Skip to content
Security & Privacy

Your data stays yours.

Focused Lens is designed to give you insight into your own time — not to surveil you. Here is exactly what we collect, what we never touch, and how it is protected.

What we collect

Only the minimum needed to show you where your time goes.

App names

Which application is in focus.

Window titles

The title of the active window or browser tab.

Usage durations

How long each app or window was in use.

What we never collect

These are hard limits — not configuration options.

Screenshots

We never capture your screen.

Keystrokes

No input or typing is ever recorded.

Clipboard content

We have no access to your clipboard.

Private browsing

Incognito and private windows are ignored entirely.

Passwords or credentials

We never read page content or form fields.

Identifying site analytics

Public-site analytics never include cookies, replay, raw referrers, account IDs, full URLs, query strings, hashes, app names, or window titles.

Storage & encryption

In transit

All data is transmitted over HTTPS/TLS. Nothing travels unencrypted between your device and our servers.

At rest

Your activity data is stored encrypted in our cloud database. Database credentials are never exposed to the application layer.

Local buffer

The desktop app buffers data locally before syncing. If you are offline, nothing is lost — it syncs when you reconnect.

Infrastructure

Hosted on Supabase (database & auth) and Railway (API). Both providers maintain their own security programmes.

Your control

Only you can see your data

Your activity data is scoped to your account. No one — including the Focused Lens team — can access your usage history. We do not sell, share, or analyse your data for any purpose other than serving it back to you.

Delete everything, anytime

You can permanently delete your account and all associated data from Settings → Delete Account. Deletion is immediate and irreversible. We do not retain backups of deleted accounts.

Public analytics stay aggregate

We use Vercel Web Analytics only to count public page views and CTA clicks. Events use sanitised route paths and fixed CTA labels, not personal account data or desktop activity contents.

Device-level revocation

You can revoke access for any individual device from Settings → Devices without affecting other devices or your account.

Report a vulnerability

If you discover a security vulnerability, please email us at security@focusedlens.app rather than opening a public GitHub issue. If you do not receive an acknowledgement within 48 hours, forward the report to hello@focusedlens.app.

We do not currently operate a formal bug bounty programme.