Pomodoro+

Privacy Policy

Effective date: August 27, 2026 · Last updated: August 27, 2026

This Privacy Policy explains how Joshua & Company Inc ("we", "us") handles information in connection with the Pomodoro+ mobile application for iOS and Android (the "App"). It applies to the App and to the services it connects to. Please read it before using the App.

At a glance

1. Who we are

The data controller responsible for the App is:

If you have any question about this policy or about how your data is handled, email us at the address above.

2. Information we collect

2.1 Data stored on your device

The core of Pomodoro+ works offline. The following is created by you and stored locally on your device, in the App's private storage:

We cannot see this data. It never leaves your device unless you enable Cloud Sync (section 2.2), and it is removed when you uninstall the App.

2.2 Account and Cloud Sync (optional)

Cloud Sync is off by default. If you choose to turn it on, you sign in with Google Sign-In or Sign in with Apple through Firebase Authentication. In that case we process:

The purpose is strictly to let you restore your history and settings on another device. We do not read this data for any other reason, and we do not use it for advertising or profiling.

2.3 Purchases and subscriptions

Premium purchases are processed by Apple's App Store or Google Play. We use Adapty as our purchase infrastructure to validate receipts and determine whether your Premium entitlement is active. This involves a pseudonymous customer identifier, the store transaction/receipt, product identifiers, and subscription status.

We never receive or store your payment card details, billing address, or full store account credentials. Those stay with Apple and Google.

2.4 Advertising

The free version of the App shows interstitial ads served by Google AdMob. To serve and measure ads, Google may process:

This processing is carried out by Google as an independent party under its own privacy policy. Purchasing Premium removes ads and stops this ad-serving processing.

2.5 Device permissions

The App requests a small number of system permissions. They are needed for the timer to work reliably and are not used to collect information about you:

PermissionWhy it is needed
NotificationsTo tell you when a focus or break period ends.
Exact alarms (Android)To fire the end-of-session alert at the right second, even when the device is idle.
Foreground service & wake lock (Android)To keep the timer counting accurately while the App is in the background.
VibrationFor haptic feedback at session transitions.
Run at startup (Android)To restore a running timer and refresh the home-screen widget after a reboot.
Network accessTo load ads, verify purchases, and run Cloud Sync when you enable it.
Advertising ID (Android)Used by Google AdMob to serve ads in the free version.

The App does not request access to your contacts, camera, microphone, photos, precise location, calendar, or health data.

3. How we use information

We do not use your data to build advertising profiles, and we do not sell or rent personal information to anyone.

4. Legal bases for processing (EEA/UK)

If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR:

ProcessingLegal basis
Running the timer and storing data on your devicePerformance of a contract (Art. 6(1)(b))
Cloud Sync and account sign-inPerformance of a contract, at your request (Art. 6(1)(b))
Purchase validation and entitlementPerformance of a contract (Art. 6(1)(b))
Personalized advertisingYour consent (Art. 6(1)(a)), collected through Google's consent form
Non-personalized advertising and fraud preventionLegitimate interests (Art. 6(1)(f))
Responding to support requestsLegitimate interests (Art. 6(1)(f))

5. Third-party services

We use the following providers. Each processes data under its own privacy policy:

ServicePurposePrivacy policy
Google AdMobServing ads in the free version policies.google.com/privacy
Google User Messaging PlatformCollecting and storing your ad consent choices (EEA/UK) policies.google.com/privacy
Firebase AuthenticationSign-in for Cloud Sync firebase.google.com/support/privacy
Google Cloud FirestoreStoring your synced sessions and settings firebase.google.com/support/privacy
Google Sign-InOptional sign-in method policies.google.com/privacy
Sign in with AppleOptional sign-in method apple.com/legal/privacy
AdaptyPurchase validation and subscription entitlement adapty.io/privacy
Apple App Store / StoreKitProcessing purchases on iOS apple.com/legal/privacy
Google Play BillingProcessing purchases on Android policies.google.com/privacy

6. Advertising choices

7. Data retention and deletion

You can also email support@joshuanco.com to request deletion, and we will action it within 30 days.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, to withdraw consent, and to receive a copy of your data in a portable format. Residents of the EEA/UK (GDPR), California (CCPA/CPRA), Korea (PIPA), and other jurisdictions with comparable laws all have such rights.

Because most data stays on your device, you can exercise many of these rights directly in the App. For anything else, email support@joshuanco.com and we will respond within the period required by applicable law.

We do not sell or share personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. EEA/UK residents also have the right to lodge a complaint with their local supervisory authority.

9. International data transfers

Our providers — Google, Apple, and Adapty — operate globally, so data may be processed on servers outside your country, including in the United States. Where required, these transfers rely on the European Commission's Standard Contractual Clauses or another approved transfer mechanism put in place by the relevant provider.

10. Security

Data on your device is stored in the App's private, sandboxed storage. Data in transit is encrypted with TLS. Synced data in Firestore is protected by security rules that restrict every document to the authenticated account that owns it, and is encrypted at rest by Google Cloud. No method of transmission or storage is completely secure, but we take reasonable measures to protect your information.

11. Children's privacy

Pomodoro+ is a general-audience productivity app and is not directed to children under the age of 13 (or under 16 where local law sets a higher age). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact support@joshuanco.com and we will delete it.

12. Changes to this policy

We may update this policy as the App evolves or as the law requires. When we do, we will revise the "Last updated" date at the top of this page. For material changes we will provide additional notice in the App. Continuing to use the App after an update means you accept the revised policy.

13. Contact us

Questions, requests, or complaints about this policy: