Product privacy · Updated 11 September 2026

Privacy policy — PomodoFlow

PomodoFlow keeps your productivity data on your Apple devices and can synchronise it through your private iCloud account. Product analytics remains off until you choose to enable it.

1. Scope and controller

This policy applies to the PomodoFlow application for iPhone, iPad and Mac. The controller is Vincent Mary, sole trader in France. For a privacy request, write to confidentialite@tissyo.com.

2. Data processed by the application

Depending on how you use the app, PomodoFlow processes tasks, projects and clients, tags, subtasks, focus sessions, time blocks, goals, revenue and payment status, financial settings, dashboard settings, reminders, notes and attachments. This working data is stored locally using SwiftData.

When private iCloud synchronisation is available, this working data can synchronise through Apple CloudKit in the private database attached to your Apple account. Attachments can be stored there as CloudKit assets. Tissyo does not operate a separate server containing this working database.

3. Mac auto-tracking

Mac auto-tracking is an optional feature that you start yourself. While active, it may record the foreground application, its bundle identifier, the active window title and, for supported browsers, the current URL. macOS may ask for Accessibility and Apple Events permissions for these details.

Raw auto-tracking activity and its rules remain in a separate local store on the Mac and are not synchronised to iCloud. Raw observations are also excluded from the JSON backup. When you confirm an observation as working time, the resulting focus session becomes ordinary working data and may synchronise through private iCloud.

4. Optional PostHog analytics

Analytics is disabled by default and requires your explicit choice in Settings. If enabled and if a verified dedicated configuration is bundled, PomodoFlow sends limited events to the European Union endpoint of PostHog. These events describe a screen or feature category, paywall origin, offer or purchase stage, focus mode or restoration outcome, together with the platform, app version, build, timestamp and a random identifier created only after consent.

Event properties cannot contain free-form values. PomodoFlow does not send task or project titles, notes, amounts, attachments, window titles, browser URLs or raw auto-tracking activity. It does not use automatic capture, session replay, cookies or PostHog person profiles. Revoking consent deletes the local analytics identifier and cancels pending sends. Events already received remain subject to the retention configured for the dedicated PostHog EU project.

5. Other optional services and permissions

Apple processes purchases, subscriptions and restoration through StoreKit 2 and the App Store. PomodoFlow does not receive your payment-card details. With calendar permission, the app reads Apple Calendar events to display them alongside your plan; those events are not copied into SwiftData and PomodoFlow does not edit or delete them. Notification permission is used for timer completion and reminders on your device.

If you connect Abby, the API key is stored in Apple Keychain and sent only to the Abby API to read paid invoices. Imported invoice references, client labels and amounts become PomodoFlow working data; the API key is excluded from SwiftData, analytics, widgets and backups.

If you open Tissyo Support, your browser loads the Tissyo support service. Only the information you choose to send there, such as your message, contact details or an attachment, is used to handle the request. The support service has its own operational retention and security controls.

6. Purposes and legal bases

Working data is processed to provide the features you request, save your work, calculate time and financial indicators, synchronise between your devices and create exports. This processing is necessary to provide the requested service. StoreKit data is processed to supply and restore purchases. PostHog analytics is based on consent and can be disabled at any time. Support data is processed to answer your request.

7. Retention, deletion and export

Working data remains until you delete individual items or use Erase all data in Settings. That command deletes PomodoFlow records from the local SwiftData stores and, when CloudKit synchronisation is active, the deletions are submitted to your private iCloud database. Apple controls cloud propagation time and iCloud account retention.

The same command revokes analytics consent, clears widget data, stops Mac auto-tracking and attempts to remove the optional Abby credential from Keychain. Ignoring an application in auto-tracking erases its raw local activity; converted raw observations older than 30 days are automatically purged. PomodoFlow offers CSV and PDF session reports and a restorable JSON backup; these exports are created only when you request them and saved or shared using the system interface.

8. Recipients and transfers

Recipients are limited to you and anyone with whom you deliberately share an export, Apple for iCloud and StoreKit functions, PostHog EU only after analytics consent, and Tissyo Support only when you contact it. Network communications use encrypted HTTPS. Apple may process data under its own account and service terms. The analytics endpoint used by the app is located in the European Union.

9. Your choices and rights

You can refuse or revoke analytics, stop auto-tracking, withdraw macOS permissions, ignore selected applications, delete records, erase all data and create exports from the app. Subject to applicable law, you may also request access, correction, deletion, restriction, portability or objection by writing to the address above. You may lodge a complaint with the CNIL or your competent supervisory authority.

10. Security and changes

PomodoFlow uses the Apple sandbox, separate local stores for raw tracking and synchronised working data, private CloudKit, a closed analytics event vocabulary and system file pickers. No system is risk-free; protect your device, Apple account and exported files. This policy will be updated if the application, providers or verified data flows change.

See the Tissyo trust overview →