BackFocus2.me

Privacy Policy

Last updated: May 31, 2026 · DRAFT — pending legal review.

What we believe

Your data is yours. We collect the minimum we need to make Focus2.me work, we never sell it, and we delete what we don't need.

1. What we collect

  • Account basics: name, handle (@you), email, password (stored hashed — we can't read it), date of birth.
  • Profile: bio, avatar, location, public interests — whatever you choose to add.
  • Messages & Intro Cards: the structured prompts you send and receive.
  • Age verification (optional): a copy of your ID image, kept only until an admin reviews it, then deleted (see Section 4).
  • Technical: basic logs (IP, browser, timestamps) for security and abuse prevention.
  • Push notification token: if you opt-in to Web Push, your browser's push subscription endpoint.

2. What we never collect

Card numbers (merch checkout is handled by our fulfilment partner), data from your third-party social-network accounts, or content from other apps. We don't run third-party advertising trackers, and Focus2.me never links out to external social media platforms.

3. How we use your data

  • To run the service: sign you in, deliver messages, show your profile, ship your merch.
  • To keep things safe: detect abuse, block spammers, investigate reports.
  • To improve Focus2.me: aggregate, anonymous usage stats — never individual profiling.
  • To contact you about your account (e.g. security, important changes). We don't send marketing email without your opt-in.

4. Age verification — the deletion contract

If you upload a government-issued ID for age verification:

  • The image is shown only to an admin reviewer.
  • The moment the admin approves or rejects, the image bytes are deleted from our database immediately (`$unset`).
  • We keep only a status (approved / rejected), reviewer ID, decision timestamp, and any rejection reason — purely for compliance and abuse prevention.
  • Your full date of birth is never displayed publicly. Other users only see your computed age (e.g. "30 y/o").

5. Who can see what

  • Public on your profile: name, handle, bio, avatar, location (if added), public interest icons, age (if you've added a DOB), Verified 18+ badge (if approved).
  • Private: email, password hash, full date of birth, your message history, verification status detail.
  • Visible only after an Intro Card: the message thread between you and the other user.

6. Cookies & sessions

We use a single secure, HttpOnly session cookie to keep you signed in. It can't be read by JavaScript or third parties. We don't use cross-site tracking cookies.

7. Sharing your data

We don't sell or rent your data. We share it only with:
  • Service providers who help us run the platform (hosting, database, email delivery, push notifications, merch fulfilment). They're bound by contracts to handle your data only on our instructions.
  • Legal authorities when required by a valid legal request, or to prevent imminent harm.

8. Your rights

  • See what we hold about you (request a copy by emailing us).
  • Correct anything that's wrong — most fields you can edit yourself in the app.
  • Delete your account anytime from your profile. Some logs may be retained for security/legal reasons.
  • Withdraw consent (e.g. turn off push notifications) at any time.

9. Security

Passwords are hashed (bcrypt). Sessions use HttpOnly, SameSite-Lax cookies over HTTPS. ID images used for age verification are deleted immediately after review. We work hard to protect your data but no system is 100% secure — please choose a strong, unique password and tell us right away if you suspect anything is off.

10. Data retention

We keep account data while your account exists. Once you delete your account, your profile is removed promptly; backups and limited audit data (e.g. age-verification audit, abuse logs) may persist for up to 90 days for security and legal compliance.

11. International users

Focus2.me may store and process data in countries other than where you live. By using the service you understand and consent to that transfer.

12. Changes to this Policy

If we make a meaningful change, we'll surface the new policy next time you sign in. Continuing to use Focus2.me after that means you accept the changes.

Last updated

Draft v2026-08 — pending legal review. Effective date will be set at deployment.

14. Intro Card photographs (optional)

Attaching a photograph to an Intro Card is optional. When you upload a photograph, Focus2.me sends the image to Google Cloud Vision SafeSearch for automated safety screening.

SafeSearch returns likelihood assessments (VERY_UNLIKELY through VERY_LIKELY) across five categories: adult, racy, violence, medical, and spoof (spoof/manipulation). Focus2.me uses those likelihoods to approve, reject, or hold for human review. Automated systems can make mistakes, so an authorized Focus2.me administrator may privately review a photograph when the automated result is uncertain.

Focus2.me does not use this SafeSearch integration to identify the person in the photograph or perform facial recognition. Google Cloud is the data processor for the SafeSearch call; Google's handling of image data is governed by its own agreements, which we link below rather than restate. See SafeSearch documentation, Google Cloud Data Processing Addendum, and Google Cloud privacy information.

15. Photo visibility and retention

  • Photographs in review or rejected are never shown to the intended recipient.
  • An approved photograph becomes visible only after you explicitly attach and send it with an Intro Card.
  • The sender and the intended recipient may view an approved, attached photograph. Authorized Focus2.me administrators may access photographs when required for moderation, reports, safety, or system administration.
  • Unattached uploads normally expire after 24 hours.
  • A photograph approved through human review receives a fresh 24-hour attachment window from the approval time.
  • Approved attached photographs may remain with the associated Intro Card while that record is retained.
  • Rejected image bytes are removed promptly, unless a report or safety evidence hold requires temporary preservation.
  • Deleting or cancelling a photograph may hide it from normal user access while necessary evidence remains privately preserved.

16. Reporting other users

You can privately report a profile, an Intro Card, an individual conversation message, a photograph, or a safety concern. Focus2.me records the selected reason, an optional explanation you provide, relevant account identifiers, and a limited server-created evidence snapshot.

Authorized administrators review reports and decide the appropriate action, which may include blocking, further review, dismissal, resolution, account restriction, or other appropriate safety action. Reports are not public. Focus2.me does not display public report totals or accusations.

Focus2.me does not show the reporter's identity to the reported user through the normal reporting experience. We may disclose information when required by law or when reasonably necessary to protect safety, rights, and the service.

17. Report evidence retention

  • Evidence remains available to reviewers while a report is open or in review.
  • When a report is resolved or dismissed, its detailed evidence snapshot and the reporter's explanation are scheduled for removal after 30 days.
  • Cleanup normally runs approximately every six hours, so removal may not occur at the exact minute the 30-day period ends.
  • Limited report and audit metadata may be retained longer for abuse prevention, security, dispute handling, legal obligations, and protection of the service.
  • Photo evidence holds can remain until all reports involving that photograph reach their applicable purge dates.
  • If applicable law, safety needs, fraud prevention, or a valid legal request requires longer retention, we may retain records accordingly.

18. Your choices and privacy rights

Contact privacy@focus2.me to request:

  • Access to the personal data we hold about you where applicable.
  • Correction of inaccurate information.
  • Deletion of applicable personal data.
  • Information about how your data is processed.

We may not be able to delete every record immediately. Limited records may be retained when reasonably required for safety, fraud prevention, legal obligations, or resolving disputes. For general privacy guidance for Texas residents, see the Texas Attorney General's privacy resource.

19. Age

Focus2.me is intended for people who are at least 18 years old. Accounts must confirm a date of birth at registration, and access is refused when the calculated age is below 18.

20. Safety Guidelines — Photographs

Generally permitted:

  • Safe profile-style photographs.
  • Ordinary swimwear in a legitimate beach, pool, recreational, or athletic setting.
  • Ordinary athletic clothing.
  • Ordinary nonsexual shirtless photographs.

Not permitted:

  • Nudity or explicit sexual content.
  • Underwear or lingerie presentation.
  • Boudoir-style photographs.
  • Sexually suggestive posing.
  • Graphic violence or threats.
  • Graphic medical content.
  • Impersonation or intentionally misleading imagery.
  • Content that violates other Focus2.me safety rules.

Automated screening cannot always determine context — contextually acceptable swimwear, athletic, or shirtless photographs may still be sent to human review before appearing to your recipient.

21. Contact

Privacy questions, data requests, or concerns? privacy@focus2.me.
DRAFT — pending review by a qualified attorney. Nothing here constitutes legal advice.