Privacy Policy
Last updated: July 20, 2026
Pomiq (“we”, “pomiq”) is a focus timer and day planner. This page explains what data pomiq handles, why, and how you can control it. Pomiq is built to work fully without an account — most of what’s below only applies once you turn on optional features like cloud sync or calendar view.
Data stored on your device
By default, everything you enter — tasks, projects, focus sessions, distraction logs, settings — is saved only in your browser’s local storage. Nothing leaves your device unless you turn on one of the optional features below. Uninstalling the app or clearing site data removes it permanently; there is also a Reset App control in Settings that does the same on demand.
Optional account & cloud sync
Signing in (with Google, or an email link) is optional and only needed to back up your data and sync it across devices. Authentication is handled by Supabase; if you sign in with Google, Google shares your name, email address and profile photo with us for that purpose. Once signed in, your task/project/ session data and settings are stored in our database (hosted by Supabase) under your account, so a second device can pull the same data down.
Synced data is encrypted in transit and at rest, but it is not end-to-end encrypted. This is the same model most productivity apps use: it means we could technically access stored account data while operating the service. In practice we only look at account data to resolve a support request you bring to us. If you prefer that nothing leaves your device at all, simply use pomiq without an account.
Signing out stops syncing but keeps your local data on the device. You can remove tasks and focus history from Settings → Account. To delete your cloud account and its associated profile and synced data, email hello@pomiq.app from the address used for the account.
Bot protection
The email sign-in form is protected by Cloudflare Turnstile, which runs invisibly to verify you’re not a bot before we send a sign-in link. It does not identify you personally. Cloudflare’s practices for this are described in the Turnstile Privacy Policy.
Google user data
Google features are optional. Pomiq uses Google Sign-In for account authentication and, only when you separately choose Connect in Settings → Calendars, read-only Google Calendar access. Calendar access is not required to use the timer, tasks, reports, or cloud sync.
Google user data we access
Google Sign-In provides your name, email address, profile photo, and Google account identifier. The Calendar connection accesses calendar identifiers, names, and colors, plus event identifiers, titles, start and end times, all-day status, and the calendar each event belongs to. It also receives OAuth access and refresh tokens needed to maintain the connection. Pomiq does not use event descriptions, locations, attendees, attachments, or contact data.
How we use Google user data
Sign-In data is used only to authenticate you, label your account, and associate your optional cloud backup with that account. Calendar names and colors power the visibility controls in Settings; today’s event titles and times are displayed beside your tasks in Schedule. Pomiq does not create, edit, or delete Google Calendar data, use Google data for advertising, or use it to train AI models.
Sharing, transfer, and disclosure
Calendar data travels from Google through Pomiq’s server hosted by Vercel to your browser so the requested view can be rendered. Vercel processes that request as our hosting provider. We do not send Google Calendar data to Supabase, PostHog, Cloudflare, advertisers, data brokers, or other users, and we do not sell it. Google Sign-In profile data is processed by Supabase as our authentication provider. We may disclose data when legally required or when necessary to protect users and the service.
Data protection
Google data is transmitted over HTTPS. Calendar OAuth tokens are sealed with authenticated AES-256-GCM encryption and kept in an HttpOnly, SameSite cookie that client-side JavaScript cannot read; the cookie is marked Secure in production. Encryption keys and Google client secrets remain on the server. The OAuth connection also uses a one-time state value to protect against cross-site request forgery. Calendar tokens and event data are excluded from Pomiq analytics and cloud sync.
Retention and deletion
Fetched calendar lists and events are held in browser memory for the current app session and are not stored in Pomiq’s database. A device may keep only your calendar visibility choices locally. The encrypted Calendar token cookie lasts for up to 180 days, or until the token expires or you disconnect. Disconnecting in Settings → Calendars deletes Pomiq’s token cookie and the fetched Calendar data on that device. It does not delete events from Google. You can also revoke Pomiq from your Google Account permissions.
Pomiq’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Analytics
We use PostHog to understand which parts of pomiq are used and to fix what’s broken. This tracks anonymous usage events (e.g. a focus session started, a task was created) and basic page views — never the content of your tasks, notes, or calendar. If you sign in, your account is linked to your prior anonymous activity so we can understand usage across your session, not to identify you personally beyond what sign-in itself already shares with us.
Other services we use
Pomiq is hosted on Vercel. Sign-in and cloud sync run on Supabase. Analytics run on PostHog. Calendar data comes from the Google Calendar API. Bot protection on sign-in runs on Cloudflare Turnstile. Each provider processes only the data needed for the service described in this policy.
Children
Pomiq is not directed at children under 13, and we do not knowingly collect data from them.
Changes to this policy
If this policy changes in a way that matters, we’ll update the date at the top of this page. We won’t change how already-collected data is used without telling you first.
Contact
Questions about this policy or your data — email hello@pomiq.app.