Privacy Policy
Last updated: September 14, 2026
Hima focus (“the App”) is a personal digital-wellbeing app that helps you consciously reduce time spent in distracting apps. This policy explains what information the App processes, why, on what legal basis, who else sees it, how long it is kept and what you can ask us to do about it. Our core principle is simple: your Screen Time data stays on your device — it never reaches our servers.
1. Who is responsible for your data
Hima focus is made by Artem Nikitin, an independent developer. For the purposes of the EU and UK General Data Protection Regulation, he is the data controller for the processing described here.
Contact for any privacy question, including every request described in Section 11: support@himafocus.com. A person reads that address, and we answer within 30 days as the GDPR requires.
2. Screen Time data
The App uses Apple's Screen Time API (the FamilyControls, ManagedSettings, and DeviceActivity frameworks) with individual authorization, meaning you manage only your own device. The App is not a parental-control or device-management product.
When you choose which apps to be more mindful about, iOS provides the App only with opaque, privacy-preserving tokens — not the names of those apps, and not their contents. We use these tokens solely to apply and remove a Screen Time shield and to schedule sessions, limits, and quiet hours that you set up yourself.
All Screen Time data and app tokens remain on your device. We do not transmit this data off your device, we do not store it on any server, we do not use it for advertising or analytics, and we never sell or share it with any third party.
3. Information stored on your device
Your settings — selected apps, limits, schedules, focus sessions, and personal preferences — are stored locally on your device. We do not have access to this information, and it does not currently sync via iCloud or any other service.
4. What the App sends to our server
The App does not require you to create an account, sign in, or provide your name, email, or phone number to use it. On first launch it generates a random identifier that isn't linked to your name, email or phone, and that you can delete. It is stored in your device's Keychain, and it is what our server uses to keep track of your subscription.
We call it random rather than anonymous on purpose. Because it stays the same on your device until you delete it, data protection law treats it as personal data, and it is covered by all the rights in Section 11. What it is not is a link to your identity: we cannot turn it into a name, an email address or a phone number, because we never had one.
Alongside that identifier, our server holds:
- Your subscription status — plan, whether a trial is running, start and expiry dates.
- Basic technical facts about the install — platform, app version, and when the App last contacted the server.
- Product-usage events — for example, which onboarding step you reached or that a focus session started. These never include the names or content of the apps you limit with Screen Time.
- A push identifier — only if you turn notifications on, so that reminders you asked for can arrive.
- Payment records — amount, currency, product and the transaction reference Apple gives us. We never receive your card details.
Two more things exist, and neither is part of that record.
- An abuse counter tied to your IP address. To stop someone scripting thousands of registrations, or flooding the support form, our server keeps a counter against the IP address your device connects from. It sits in a rate-limiting table of its own: it is not joined to your identifier, it says nothing about what you do in the App, and we do not use it to identify you. It is the one place an IP address reaches our database, and Section 9 says how long it stays.
- What you send us through the support form. Your message, the email address you give us so we can reply, and a screenshot if you attach one. This goes straight to our support mailbox as an email — it is never written to our database. Giving an email address is your choice; without one we have no way to answer you.
We do not build advertising or behavioural profiles of you.
5. Why we process it, and on what legal basis
Under Article 6 of the GDPR every purpose needs a legal basis. Ours are:
- Running the App and keeping your subscription working — the identifier, subscription status and install facts. Basis: performance of a contract (Art. 6(1)(b)). Without this the App cannot tell whether Premium is active, so this part is not optional.
- Notifications you asked for — the push identifier. Basis: your consent (Art. 6(1)(a)), given when you allow notifications. Turn notifications off in iOS Settings at any time and the basis ends with them; that does not affect anything processed before.
- Understanding how the App is used, to improve it — product-usage events. Basis: our legitimate interest (Art. 6(1)(f)) in knowing which parts of the App work and which do not. You can object to this at any time — see Section 11.
- Answering you when you write to support — whatever you put in your message. Basis: legitimate interest (Art. 6(1)(f)) in replying to you.
- Keeping payment records — Basis: legal obligation (Art. 6(1)(c)). Accounting and tax rules require these to be kept, which is why they outlive a deleted profile (Section 9).
We do not make any decision about you by automated means, and we do not profile you within the meaning of Article 22.
6. Purchases
Any subscription or purchase is processed by Apple through the App Store, using RevenueCat as our subscription-management provider. We do not receive or store your payment details (card numbers, billing address). Apple's and RevenueCat's handling of that information is governed by their own privacy policies.
7. Who else processes data for us
We use a small number of service providers. They act on our instructions as processors, they may not use your data for their own purposes, and each one is bound by a data-processing agreement that forms part of the terms we accepted when we signed up.
- Supabase — our database and backend. Hosted in the European Union.
- RevenueCat — subscription management (United States).
- OneSignal — delivery of the notifications you opt into (United States).
- Resend — delivery of email you send us through the support form (United States).
- Cloudflare — hosting for himafocus.com and routing for our support address.
- Apple — payment processing and App Store delivery. Apple is an independent controller for what it collects, not our processor.
We do not sell your data, we do not share it with data brokers, and we do not pass it to advertising networks. We do not track you across other apps or websites. There are no third-party advertising or tracking SDKs in the App, and we never collect your browsing history or the contents of what you do inside other apps.
8. Where your data is processed
Our database is hosted in the European Union. Some of the providers listed in Section 7 are based in the United States, so for those specific purposes a transfer outside the EEA and the UK takes place. Those transfers rely on the European Commission's Standard Contractual Clauses — with the UK Addendum where the UK GDPR applies — which form part of each provider's data-processing agreement. Write to support@himafocus.com and we will tell you which safeguard covers which provider, or send you a copy.
9. How long we keep it
- While you use the App — your identifier, subscription status, install facts and usage events are kept for as long as the App is installed and in use.
- When you delete the record (Section 10) — your device records, push identifier and usage events are deleted straight away.
- A marker is kept for six months after that deletion. It holds no personal detail beyond the fact that this device once registered, and it exists for one reason: without it, deleting and reinstalling would hand out an unlimited series of free trials. After six months it is purged automatically, by a job that runs daily.
- Payment records are kept longer, for as long as accounting and tax law requires. This is the legal obligation named in Section 5, and it is why a profile that has payments against it is not erased outright — the link to your device is removed instead.
- The abuse counter from Section 4 counts within a one-hour window. The row that holds it is not on an automatic timer today, so an IP address can remain in that table after the window has passed. It is not linked to you or to your profile, and you can ask us to delete yours at any time.
- Support email stays in our mailbox for as long as it is useful to have the history of your request, and you can ask us to delete it — including any screenshot you attached.
10. Deleting the record we hold
Open Settings → Delete Account in the App. There is no login behind that name — what it deletes is the record described in Section 4: the random identifier, your subscription status, your device records and your push identifier. Section 9 explains exactly what is removed at once and what is kept.
Deleting it does not cancel an active Apple subscription — manage or cancel that separately in your Apple Account settings. Your local settings, limits and history remain on your device and go with the App if you delete it.
11. Your rights
If the GDPR or the UK GDPR applies to you, you have the right to:
- Access the data we hold about you, and get a copy of it.
- Correct anything inaccurate.
- Erase it — the Delete Account button in Section 10 does this for you without having to ask, and you can also write to us.
- Restrict or object to our processing, including the product-usage events we rely on legitimate interest for.
- Portability — receive the data you gave us in a machine-readable format.
- Withdraw consent for notifications at any time, by turning them off in iOS Settings.
Write to support@himafocus.com to use any of these. One practical note, and it is in your favour as well as ours: since we hold no name or email, the only thing that connects you to your record is the identifier on your device. To act on an access, correction or portability request we will need it, and the App can show it to you. If you have already deleted the record, there is nothing left for us to look up.
The abuse counter in Section 4 is the one thing we can look up without your identifier, from the IP address you write to us from. Ask and we will delete it.
We do not charge for any of this, and we will not make you justify the request.
12. Children
The App is intended for personal self-management and is not directed at children. It is not a parental-control product and does not knowingly collect personal information from children.
13. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above, and where the change matters we will say so in the App.
14. Contact, and how to complain
Any question about this policy: support@himafocus.com.
If you think we have handled your data badly, please tell us first — it is usually the fastest way to fix it. You also have the right to complain to a data protection authority without going through us: in the EU, the supervisory authority of the country where you live, work, or where you think the problem happened (the list is at edpb.europa.eu); in the UK, the Information Commissioner's Office at ico.org.uk.