Pomosaka
FeaturesHow it worksExtensionThemesCompanionsSupport
Log inGet started
FeaturesHow it worksExtensionThemesCompanionsSupportGet started — it’s free

Legal

Privacy Policy

Effective date: July 18, 2026

Pomosaka (also shown as “pomo” or “Pomodoro” in our products — “we”, “us”) is a focus timer available as a web app, a browser extension, and this website. We built it to help you study, not to study you. This policy explains what data we handle, why, and the choices you have. It applies to the web app at web.pomosaka.com, the “pomo — focus companion” browser extension, and this website.

The short version

  • The extension works without an account, and its data stays on your device.
  • We collect only what the product needs to function — no ads, no data sales, no third-party analytics trackers.
  • Emails we send are transactional (sign-in codes, password resets, security alerts, support replies).
  • We don’t offer purchases today. If we add in-app purchases later, payments will be handled by dedicated payment providers and we will never store your full card details.
  • You can access, export, or delete your data at any time by contacting us.

1. Data we collect

Account data (only if you create an account)

Email address, display name, timezone, and a password (stored only as a salted hash — we cannot read it). An account is optional for the extension and required for the web app.

Focus data (only if you use an account)

The content you create while using Pomosaka signed in: focus sessions (start/end times, planned and actual minutes), goals and habits, journal entries, streaks and stats, and your companion and decoration choices. This data exists so your progress syncs across devices; it is yours and is never used for advertising or profiling.

Support messages

If you contact us through the support form or by email, we receive your name (if given), email address, and message, and keep the correspondence for as long as needed to resolve your request.

Data that never leaves your device

Your theme choice on this website is saved in your browser’s local storage. The extension keeps its timers, blocklist, and buddy state in extension storage on your device (see the next section).

What we do not collect

We run no advertising, no data brokers, and no third-party analytics trackers on the web app, the extension, or this site. Our servers keep standard, short-lived technical logs (such as IP address and request path) for security and abuse prevention — for example, rate-limiting sign-in attempts and the support form.

2. The browser extension

The extension is designed to be local-first. Without an account, everything it does — timers, goal attribution, the walking buddy, and site blocking — happens on your device, stored in your browser’s extension storage, and is sent nowhere.

  • Site blocking is evaluated entirely inside your browser. Your blocklist is stored locally and is not transmitted to us. We do not record your browsing history or the sites you visit or block.
  • Page access permissions exist only to show the timer overlay and the blocking screen on the pages you visit. The extension does not read, collect, or transmit the content of web pages.
  • If you sign in inside the extension, your completed focus sessions sync to your account, exactly as the web app does. Signing in is optional and can be undone by logging out.

Our use of browser permissions complies with the Chrome Web Store User Data Policy, including its Limited Use requirements: extension data is used only to provide the features described here, and is never sold, used for advertising, or handed to data brokers.

3. Emails

We send transactional email only: two-factor sign-in codes, password-reset codes, security alerts about your account (for example, when your password changes), and replies to your support requests. We do not send marketing email. Delivery is handled by Resend, our email service provider, which processes the recipient address and message content on our behalf solely to deliver the email.

4. Payments and in-app purchases

Pomosaka currently has no paid features and we collect no payment information. We plan to introduce optional in-app purchases in the future. When we do:

  • Payments will be processed by dedicated payment providers (such as a card processor or the app store / browser store billing system of your platform). Your full card number and payment credentials will go to them, not to us — we will never store them.
  • We will receive and keep only what is needed to operate purchases: what you bought, when, the amount, a transaction identifier, and enough to grant the purchase to your account and to meet tax and accounting obligations.
  • Purchases will be optional, and free features will not require payment data.
  • We will update this policy before purchases launch, and material changes will be announced in the product.

5. How we use data

We use the data above to:

  • provide the service — run timers, sync sessions, keep streaks and stats (performance of our contract with you);
  • keep accounts secure — authentication, 2FA codes, security alerts, rate limiting (legitimate interest in security);
  • answer support requests (legitimate interest / your request);
  • comply with legal obligations where they apply.

We do not sell or rent personal data, and we do not use it for advertising or automated decision-making with legal effects.

6. Who we share data with

Only service providers who process data on our behalf, under contract, to run the product:

  • Hosting — our API and database run on cloud infrastructure (currently Render).
  • Email delivery — Resend, for the transactional emails described above.
  • Payment providers — in the future, if you make a purchase, as described in section 4.

Beyond that, we disclose data only if the law requires it, or as part of a merger or acquisition in which the receiving party remains bound by this policy.

7. Retention and deletion

Account and focus data are kept while your account exists. When you delete your account (or ask us to), your personal data is deleted, except records we must keep for legal, security, or accounting reasons — and those are kept no longer than required. Expired one-time codes are short-lived by design. Local extension data is removed by uninstalling the extension or clearing its storage.

8. Security

Passwords are stored with modern password hashing (Argon2). Traffic to our servers is encrypted in transit (TLS). Sign-in uses short-lived tokens, optional email two-factor authentication, and rate limiting against brute force. No system is perfectly secure, but security decisions in Pomosaka default to the cautious side.

9. Your rights

Depending on where you live (for example, under the GDPR or CCPA), you may have rights to access, correct, export, delete, or restrict the processing of your personal data, and to object to certain processing. We honor these requests for everyone, wherever you live: email us at kjorn@gmail.com and we will respond within 30 days. You also have the right to complain to your local data-protection authority.

10. Children

Pomosaka is not directed at children under 13 (or the higher minimum age of your country), and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.

11. International transfers

Our infrastructure providers may store data in countries other than yours, including the United States. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.

12. Changes to this policy

We may update this policy as the product evolves — for example, when in-app purchases launch. The effective date at the top always reflects the latest version, and material changes will be announced in the product or by email before they take effect.

13. Contact

Questions, requests, or concerns: kjorn@gmail.com, or use the support page.

Pomosaka
FeaturesHow it worksExtensionThemesCompanionsSupportPrivacyLog in

© 2026 Pomosaka · Made for slow, steady studying