Privacy Policy

Last updated: February 27, 2026

Tobydoro does not collect, transmit, or share any of your data. All information stays on your device. There are no servers, no analytics, no tracking, and no third-party access. Your privacy is guaranteed by design.

1. Data Stored on Your Device

Tobydoro stores the following data locally on your device using Apple's on-device storage technologies (SwiftData and UserDefaults):

  • Flow sessions: start and end times, duration, and completion status
  • Tasks and projects: names, notes, and organization data
  • Tags: labels you create to categorize your work
  • Journal entries: personal reflections you write after sessions
  • Mood and energy ratings: numeric ratings (1-5) you provide before sessions
  • Distraction counts: the number of distractions you log during sessions
  • Session reflections: notes on session quality and break activity choices
  • App preferences: your chosen settings such as break ratios and quiet hours

All of this data is created and stored on your device. The developer does not have access to it.

2. No Data Collection or Transmission

Tobydoro does not operate its own servers and contains no analytics SDKs, crash reporting tools, advertising frameworks, or third-party code that transmits your data. There are no user accounts or logins. The app makes zero network calls to developer-controlled infrastructure.

Under Apple's App Store privacy definitions, data that is processed only on-device and never sent to a server is not considered "collected." Tobydoro qualifies for "Data Not Collected" across all privacy categories.

3. iCloud Sync (Optional)

If you enable iCloud sync on your device, your Tobydoro data may sync to your personal iCloud account for backup and multi-device access. This synchronization is:

  • Handled entirely by Apple's CloudKit framework
  • Governed by Apple's Privacy Policy
  • Stored in your personal iCloud account only
  • Not accessible to the developer of Tobydoro

You can disable iCloud sync at any time in your device's Settings under iCloud.

4. No Third-Party Access

No third parties have access to any of your data. Tobydoro does not share, sell, or transmit your information to any external party. We do not sell or share personal information as defined by the California Consumer Privacy Act (CCPA/CPRA).

5. No Tracking

Tobydoro does not track you across other apps or websites. The app does not use device identifiers, advertising identifiers (IDFA), fingerprinting, or any form of cross-app tracking. There are no cookies or web beacons.

6. Data Security

Your data is protected by Apple's built-in device security, including:

  • On-device encryption (Data Protection) when your device is locked
  • Secure Enclave for biometric authentication (Face ID / Touch ID)
  • App sandboxing that prevents other apps from accessing Tobydoro's data

If iCloud sync is enabled, data in transit and at rest in iCloud is encrypted by Apple.

7. Deleting Your Data

You can delete all data stored by Tobydoro in two ways:

  • Use the "Delete All Data" option in the app's Settings screen. This removes all sessions, tasks, tags, projects, journal entries, and resets all preferences.
  • Delete the Tobydoro app from your device, which removes all associated local data.

If iCloud sync was enabled, you may also need to delete the data from iCloud via Settings > Apple ID > iCloud > Manage Storage.

8. Health and Wellbeing Disclaimer

Tobydoro is a general wellness and productivity tool. It tracks work patterns and suggests breaks based on time-based rules. It is not a medical device, does not provide medical advice, and is not intended to diagnose, treat, cure, or prevent any disease or medical condition.

If you have concerns about your mental or physical health, please consult a qualified healthcare professional.

9. Your Rights by Jurisdiction

European Union / EEA (GDPR)

Since Tobydoro processes data exclusively on your device, the developer does not act as a data controller for your personal data in the traditional sense. However, in the spirit of transparency and GDPR compliance, we provide the following information:

Data controller: Mike Pulgar Olguin, individual developer, based in Spain.

Legal basis: Legitimate interest (app functionality). No personal data is transmitted to or processed by the developer.

Your rights under GDPR:

Right of access to your data (exercised directly on your device)
Right to rectification (edit your data within the app)
Right to erasure ("Delete All Data" in Settings)
Right to data portability
Right to object to processing
Right to restriction of processing

To exercise any right, contact: mpulgar.olguin@gmail.com

Supervisory authority: You have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan, 6, 28001 Madrid, Spain.

International transfers: No personal data is transferred outside your device. If iCloud sync is enabled, Apple manages transfers under its own Standard Contractual Clauses (SCCs).

Data retention: Data is retained on your device for as long as the app is installed. Deletion is immediate when you use "Delete All Data" or uninstall the app.

United Kingdom (UK GDPR)

UK residents have the same rights as listed above under GDPR. The relevant supervisory authority is the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, SK9 5AF, United Kingdom.

California, USA (CCPA/CPRA)

Under the California Consumer Privacy Act:

  • We do not sell personal information.
  • We do not share personal information for cross-context behavioral advertising.
  • We do not use or disclose sensitive personal information for purposes beyond those authorized by the CCPA.
  • Categories of personal information collected: None.

California residents have the right to know, delete, and opt-out of the sale of personal information. Since we collect no data, these rights are inherently fulfilled.

Brazil (LGPD)

Brazilian residents have rights to confirmation, access, correction, anonymization, deletion, and portability of personal data. Since no personal data is collected or processed by the developer, these rights are inherently fulfilled. Legal basis: consent (acceptance of terms by using the app).

Canada (PIPEDA)

Canadian residents are protected under the Personal Information Protection and Electronic Documents Act. Tobydoro complies with PIPEDA's fair information principles: no personal information is collected, and the purpose of on-device data storage is solely for app functionality.

South Africa (POPIA)

South African residents may contact the Information Regulator for privacy concerns. No personal information is processed by the developer.

Japan (APPI)

No personal information is acquired, used, or provided to third parties by the developer. All data processing occurs exclusively on the user's device.

10. Children's Privacy

Tobydoro is not directed at children under 13 (COPPA) or under 16 (GDPR Article 8). The app does not knowingly collect personal information from anyone, including children. Since all data remains on-device and is never transmitted, there are no age-related data concerns.

11. Changes to This Policy

If this privacy policy is updated, the revised version will be published at this URL and included in a future app update. The "Last updated" date at the top will reflect the change. Continued use of the app after changes constitutes acceptance of the updated policy.

12. Contact

If you have questions about this privacy policy or wish to exercise your data rights:

Developer: Mike Pulgar Olguin (individual developer), Spain.