Grab Back to School Deals
Up to €40 OFF + FREE 3-month App Pro

Privacy Policy

Makeblock Europe B.V. values your privacy. This Privacy Policy (the “Policy”) explains how we collect, use, share, and protect your Personal Data when you use our (i) websites, (ii) devices (“Devices”), (iii) mobile or desktop software (“Applications”), (iv) use our AI-powered voice assistant and chatbot services through the Device or third-party messaging platforms such as Telegram, WhatsApp, and Feishu/Lark (“AI Service”), or (v) any other products, programs, or services we provide (together with “Site”, “Device”, “Application”, and “AI Service”, the “Service”). New or additional features we launch are covered by this Policy unless we provide a separate notice.
Your Personal Data may be processed in the countries/regions where you use the Service and where we, our affiliates, or service providers operate, subject to Applicable Law. Where this involves a transfer of Personal Data outside the EEA, the UK or Switzerland, we apply the safeguards described in Section 8. References to “we”, “us” or “our” mean “Makeblock Europe B.V.”. “You” means any individual whose Personal Data we process.

1. INTRODUCTION AND SCOPE
This Policy describes: (a) what we collect, (b) how we use it, (c) how we share it, and (d) your rights and choices (including under the EU GDPR, the UK GDPR and the Swiss FADP; see Section 14). It does not cover anonymous, aggregated, or de-identified data unless it is linked back to you.

2. WHO WE ARE & DATA RESPONSIBILITY
We act as the “Controller” of your Personal Data (the entity that decides how and why your data is used). Makeblock Europe B.V. (Westplein 12, 3016 BM, Rotterdam, the Netherlands is the controller responsible for processing your Personal Data in connection with the Service and the online store, unless we provide a separate notice stating otherwise.
Key Partners & Operational Modes
To provide our service effectively, we may rely on established third parties. Specifically note the following data relationships:
· Platform Provider (Shopify): We utilize Shopify to manage our storefront and related operations. By shopping or interacting with us, your data is processed through Shopify’s systems in accordance with Shopify’s Privacy Policy and industry security standards.
· Cloud Infrastructure Provider: We utilize cloud hosting services (including Microsoft Azure) to host our servers and store data. Our AI Service communicates with third-party AI service providers for speech recognition, language processing, and text-to-speech functionality. Details of these providers are set out in Section 8.

3. HOW TO CONTACT US
Your feedback and resolving complaints efficiently are important to us. If you have questions about your data rights:
· Email: hello@focusaur.com
· Data Controller: Makeblock Europe B.V.
· Registered Office: Westplein 12, 3016 BM, Rotterdam, the Netherlands

4. PERSONAL DATA WE COLLECT
We collect only what we need to provide and improve the Service. We do not require, and do not intentionally collect for the purpose of inferring your health, special-category health data, biometric identifiers (e.g., fingerprints, facial templates, or voiceprints), behavioral-biometric identifiers, neural or brain-activity data, or financial account credentials as part of our standard Services, and we do not collect precise geolocation unless you enable a feature that requires it.
Health-related context you choose to provide. Because the Service lets you freely name and define your own habits, tags, goals, and notes, you may choose to enter information that could reveal health-related context (for example, a habit you name “weight loss” or “rehabilitation training”). Any such information is provided at your own initiative and under your control; where you choose to provide it, you consent to our processing it solely to deliver the features you request. Our AI insights and reports use this information only in aggregate, analytical form to summarize your focus and habit patterns. They do not generate medical, psychological, or health diagnoses, do not provide medical or treatment advice, and are not designed to deliver negative or evaluative judgments about you. You can edit or delete these entries at any time.
If we otherwise need sensitive data for a specific feature or to meet legal obligations, we will provide additional notice and, where required, obtain your consent, and use it only for that purpose.
Categories :
· Identity Data: name/preferred name; usernames/display names; user ID; avatar/profile image (if provided); and, where required by law or for certain transactions, government-issued identifiers.
· Contact Data: mailing address, email, phone, billing address.
· Credentials & Settings: login credentials/tokens; account preferences and settings. Passwords are stored in hashed form.
· Financial & Services Data: purchase, payment method type, transaction history, returns, warranty claims, subscription status and plan type (e.g., monthly or annual Pro), renewal and expiration dates, in-app purchase receipts and transaction identifiers, and AI credit balances. Payments are processed by third-party payment providers (we generally do not store full card numbers). In-app purchases on iOS and Android (including Pro Subscriptions and AI Credit Packs) are processed by Apple App Store and Google Play, respectively, in accordance with their own terms and privacy policies.
· Device & Content Data : device identifiers (e.g., serial number), firmware/app versions, crash/error logs; mobile-device motion-sensor readings (e.g., accelerometer, gyroscope) processed primarily on-device to detect movement during App-side Deep Focus sessions; aggregate detection outcomes (e.g., whether a focus session ended due to detected movement) may be transmitted to our servers for session integrity verification and analytics; content you create/upload or that is generated/uploaded from your Device when you use enabled features (e.g., feature-generated photos, files, or diagnostic artifacts). This category also includes NFC tag identifiers and any user-defined NFC tag content you choose to associate with a habit, used solely to enable physical habit check-ins.
· Voice and Audio Data: audio recordings of your voice captured through the Device’s microphone during voice interaction sessions with our AI Service. This data is processed in real-time for speech-to-text conversion. By default, Audio data is processed in real-time in memory and is not written to persistent storage by default. Temporary audio buffers are discarded after speech recognition processing is complete. Audio recordings are transmitted to third-party speech recognition providers for transcription.
· Usage Data: pages/features used, time spent, interaction logs, referrers, and (where enabled) usage metadata for features such as chat and local networking (including Wi-Fi).
· Technical Identifiers: IP address (approximate location), browser/device details, time zone, server/request logs.
· Profile Data: profile fields you choose to share (e.g., bio/interests).
· Marketing & Communications Data: marketing preferences and related interactions.
· Sensitive Personal Data: Certain data may be considered sensitive under some laws (e.g., account credentials and, where enabled, precise geolocation). We use or disclose such data only as permitted by Applicable Law and as described in this Policy.
· Screen Time and App Usage Data (iOS and Android, optional): If you opt in, the Application reads which app is in the foreground only while a Focus Session is active, in order to deliver gentle on-device interruption reminders. On iOS this uses Apple’s Family Controls / Device Activity APIs (showing aggregated Screen Time statistics inside the Application); on Android this uses the system “Usage Access” permission (PACKAGE_USAGE_STATS) and reads only the foreground package name. We do not enumerate or transmit your installed app inventory, do not store the underlying granular app-usage events on our servers, and do not use this data for advertising, profiling, cross-app tracking, or AI model training. Use of iOS Screen Time data is also subject to Apple’s Family Controls policies. You may disable this monitoring at any time in App Settings.
· Aggregated/de-identified data: may be used for analytics; treated as Personal Data if re-linked to you.
· Calendar, Reminders, and Third-Party Account Data: If you connect Google Calendar or Microsoft Outlook, we collect and store OAuth tokens, your third-party account name, and calendar event data (titles, descriptions, times, recurrence rules); these tokens are used to read and write events on your behalf until you disconnect. For Apple Calendar and the iOS Reminders system, we access events and reminder items stored on your local device through the iOS EventKit framework based solely on the device-level permission you grant — no OAuth token is stored on our servers. You may revoke calendar or reminders permissions at any time in your device or Application settings.
· AI Conversation Data: text transcriptions of your voice interactions. These transcripts exist only transiently in memory during your active session to enable real-time responses and are not persistently stored. (Note: specific facts, preferences, or instructions extracted from these transient transcripts may be stored securely as “AI Memory” associated with your account, so the AI can remember your preferences for future interactions).
· Memory Data: our AI Service may extract, store, and recall personal information from your conversations to provide personalized responses, including your preferences, facts about your life, past events, and behavioral patterns. This information is stored as structured memory records with vector embeddings. You may correct or request deletion of specific memories through voice interaction or by contacting us.
· AI Insights and Reports Data: AI-generated narrative reports (such as weekly, monthly, and annual focus and habit reports), aggregated insights, and recommendations derived from your Behavioral and Productivity Data. These reports are stored on our servers and associated with your account so you can access your report history within the Application; you may delete individual reports at any time, and all reports are removed when your Focusaur account is deleted in accordance with this Policy.
· Behavioral and Productivity Data: habit tracking records (names, check-ins, streaks, completion rates), focus session records (times, duration, deep focus mode), schedule and task management data (titles, status, recurrence rules), and gamification data (virtual currency, achievements, collected items).
· Messaging Platform Data: if you use our chatbot via Telegram, WhatsApp, or Feishu/Lark, we collect your platform user identifier (e.g., Telegram user ID, WhatsApp phone number, or Feishu Open ID), platform display name, and messages you send to our chatbot. We maintain a record linking your messaging platform account with your Focusaur account. Telegram, WhatsApp / Meta, and Feishu / Lark act as independent data controllers for messages sent through their platforms and process your data in accordance with their own privacy policies. We recommend reviewing those policies before using our chatbot via those platforms.

5. CONSEQUENCES OF NOT PROVIDING DATA
Where we need to process specific data either by law or under the terms of a contract (for example, fulfilling a physical shipping order or activating device software), and you fail to provide required fields, we may be unable to accept the order or fully activate features dependent on specific input (for example, warranty activation or verification of ID/serial-number mismatches). If active Services exist and required data is not provided or maintained, we may need to suspend or cancel affected Services where delivery becomes commercially unviable or impossible. We distinguish required (“Mandatory”) information from strictly voluntary (“Recommended only”) information at the point of collection.

6. METHODOLOGY FOR COLLECTION
We collect Personal Data from multiple sources:
A. Direct Interactions (Information you give us): you enter data when creating/registering an account, subscribing to newsletters/alerts, requesting support or troubleshooting, providing feedback, signing agreements, or participating in competitions, surveys, or promotions.
B. Automated Technologies (Information collected via use): browsing and use of the Service generate technical data (for example through cookies, server logs, web beacons, pixels, embedded scripts, and standard mobile SDKs). We may also engage in behavioral tracking via these technologies.
Depending on your browser and device, you may be able to limit certain tracking through browser settings and cookie controls. Please note that “Do Not Track” (DNT) signals are not uniformly interpreted, and our Sites may not respond to all DNT signals. You can control cookies via the methods described in Section 12 and you can opt out of certain targeted advertising/sharing as described in section 13. If you disable cookies, certain features of the Services may not function properly.
C. Data via Third Parties & Public Sources: where permitted by law, we may receive or enrich information from:
· Linked Sign-on partners and providers: our Services may allow you to log in through a third-party social network or authentication service, such as Shopify, Apple, Google, and Facebook. When you use these single sign-on services, we do not receive your login credentials. Instead, we receive authentication tokens and any Personal Data you choose to share through the relevant third-party service (for example, Identity Data, Contact Data, and Profile Data, depending on your settings with that third party).
· Analytics partners: such as Google Analytics and similar tools that provide aggregated reporting.

7. HOW WE USE YOUR PERSONAL DATA: PURPOSES & LEGAL BASES
We use Personal Data in accordance with applicable law. For transparency (including GDPR Article 13 / CCPA obligations), below are the main purposes for which we process Personal Data and the lawful basis we rely on:
A. To Enable Service Functionality & Delivery (Contract Performance): we process Identity Data, Contact Data, Financial Data, and Services Data to fulfill our contract with you, including processing orders, payments, shipments, enabling device usage, and providing core software features.
B. To Manage Relationship, Notifications, and Support (Contract or Legitimate Interests): we process Contact Data and Profile Data to notify you about changes to terms or products (including software updates and bug alerts) and to provide troubleshooting and customer support (including warranty and account issues). Our legitimate interest is in maintaining and servicing our customer relationship and providing effective support.
C. Operations: Security & Business Integrity (Legitimate Interests and sometimes Legal Obligation): we analyze Usage Data and Technical Identifiers to maintain systems, detect and prevent fraud and misuse, investigate violations of terms, and prevent automated traffic that may affect Service performance. Our legitimate interest is in ensuring the security and integrity of our systems and preventing fraud and misuse.
D. Analysis (Growth) Improvement (Legitimate Interests; with privacy controls): we use analytics (often aggregated) to improve features and user experience, including models guiding Service logic, subject to applicable privacy controls and legal requirements. Our legitimate interest is in analysing usage to maintain and improve our Service and the user experience.
E. Marketing & Advertising Recommendations (Consent; or, for messaging to existing customers about our own similar products/services, the soft opt-in permitted under applicable ePrivacy laws): we send newsletters, offers, or product recommendations by electronic means only where you have given prior consent or where the soft opt-in applies. We rely on consent for marketing-related cookies and tracking. You can withdraw consent or object at any time, free of charge, through the unsubscribe link in every marketing email, through cookie controls as described in Section 12, or by contacting us as described in Section 13.
F. Specific App & AI Service Processing Details: In addition to the general business purposes above, our Application and AI devices process specific data categories to deliver core functionalities. The detailed purposes, data categories, and corresponding lawful bases are outlined in the table below:

Processing Purpose

Categories of Personal Data

Lawful Basis for Processing

AI Voice Assistant (ASR, LLM, TTS)

Voice/Audio, AI Conversation, Device Data

Contract Performance

AI Memory Extraction & Personalization

Memory Data, AI Conversation Data

Legitimate Interests (Personalized Services)

Habit Tracking & Check-ins

Behavioral and Productivity Data

Contract Performance

Focus Session Tracking

Behavioral Data, Device Data

Contract Performance

Schedule / Calendar Management & Syncing

Calendar and Third-Party Account Data

Contract Performance; Consent (Third-Party Integration)

Chatbot Services (Telegram / WhatsApp / Feishu)

Messaging Platform Data, AI Conversation Data

Contract Performance

Device Management & Firmware Updates

Device Data

Contract Performance

Push Notifications & Reminders

Device Data (push tokens)

Consent

Analytics, Monitoring & Improvement

Usage Data, Technical Data

Legitimate Interests (Service Improvement)

Crash Reporting

Technical Data, Device Data

Legitimate Interests (Service Reliability)


AI Transparency and Use. AI-generated narrative content (including the weekly, monthly, and annual AI growth reports, AI Bot replies, and AI habit analyses) is clearly labeled as AI-generated within the Application. Your AI Conversation Data, Memory Data, and Behavioral and Productivity Data are used to generate your personalized reports, insights, and responses, and are not used to train third-party foundation models. We do not currently route end-user data through China-based AI providers (such as Doubao, Coze, or StepFun); should this change, we will update this Policy and, where required, obtain your consent. Any future use of your data to train or fine-tune AI models for product improvement will be subject to your prior opt-in consent and a separate notice.

8. WHO WE SHARE WITH
To provide the Service and achieve the purposes described above, we may share Personal Data with authorized parties that need it.
A. Structured Shared Network (Inter-company group transfers): for efficiency, data may flow among affiliated corporate organizations worldwide, including our affiliates in the United States, for joint administrative and operational purposes. Where this involves a transfer of Personal Data outside the EEA/UK, we rely on the transfer mechanisms described under “International Transfers” below, subject to appropriate confidentiality and safeguards.
B. External Processors (Vendors): we use vendors under contractual obligations to protect Personal Data. Categories include:
· Hosted Cloud/IT Platforms: hosting providers and IT tools supporting online store and Service functions (including the Shopify ecosystem).
· Payment & Anti-fraud Processors: checkout facilitators and payment processors (including Shop Pay, Stripe, Affirm, Afterpay, PayPal, Google Pay, Apple App Store In-App Purchase, and Google Play Billing) that process payments in accordance with applicable security standards.
· Supply Chain Logistic Providers: warehouse and courier partners to deliver products, using the minimum contact and address details necessary for delivery.
· Business Tools / Analytics: tools we use to manage communications and to assist us with user analytics (if you have not opted out) (for example, Google Analytics reporting suites and Shopify Analytics, Google Firebase/Crashlytics), subject to applicable law and your settings.
· AI and Machine Learning Service Providers: tools and APIs we use to provide core app functionalities, including text-to-speech, speech recognition, conversational AI responses, and language model inference (for example, Microsoft Azure Cognitive Services, including Azure OpenAI Service).
· Communication & Messaging Platforms: services facilitating our chatbot functions and user communications (for example, Telegram, Meta/WhatsApp Business API, and ByteDance/Feishu).
· Calendar & System Integrations: APIs used to sync or integrate Services with your personal schedules, subject to your device permissions (for example, Google Calendar API, Microsoft Graph API, Apple EventKit). For real-time calendar updates, Google Calendar may push event change notifications directly to our cloud servers via webhooks. Such transfers from Google to our infrastructure (which may be located outside your country of residence) are subject to the safeguards described under “International Transfers” below.
C. Legal / Safety Imperatives: where required by law or necessary to protect rights, safety, and property, data may be disclosed to regulators, governmental tax authorities, law enforcement (valid court orders/warrants), or parties involved in corporate transactions (such as mergers or asset sales). We may disclose Personal Data to enforce or apply our terms (including for billing and collection purposes). If necessary, we may also disclose or exchange information with other companies and organizations for fraud protection and credit risk reduction, and to protect the rights, property, or safety of us, our customers, or others.
Categories of Personal Data disclosed. The categories of Personal Data we may disclose include Identity Data, Contact Data, Financial Data, Services Data, Marketing and Communications Data, Profile Data, Usage Data, Technical Identifiers, Device Data, and Content Data, depending on the nature of the Service and the recipients described above.
International Transfers: because our affiliates and certain service providers are located outside the EEA, the UK and Switzerland, we transfer Personal Data to third countries. For transfers to the United States, we rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise on the European Commission’s Standard Contractual Clauses (“SCCs”) (together with the UK International Data Transfer Addendum and the Swiss addendum, as applicable). For transfers to other third countries, including China, we rely on the SCCs together with a transfer impact assessment and supplementary technical and organizational measures (such as encryption and pseudonymization) where required. You may request a copy of the relevant safeguards by contacting us as set out in Section 3. For transfers made under the EU-US Data Privacy Framework, you also benefit from the redress mechanisms available under that framework, including free independent dispute resolution and, as a last resort, binding arbitration.
Marketing / Ads Opt-outs: sharing with advertising networks (if applicable) typically depends on your cookie choices. See Section 12 for cookie controls and opt-out options.
Google API Services User Data Policy. Focusaur’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

9. DATA SECURITY
We use technical and organizational safeguards designed to protect Personal Data, including:
· Pseudonymisation and encryption: removing direct identifiers from certain internal analysis datasets where appropriate; using encryption and other safeguards to protect Personal Data in transit and at rest.
· Access controls: limiting access to personnel with a legitimate business need, under role-based controls.
· Incident response: procedures to assess and notify relevant authorities and affected individuals where required by law.
· Your responsibility: you are responsible for keeping your account credentials confidential and using strong passwords.Public areas. If the Services include public or interactive areas (for example, forums or message boards), any information you submit there may be viewed by any user and should be treated as public.
Transmission over the internet. The transmission of information via the internet is not completely secure. While we use reasonable safeguards, we cannot guarantee the security of Personal Data transmitted to or through our Services; any transmission is at your own risk.

10. HOW LONG WE KEEP YOUR DATA
Makeblock Europe B.V. retains Personal Data only for the period necessary to provide you with Focusaur term of use and for achieving legitimate and essential business purposes, such as making data-driven business decisions about new features and offerings, complying with legal obligations, or resolving disputes. We apply retention periods across the following key categories:
· Data retained until you request us to remove it: for example, we may retain surveys, research, and promotions data until you withdraw consent or opt-out to honor your preferences and comply with marketing regulations.
· Legal / Admin / Tax laws: sales transactional records (for example invoice history) may be retained for the minimum period required by applicable tax and accounting laws.
· Legal defense windows: we retain necessary records for the duration of applicable statutes of limitations so we can establish, exercise, or defend legal rights if disputes arise.
· Active utility period: certain technical and transient logs (for example crash logs) may be retained for shorter periods and deleted, anonymized, or otherwise securely destroyed when no longer needed, subject to legal requirements.
We will not keep your Personal Data longer than necessary for the purposes stated in this Policy. When it is no longer needed, we will delete it or irreversibly anonymize it unless a longer retention period is required by law. Where we cannot state an exact retention period in advance, we determine it using the criteria described above (in particular the statutory tax and accounting retention periods and the applicable limitation periods). You may request further detail on our retention periods by contacting us as set out in Section 3.

11. YOUR RIGHTS & CONTROLS
Depending on your jurisdiction (for example EU/EEA, UK, or certain U.S. states), you may have rights regarding your Personal Data. We honor applicable rights unless an exception applies. You may have the right to request:
· Access (“Right to Know”)
· Correction / Rectification · Deletion (“Erasure”) (subject to legal exceptions).
· Data Portability (where applicable)
· Restrict or Object to Processing (including direct marketing)
· Withdraw Consent (where we rely on consent)
· Automated decision-making and profiling. Our Service uses automated processing, including profiling, in the following ways:
(a) AI Memory Extraction: Our AI Service automatically extracts and stores personal facts, preferences, and patterns from your conversations to provide personalized responses. You can correct or delete memories by contacting us.
(b) AI Conversation Analysis: Your voice interactions are automatically transcribed and analyzed by language models to understand intent and generate personalized responses.
(c) Behavioral Pattern Analysis: Your habit completion rates, focus patterns, and productivity data may be analyzed to provide personalized coaching insights.
(d) Operational Grants: We or our operations team may grant Pro Memberships or special in-app rewards (e.g., the Aurora Microraptor dinosaur) to selected users based on criteria such as early-adopter status, testing participation, or operational discretion. These grants do not produce legal or similarly significant effects on you. You may review your current entitlements via the Application’s “My” page.
These processes do not produce legal or similarly significant effects. Where Applicable Law provides an opt-out right for certain profiling or targeting activities, you may exercise it as described in Sections 11–13.
· Lodge a Complaint: if you are in the EEA/UK, you may lodge a complaint with your local data protection supervisory authority (and, where the EU one-stop-shop mechanism applies, our lead supervisory authority: the Dutch Autoriteit Persoonsgegevens (AP)), without prejudice to any other legal remedy.
How to exercise your rights: contact us using the details in Section 3, or use self-service tools (such as delete-account functions) where available.
No fees usually required: requests are generally free, but we may charge a reasonable fee or refuse requests where permitted by law if they are manifestly unfounded or excessive.
Response time: we normally respond within one month after verifying your identity. Where legally permitted, we may extend for complex requests (up to 60 days total) and will notify you.
Appeals (certain U.S. states). If we decline to take action on your request, you may appeal our decision by emailing hello@focusaur.com with the subject line “Privacy Request Appeal”. Please include your original request and our response. We will respond to appeals within the timeframe required by Applicable Law.
Authorized agents (California and certain jurisdictions). In some jurisdictions, you may designate an authorized agent to submit requests on your behalf. We may require the authorized agent to provide proof of authorization and may also require you to verify your identity directly with us.

12. COOKIES
We use cookies and similar technologies on our Sites and Applications to (i) operate core functions (such as account login, security, and checkout), (ii) measure performance and improve the Service, and (iii) where permitted by Applicable Law and your choices, support marketing and advertising.
Application and AI Service Technologies. In addition to cookies on our Sites, our Application and AI Service use the following tracking and similar technologies:
· (a) Firebase Analytics (Google LLC): Collects app usage data including feature interactions, screen views, and session duration. Your user ID is linked to analytics events for analysis purposes.
· (b) Firebase Crashlytics (Google LLC): Automatically collects crash data and device information when errors occur.
· (c) Firebase Cloud Messaging: Assigns a persistent device token for push notifications, which is stored linked to your account.
· (d) Device Authentication: Our AI Device connections use HMAC signature-based authentication rather than cookies.
Your choices. In the EEA, the UK and Switzerland we place non-essential cookies and similar technologies (including analytics and advertising technologies) only after you have given consent through our cookie banner / preference tool, and you can change or withdraw your choices at any time using that tool. You can additionally manage cookies through your browser and device settings. If you disable certain cookies, parts of the Service may not function properly.
Third-party technologies. Some third parties may place cookies/pixels/SDKs on our Sites or in our Applications to provide content, analytics, or advertising. Their use of these technologies is governed by their own policies.
Where required by Applicable Law (including the ePrivacy Directive as implemented in EU member states), we will obtain your consent before placing any non-essential cookies or trackers (including analytics and advertising technologies) on your device. You may withdraw consent at any time through the Application’s settings. Essential cookies and tokens (such as authentication tokens and session management) do not require consent as they are strictly necessary for the Service to function.

13. PRIVACY CHOICES / OPT-OUTS
(a) Email marketing. We send marketing emails only with your prior consent or on the soft opt-in basis permitted by applicable ePrivacy laws. You may withdraw consent or opt out at any time, free of charge, using the unsubscribe link in every marketing email. You may continue to receive non-promotional messages (e.g., order, account, and service notices).
(b) Targeted advertising / cross-context behavioral advertising. Where applicable under State Privacy Laws, you may opt out of our processing of Personal Data for targeted advertising by contacting us at hello@focusaur.com with the subject line “Opt out of Targeted Advertising”.
(c) “Sale” / “Share” of Personal Data (U.S. states). Where applicable, you may opt out of the “sale” or “sharing” of your Personal Data (as those terms are defined by State Privacy Laws, including California) by contacting us at hello@focusaur.com with the subject line “Do Not Sell or Share My Personal Data”.
(d) Cookies and similar technologies. You can manage cookies through your browser/device controls. If a cookie banner or preference tool is available on a particular Site or Application, you can also use it to manage non-essential cookies. See Section 12.

14. ADDITIONAL REGIONAL / STATE NOTICES
A. United States State Privacy Notice.
These disclosures supplement the main body of this Policy for residents of certain U.S. states (this “U.S. State Privacy Notice”). For details on how we collect, use, disclose, and otherwise process Personal Data, please read the main body of this Policy. Capitalized terms not defined here have the meanings given elsewhere in this Policy or under applicable U.S. state privacy laws (“State Privacy Laws”). If there is any conflict between this U.S. State Privacy Notice and the rest of this Policy, this U.S. State Privacy Notice controls only for covered U.S. state residents and their Personal Data.
Covered U.S. States. This U.S. State Privacy Notice applies to residents of the following states (as applicable, now or in the future): California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia.
Nevada Residents. Nevada provides a limited right to opt out of certain sales of personal information. Although we do not currently “sell” Personal Data in a manner that triggers Nevada’s opt-out requirements, Nevada residents may submit an opt-out request using the contact details in Section 3.
Personal Data Disclosures, “Sales,” and Targeted Advertising
We disclose the categories of Personal Data we collect to the categories of recipients described in Section 8. Under certain State Privacy Laws, some disclosures may be considered the “sale” of Personal Data or the processing/sharing of Personal Data for “targeted advertising” (also called cross-context behavioral advertising). You can opt out where required (see Sections 11–13 and “Your Additional U.S. Privacy Rights” below).
We do not sell the Personal Data of individuals we know to be under 16 years of age and we do not share such information for targeted advertising purposes.
Sensitive Personal Data
Certain data elements may be considered “Sensitive Personal Data” under some State Privacy Laws, such as account credentials and, where enabled, precise geolocation. Payment card details are generally collected and processed by third-party payment providers. We use or disclose Sensitive Personal Data only as reasonably necessary and proportionate to provide the products and services you request; verify and improve services; detect and prevent security incidents, fraud, and unlawful activity; ensure physical safety; perform services on behalf of the business; and for short-term, transient use. We do not use Sensitive Personal Data to infer characteristics about you, and we do not sell Sensitive Personal Data or share it for targeted advertising.
De-Identified Information
We may create or receive de-identified information that cannot reasonably be linked to an individual or household. Where we maintain de-identified information, we keep it in de-identified form and do not attempt to re-identify it except as permitted or required by law.
Automated Decision-Making and Profiling
We do not conduct automated processing of Personal Data for decisions that produce legal or similarly significant effects. If Applicable Law nevertheless provides an opt-out right for certain profiling/targeting activities, you may exercise it as described in Sections 11–13.
Your Additional U.S. Privacy Rights
Depending on your state of residency and subject to legal limitations and exceptions, you may have the right to know/access, portability, correction, deletion, opt-out of targeted advertising, opt-out of “sales,” and (in some states) control of Sensitive Personal Data.
Past 12 months (California and certain states). In the past 12 months, we may have disclosed the categories of Personal Data listed in Section 4 to the categories of recipients described in Section 8 for business purposes (e.g., order fulfillment, payment processing, customer support, security, analytics, and marketing communications). We do not knowingly “sell” Personal Data in exchange for money. However, some disclosures (such as to advertising/analytics partners via cookies or similar technologies) may be considered “sale” or “sharing” under certain State Privacy Laws. You may opt out as described in Section 13.

B. EEA/UK/Switzerland Privacy Supplement
If you are located in the EEA, the UK, or Switzerland, this Section supplements the Policy. The controller for EEA/UK/Swiss users is Makeblock Europe B.V. (see Sections 2–3). If there is any conflict, this Section prevails for those jurisdictions. Where GDPR/UK GDPR applies, our legal bases include performance of a contract, legal obligation, legitimate interests, and consent (see Section 7). Where we rely on legitimate interests, you may object as described in Section 11. International transfers: where we transfer Personal Data outside the EEA/UK, we use lawful transfer mechanisms such as adequacy decisions and Standard Contractual Clauses (or equivalent mechanisms), as applicable. You may also have the right not to receive retaliatory or discriminatory treatment for exercising these rights, subject to Applicable Law. For the specific transfer mechanisms we rely on (including the EU-US Data Privacy Framework and the SCCs), see “International Transfers” in Section 8, and you may lodge a complaint with your supervisory authority as described in Section 11.

C. CHILDREN’S PRIVACY
The Service is not directed to children under 13. We do not knowingly collect Personal Data from children under the applicable minimum age in their jurisdiction without verifiable parental consent. Our Application includes productivity and habit-building features that may be used by individuals under the applicable age of digital consent with parental or guardian supervision and consent. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete such information. In the EEA, where we rely on consent to offer an information society service directly to a child, we require the child to be at least 16, or the lower age set by the relevant EU member state (which may not be below 13); below that age we obtain verifiable consent from the holder of parental responsibility. Parents or guardians should contact us at hello@focusaur.com. For users in Korea, the minimum age is 14 (Korean PIPA); for users in Brazil, the processing of personal data of children and adolescents requires verifiable parental or guardian consent under the LGPD.

15. UPDATES & CHANGES
Technologies and laws evolve. If we make material changes that reduce protections or materially affect your rights, we will provide prominent notice where required (for example by email or account notices) before changes take effect. Minor administrative or clarifying changes may be effective upon posting. We encourage you to review this Policy periodically by checking the “Last updated” date above.

Last updated:  July 17, 2026