processes build and push-delivery data. Apple or Google may process push delivery for the operating system. School-email eligibility is checked against a domain list bundled into the App, so that check does not make a separate request to a public list provider.

Under Quebec Law 25 §17, we assess cross-border handling of personal information, including:

Using account features involves the cross-border processing described above.

8. Your Rights. Canada & Quebec

If you live in Canada, including Quebec, you have these rights:

We will respond within 30 days of receiving a verified request.

9. Your Rights. California (CCPA / CPRA)

If you live in California you have:

To exercise any of these rights, email livefonam@gmail.com. We will verify your request (typically by confirming control of the email on file) and respond within 45 days as required by CCPA. An authorized agent may submit a request on your behalf with your written permission.

10. Data Retention

11. Children (COPPA & Quebec Law 25 §14)

Student Focus is intended for students aged 13 or older with a valid school email. Onboarding asks for age to enforce that threshold, but the entered age is not stored or uploaded. We do not collect a date of birth. If we learn that an account belongs to a child under 13, we will delete it. Quebec residents aged 14 to 17 may provide consent on their own behalf where Quebec law permits.

We do not knowingly collect personal information from anyone under 13. If you are a parent or guardian and you believe your child under 13 has created an account, please email us and we will delete it.

12. Security

We take security seriously, but no system is perfect.

If a security incident presents a risk that requires notification, we will notify the Commission d'accès à l'information du Québec and affected people as required by applicable law.

13. iOS Screen Time & Android Usage Access

The two platforms provide different information and enforcement tools. Student Focus uses them only after you grant the relevant operating-system permission:

Apple selection tokens, Android app labels, raw usage totals, focus history, and block-attempt counters stay on the device. Selected Android package identifiers and configured limits or schedules are stored with your server setup as described above.

14. Friend Control (Optional Feature)

If you enable Friend Control, you can ask one trusted friend to be your accountability partner. When you do:

Friend Control is optional. Self Control uses a 10-second hold and a 2-minute in-app waiting period. Completing either authorized path grants a 45-minute local override grace period. Friend-granted grace is revalidated against the server and fails closed if approval cannot be confirmed.

15. Push Notifications

If you allow notifications, the App requests an Expo push token and stores it in Supabase with a random installation identifier, platform, Expo project identifier, and app version. We use it for fixed Friend Control and account notices; the sender does not accept arbitrary titles, messages, or recipients from the client. Delivery events and limited provider responses are recorded to prevent duplicate sends, enforce rate limits, and diagnose failures. The App may also schedule a local iOS "Focus session complete" reminder. You can revoke notification permission in device settings. On sign-out or account deletion the App attempts to unregister the current token, and deleting the account removes server rows linked to that account.

16. Account Deletion

You may delete your account and all associated data at any time:

Account deletion is irreversible. Operating-system permission choices are controlled in iOS or Android Settings and may need to be revoked there separately. Supabase may retain provider security and authentication logs under its own retention policy.

17. Changes to This Policy

We may update this Policy from time to time. When we do, we will update the "Last updated" date at the top and provide any additional notice required by applicable law.

18. Contact

Questions, complaints, or requests about your data: livefonam@gmail.com

Back