okFINE Privacy Notice

Effective date: September 5, 2026

This notice explains how the okFINE iPhone and iPad app handles information. okFINE is a product of Focused Space, Inc. This notice applies only to okFINE. It does not replace or change the separate privacy policy for the Focused Space website, Focused Space membership, Focused Companion, or other Focused Space services.

The short version

okFINE is local-first. It has no sign-in or user account managed by okFINE’s developer, Focused Space, and no Focused Space backend for okFINE. The app stores its working data on your device and coordinates with its own Screen Time extensions through an Apple App Group. Focused Space does not receive that app data during normal operation.

okFINE contains no advertising or cross-app tracking and does not send developer analytics or telemetry to Focused Space. A redacted diagnostic export leaves the app only when you preview it and choose to share it. Apple may separately handle App Store, operating-system, backup, map, location, Health, Screen Time, notification, and diagnostic data under your Apple settings and Apple’s terms.

When you connect Gmail or use Apple Maps and geocoding, information is sent directly to Google or Apple as needed to perform the action you requested. Those services handle that information under their own terms and privacy policies. The sections below explain what stays on your device and what is sent to a provider.

Information kept on your device

okFINE creates a random local profile that is independent of any Apple or Google account. The app stores the information needed to run and recover your commitments, including:

  • task names, schedules, recurrence, rules, snooze choices, and task status;

  • configured verification rules, such as a Gmail recipient, a HealthKit source identifier and workout thresholds, or an exact location target and radius;

  • occurrence state and history, including Completed and Broken outcomes, transitions, audits, verification and Gmail-send attempt states, coarse timestamps, and opaque evidence fingerprints;

  • opaque Family Controls selections, safety exceptions, Screen Time schedules, and enforcement state; and

  • a small local profile, onboarding state, and history-visibility preferences.

These records remain until they are removed through an applicable in-app action. Retiring or deleting a task may keep history and safety records needed for existing occurrences. See “Your controls and deletion” below for the difference between clearing History and erasing all data.

Screen Time, Family Controls, and App Group coordination

If you create a task, okFINE asks for Apple’s Family Controls permission and uses Apple’s Family Controls, Device Activity, and Managed Settings frameworks to schedule and apply the app, category, or website restrictions you selected.

Apple represents a Family Controls selection with opaque tokens. okFINE stores the opaque selection locally and does not resolve, log, or send individual selected app, category, or website identities to Focused Space. The main app shares a minimal, versioned enforcement snapshot and content-free or redacted extension events with okFINE’s Screen Time extensions through its private Apple App Group. That coordination includes random identifiers, schedules, state, and opaque restriction data; it excludes task names, verifier details, notification text, and user-authored content. The main app’s local database remains authoritative, and the extensions do not open it.

HealthKit workout verification

For a workout task, okFINE requests read-only access to HealthKit workouts and, only when the task needs it, the one supported HealthKit quantity type for distance or active energy. okFINE does not request permission to write Health data and does not request unrelated Health types as a fallback.

HealthKit workout objects and raw sample values are queried from Apple’s HealthKit store and held transiently in memory. They are immediately reduced to the limited fields needed to evaluate the locked workout rule. The temporary workout details and source display names are not written to the okFINE database or diagnostic export.

The task’s selected source identifier, activity, duration, and optional effort threshold stay in its local rule. When a workout qualifies, okFINE stores reduced evidence locally: an opaque, one-way fingerprint plus occurrence and rule references and an observation time. It does not store the raw workout UUID, raw HealthKit sample, route, source display name, workout duration, or health quantity as completion evidence. Health data remains in HealthKit under Apple’s controls.

Apple does not tell apps whether read access to Health data was denied. A missing workout therefore does not prove denial or completion, and okFINE may leave verification pending.

Location and Apple Maps

A Location Visit task requires Always location permission and Precise Location from task activation through completion or Emergency Exit. okFINE may monitor the selected region and collect bounded location observations in the background during that period. If either permission is unavailable, location verification cannot complete. okFINE does not store a continuous route or exact location history.

The exact target coordinate and radius you confirm are stored locally in the task rule because the app needs them for verification. A bounded coarse place label, such as city and region, may also be stored for display. Location observations, including coordinates and accuracy, are processed transiently in memory. Accepted observations are reduced to times and accuracy for the active dwell session; after qualification, the database stores only an opaque evidence fingerprint and coarse occurrence references and timing—not the observed coordinates.

During setup, the text you enter for a place search and its geographic context are sent to Apple Maps to return search results. Apple may return an exact result address. If you select a map point or current location, its coordinates may be sent to Apple’s geocoding service to return a place label. MapKit may also request map content for the displayed region. okFINE does not retain the search query, result list, exact result address, or raw place identifier after setup; it retains the confirmed exact target and radius locally as described above.

Gmail send verification

Gmail is optional and is used only for a task that requires sending a message. Google authorization requests exactly these scopes:

  • openid;

  • email; and

  • https://www.googleapis.com/auth/gmail.send (gmail.send).

The openid and email scopes let okFINE retrieve the selected Google account’s verified primary email address and stable Google sub identifier. okFINE uses them only to identify and bind the selected sending account. The gmail.send scope lets the app send a message that you compose in okFINE. These scopes do not let okFINE read your inbox, Sent Mail, or other messages, and okFINE does not request Gmail read, metadata, modify, or full-mail access.

The access token, refresh token, primary email, and stable sub identifier are stored only in an iOS Keychain item marked When Unlocked, This Device Only, with Keychain synchronization disabled. A separate device-only Keychain item protects the locked recipient. The task’s actual recipient is stored locally in its immutable rule so okFINE cannot silently send the task message to a different address.

The subject, body, formatting, and any attachments you choose are held in memory while you compose and send. okFINE combines them with the locked recipient and sends the resulting message directly to the Gmail API over HTTPS. Google and the recipient then handle the sent message under their own policies. okFINE does not persist the subject, body, attachments, MIME message, raw Gmail message ID, or provider response body. It stores only a local attempt state and, after confirmed acceptance, an opaque message fingerprint, time, and device-keyed recipient check.

If the network outcome is ambiguous after the message may have reached Gmail, okFINE leaves the task in Verification Pending and does not automatically or manually send that occurrence again. Because okFINE has no Gmail read scope, it cannot inspect Sent Mail to resolve the ambiguity. A known rejection may be retried only through a later explicit action.

okFINE’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

Notifications

With your permission, okFINE schedules local notifications for due and follow-up times. The notification requests use random occurrence identifiers and fixed, generic text. They do not contain task names, verification details, locations, Health data, Gmail data, or other user-authored content. okFINE does not operate a push-notification server or upload a push token. Delivery and any copies shown in Notification Center are controlled by iOS.

Diagnostics

okFINE keeps only a small allowlist of local operational events with coarse values such as an erase stage; those events exclude identifiers, task content, provider values, credentials, evidence, coordinates, Health data, and message data. The Privacy & Diagnostics screen can prepare a redacted text export containing coarse record counts, permission or connection states, timestamps, and the time zone. It omits task names, provider identifiers, credentials, and raw provider data.

Nothing is uploaded automatically. The full export is shown to you before a system share sheet is available. If you choose to share it, the recipient and service you select will handle that copy. Apple may separately collect device or app diagnostics according to your device settings and Apple’s policies.

Emergency Exit

Emergency Exit is a safety action available independently of verification. It asks iOS to clear the affected Managed Settings restrictions first, stops related schedules, notifications, and provider observation, and records the affected occurrence or occurrences as Broken. An Emergency Exit request from a Screen Time shield contains no task name or provider content; the main app resolves it against its local authority. The Broken outcome remains in local History unless you clear visible History or use Erase All Data.

Your controls and deletion

You can control Apple permissions in iOS Settings. Revoking Screen Time, notifications, Health, or Location access may make the related task unavailable or unable to complete; revocation never counts as completion. Apple permissions remain under Apple’s control and are not removed by okFINE’s Erase All Data action.

You can disconnect Gmail in okFINE when no Gmail occurrence is active. Disconnect requires device owner authentication, deletes the local OAuth credential, and attempts to revoke the Google token. Provider revocation is best-effort and can fail after the local credential has already been deleted. You can also revoke okFINE from your Google Account. Disconnecting does not delete your local profile, tasks, or non-Gmail history, and it cannot remove messages already handled by Google or a recipient.

Clear visible history hides the Completed and Broken entries currently shown in History. It does not delete the underlying occurrences, transitions, audits, task rules, or evidence claims. Those local records and history-redaction markers remain for lifecycle recovery and to keep old evidence from being reused.

Erase All Data requires device owner authentication. It first records a local erase intent and asks iOS to release restrictions, then stops okFINE schedules, notifications, and observations; deletes both Gmail Keychain items and all records in the okFINE database; verifies that the local database is empty; and removes derived App Group data. Interrupted cleanup resumes on a later app launch while the erase intent remains active. The app reports completion only after its local inventories are empty.

Erase All Data is logical, application-level deletion. It is not a forensic secure-erasure guarantee. It cannot delete information already held by Apple, Google, a message recipient, a service you used to share a diagnostic export, device or cloud backups outside the app’s control, or records Focused Space receives if you separately contact support. Use the relevant provider or device controls for those copies. Deleting the app is not represented as a substitute for the in-app erase process.

Children

okFINE is intended for adults age 18 and older and is not directed or marketed to children. The product has not implemented age assurance, parental consent, or child-specific privacy features. If you believe a child has sent information to Focused Space through a separate support contact, email us using the address below.

Regional privacy rights

Depending on where you live, privacy law may give you rights concerning personal information, such as rights to know, access, correct, delete, or appeal certain decisions. These rights vary and may have exceptions. Contact us to make a request or ask a question. We may need to verify the request and will respond as required by applicable law.

Because okFINE has no user account managed by its developer and no Focused Space backend, Focused Space ordinarily cannot access or delete the app-managed information stored on your device. Use the in-app controls for that data. Requests concerning information held by Apple, Google, a recipient, or another sharing service should be directed to that party. We can still address information that you separately provided to Focused Space, such as a support email.

Changes to this notice

We may update this notice as okFINE, provider requirements, or applicable law changes. The updated notice will identify its effective date. Where applicable law requires additional notice or consent, we will provide it.

Contact us

Questions or privacy requests about okFINE may be sent to Focused Space, Inc. at support@focused.space.

Please contact us at support@focused.space with any questions or issues!

Please contact us at support@focused.space with any questions or issues!