Privacy Policy
Last updated: 2026-06-13
This Privacy Policy explains how FitDevotion ("we", "us") collects, uses and protects your personal data when you use the Pomodoro app at pomodoro.fitdevotion.com. The processing complies with the EU General Data Protection Regulation (GDPR) and the Brazilian Lei Geral de Proteção de Dados (LGPD).
1. Data Controller
FitDevotion. Contact: [email protected]. Country of incorporation: Brazil. Service primarily directed to users in Portugal (EU).
2. Personal Data We Collect
- Google account profile (when you sign in): name, email address, profile photo URL, Google user ID (uid).
- App usage data: tasks you create, projects, Kanban columns, project descriptions and links you add, focus sessions, daily summary aggregates, application preferences (theme, language, active task).
- Technical data: browser type, device type, IP address (transient, only as needed to deliver the service via Firebase/Google).
- Analytics (only if you accept cookies): aggregated, pseudonymous usage events via Google Tag Manager (GTM-52B7T6WX).
3. Purposes and Legal Bases (GDPR Art. 6)
- To provide the service (account, sync, persistence): performance of a contract (Art. 6(1)(b)).
- To remember your preferences (theme, language, active task): legitimate interest (Art. 6(1)(f)) and contract performance.
- To measure usage and improve the product (analytics): your consent (Art. 6(1)(a)), which you can withdraw at any time via the consent banner or your browser settings.
4. Cookies and Google Consent Mode v2
We use a strictly necessary cookie to remember your consent choice. With your consent, we additionally enable analytics cookies. We implement Google Consent Mode v2 with the following signals, all defaulted to denied until you choose:
analytics_storage— measurement of how the app is used.ad_storage— advertising-related cookies. We do not currently run advertising; signal kept denied by default.ad_user_data,ad_personalization— defaulted to denied.
You can revisit your choice at any time by clearing the fd_consent cookie via your browser settings.
5. Storage and International Transfers
Data is processed and stored on Google Cloud Platform (Firebase, region europe-west1). Servers are located in the European Union (Belgium). Google may transfer aggregated technical data to the United States; these transfers are governed by the EU-US Data Privacy Framework and Standard Contractual Clauses.
6. Retention
Account data is kept while your account is active. When you delete your account (in-app or via /delete-account), all your personal data is removed from our active databases within 30 days. Aggregated analytics events that cannot be tied back to you may be retained.
7. Your Rights
Under GDPR (Arts. 15-22) and LGPD (Arts. 17-18) you have the right to access, rectify, erase, restrict processing, port and object. To exercise these rights:
- Access and portability: use Settings → Account → Export my data (JSON).
- Erasure ("right to be forgotten"): use Settings → Account → Delete account, or the public form at /delete-account.
- Any other right: email us at [email protected].
You also have the right to lodge a complaint with a supervisory authority (Comissão Nacional de Proteção de Dados in Portugal, ANPD in Brazil).
8. Children
The service is not directed at children under 16. We do not knowingly collect data from children.
9. Changes
We will post any changes to this policy on this page and update the "Last updated" date.
10. Contact
Questions about this Policy: [email protected].