App and website

Privacy Policy

This policy explains in clear terms which data is processed when you use iFocus Plus and this website.

1. Controller

Dominik Crnkovic
Zikadenweg 12 A
70439 Stuttgart
Germany
Email: support@ifocusplus.app

2. iFocus Plus privacy principles

iFocus Plus does not use advertising tracking, tracking identifiers, or a separate user account. The app does not include analytics or advertising services. Tasks, notes, appointments, settings, focus data, and attachments are generally processed locally on your device.

3. iCloud and CloudKit sync

When iCloud is available on your device, iFocus Plus can sync content between your own Apple devices through the private CloudKit database associated with your Apple ID. The provider of iFocus Plus does not operate a separate content server for this purpose and cannot access your private CloudKit database. Apple processes data according to your Apple ID settings and Apple’s privacy terms.

Your content remains available locally when no iCloud connection is available. You can manually start a local export and later restore that export within the app.

4. Device permissions

Features such as Calendar, Reminders, Photos, Camera, and Notifications are used only after you grant permission. You can change permissions at any time in system settings. Calendar and reminder content is processed inside the app for the selected display or editing function and is not transferred to a server operated by iFocus Plus.

5. App Store and purchases

Apple handles downloads, purchases, and payments under its own responsibility and terms. iFocus Plus does not receive users’ complete payment details.

6. Website hosting

This website is hosted by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. When you access the site, the hosting service processes technically necessary access information, including the requested file, time, referrer, browser, operating system, device type, and an immediately anonymized IP address. This information is processed to provide the website securely and reliably and, according to IONOS, is retained for eight weeks. The legal basis is Article 6(1)(f) GDPR.

IONOS WebAnalytics for web hosting operates without cookies. IP addresses are anonymized immediately and evaluated statistically without a personal reference. This website does not add any other analytics, advertising, or tracking services.

7. HTTPS redirects through Cloudflare

The additional domains ifocusplus.de and ifocusplus.com are encrypted and redirected to the primary domain ifocusplus.app using services from Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare processes technically necessary connection information, particularly the IP address and details about the requested domain, URL, time, and browser, to establish the HTTPS connection, perform the redirect, and protect against abusive requests.

The legal basis is Article 6(1)(f) GDPR. The legitimate interest is the secure, stable, and encrypted availability of the brand domains. Cloudflare’s Data Processing Addendum and its Standard Contractual Clauses apply to possible transfers to the United States. Cloudflare Web Analytics, Turnstile, interactive challenges, and Under Attack Mode are not enabled on the redirect domains.

8. Cookies and local appearance preference

The public website uses no analytics, advertising, or tracking cookies. If you switch between light and dark appearance in the header, your browser stores only that selection locally on your device. It contains no unique identifier and is not transmitted to us or third parties.

After successful sign-in, the separate, non-public Community administration area sets one strictly necessary random session cookie. It is used only for authentication, access control, and request-forgery protection; it is protected with Secure, HttpOnly, and SameSite=Strict and expires after no more than eight hours or 30 minutes of inactivity. The legal bases are Section 25(2)(2) TDDDG and Article 6(1)(f) GDPR.

9. Contact form and E-Mail

The contact form sends the information you enter through a first-party endpoint on this domain to . This includes the sender address, subject, category, message, and any technical details you choose to provide. To limit automated abuse, a non-reversible value derived from the IP address is stored briefly and no longer considered after 15 minutes. Message contents are not stored in a website database for this purpose.

If direct delivery is technically unavailable, the website opens your local mail app with a prepared message instead. In that case, the message is sent only after you confirm it there. Depending on the request, the legal basis is Article 6(1)(b) or Article 6(1)(f) GDPR. Requests are deleted when no longer required and no statutory retention duty applies.

10. Protected Community staging

The public Community page remains a read-only, clearly labeled preview. A separate server-protected staging area is available only to the owner and authorized administrators. It provides no self-registration and no public access to staging content.

The staging MariaDB on IONOS web hosting processes data including email address, display name, role, account status, password hash, encrypted authenticator secret, accepted document versions, sessions, test posts, reactions, reports, moderation decisions, reviews, and a tamper-evident chained audit log. A keyed HMAC derived from an IP address may be used briefly for login protection; the raw IP is not stored for that purpose in the Community database. Passwords and invitation or session tokens are never stored in plaintext.

Depending on the operation, the legal bases are Article 6(1)(b), (c), or (f) GDPR. Sessions expire after no more than eight hours, failed-login buckets are removed after no more than two days, and invitations normally expire after 24 hours. Test content, reports, decisions, and audit records are retained only as long as required for staging validation, security, evidence, or statutory duties; a binding deletion and backup schedule will receive final review before an invite-only public beta.

11. Your rights

Subject to the GDPR, data subjects have rights including access, rectification, erasure, restriction of processing, data portability, and objection. Consent can be withdrawn with effect for the future. Requests can be sent to support@ifocusplus.app.

You also have the right to lodge a complaint with a data protection supervisory authority.

12. Authoritative version and effective date

This English translation is provided for convenience. In case of discrepancies, the German Privacy Policy is authoritative.

Effective date: 23 August 2026.