Privacy Policy

App: Prizma: Deep Focus Timer (iOS), bundle ID kz.asset.focus
Developer: Asset Kudaibergenov, individual developer, Kazakhstan
Contact: asset1759@gmail.com
Effective date: 23 August 2026 · Version: 2.1

Terms of Use · Русская версия

I built Prizma alone, and I wrote this policy myself, in plain language. It says exactly what the app does with your information — nothing more and nothing less. Version 2.0 of the app added voice input and task parsing by a language model, and with them the first and only case in which your text leaves the phone; Sections 5 and 6 are about that. If a sentence here is unclear, email me and I will fix the wording.

The short version

1. Who is responsible for your data

The data controller is Asset Kudaibergenov, an individual developer based in Kazakhstan. I am not a company, and there is no team — that is why this document says “I” and not “we”. There is no data protection officer, because an operation of this size is not required to appoint one and I have not appointed one voluntarily.

The only way to reach me about privacy — or anything else — is asset1759@gmail.com. I read every message myself. Please write in English or Russian.

EU representative: I have not appointed a representative in the European Union. The processing done through Prizma is occasional, involves no special categories of data under Article 9 GDPR, involves no profiling, and is unlikely to create a risk to anyone's rights and freedoms — so I rely on the exemption in Article 27(2)(a) GDPR. In plain words: the law lets a developer of this size skip appointing an EU representative, and I am using that option. You can write to me directly. If that ever stops being true, I will appoint a representative and name them here.

2. Data that stays on your device

Almost everything Prizma knows about you never leaves your iPhone:

Where exactly it lives: your history, statistics and settings are JSON files in the app's own sandbox on your device. The blocking state, the selection tokens and the schedule mirrors are in the shared App Group group.kz.asset.focus — a private storage area on your device that only Prizma and its own system extensions can read.

During a session Prizma can also show a Live Activity on the Lock Screen and in the Dynamic Island. It shows the current phase and when it ends, it is generated on your device, and ActivityKit push tokens are not used — nothing about it is sent anywhere.

I have no access to any of it. It is not uploaded, not backed up to a server of mine, not synced through iCloud or CloudKit, and not shared with anyone. I cannot see how long you focus or when you focus, and no session data reaches me.

One honest exception on my side: Apple may show me aggregate, anonymised App Store statistics (installs, active devices, crashes) for people who chose to share analytics with developers in iOS Settings. I never see an individual user in that data, and it comes from Apple, not from the app.

If you have iCloud Backup or an encrypted local backup turned on in iOS, Apple's system backup may include the app's files, the same way it includes files from your other apps. That backup belongs to you and Apple, not to me, and is governed by Apple's Privacy Policy.

3. App blocking, Screen Time and Family Controls

This is the part people ask about most, so here it is in detail.

When you choose which apps, categories or websites to block during a focus session, that choice is made inside a system screen provided by Apple (the Family Activity Picker). Prizma does not draw that list and does not read it.

What Prizma receives back from iOS is a set of opaque system tokens — meaningless identifiers that only the operating system can interpret. Prizma can ask iOS to “shield the things behind these tokens” and iOS does it. Prizma cannot turn a token back into an app name, a bundle identifier, an icon, a website or a category. In other words:

The single thing the app does learn about your selection is how many items are in it — how many apps, categories and websites you ticked — so it can show you that number on screen. What those items are remains unknown to the app.

This is not a promise I am asking you to take on faith — it is how Apple's Family Controls framework is designed, and it is one reason the framework requires a special permission from Apple to use at all.

Those tokens are stored on your device only, in the App Group named above. They are never transmitted anywhere. I do not sell, use or disclose to any third party any data related to app blocking or Screen Time, for any purpose.

To use blocking, iOS asks you for Screen Time permission. You grant it to the system, you can withdraw it at any time in Settings → Screen Time, and withdrawing it simply turns blocking off — the rest of the timer keeps working.

4. Purchases and subscriptions

Prizma offers optional paid plans: auto-renewing Monthly and Yearly subscriptions and a one-time Lifetime purchase. Current prices, trial lengths and currency are shown on the purchase screen in the app and on the App Store product page — they differ by country, so this document deliberately does not repeat them.

Payment itself is handled entirely by Apple through the App Store. I never see and never receive your card number, your billing address, your Apple Account email or your name. Apple's handling of your payment is covered by Apple's Privacy Policy.

RevenueCat

To check whether a purchase is valid, to unlock Pro features, and to let you restore purchases on a new device, the app uses RevenueCat, Inc. (United States) as a service provider. RevenueCat acts as my data processor: it processes this information on my instructions and under a data processing agreement, and it is not allowed to use it for its own purposes.

This is the only network request Prizma makes. What RevenueCat receives:

WhatWhy
An anonymous App User ID, generated at random by the SDK on your deviceTo tie a purchase to an installation without knowing who you are
Your Apple receipt / transaction dataTo verify the purchase is genuine and still active, and to restore it
Device type and iOS versionTechnical processing and fraud prevention
Country, locale and currency codeTo show and record the correct price
Your IP address, seen by RevenueCat when the app connectsUnavoidable for any network request; used to determine the storefront country and to prevent fraud. I never see it and never store it
The time the app was last used with an active purchaseSubscription status and aggregate subscription and revenue statistics

What RevenueCat does not receive from Prizma: your name, your email address, your Apple Account, your advertising identifier (IDFA) or vendor identifier (IDFV) — the app does not enable the option that would collect those — your location, your focus sessions, your statistics, or anything at all about app blocking.

Because the ID is anonymous and there is no account system, neither I nor RevenueCat can connect a purchase record to your identity as a person.

RevenueCat's own documents: Privacy Policy and Data Processing Addendum.

5. Voice input: microphone and speech recognition

You can dictate a task instead of typing it. For that the app asks for two permissions: the microphone and speech recognition. Both are requested the first time you tap the microphone, not in advance, and without them dictation simply does not work. Nothing else in the app is affected.

The audio does not leave your iPhone. Speech is transcribed by the operating system itself, on the device. The app creates no recording file, stores no audio and sends none anywhere — not to me, not to anyone else.

One qualification matters enough to spell out. On-device recognition is not available for every language: the offline model is downloaded by the system, and until then it is not there. In that situation iOS is willing to send the audio to Apple's servers — and to prevent that, the app checks in advance whether the offline model for your language is installed, and refuses to start dictation if it is not. You will see a message saying on-device recognition is unavailable, and the keyboard is what is left. This is a deliberate choice: better to withhold a feature than to deliver it at the cost of a broken promise.

What happens to the transcribed text is the next section: that is no longer audio but task text, and different rules apply to it.

6. Task parsing by a language model

This is the only feature in the app that sends your text off the device, so it is described in full.

The feature is off by default and available only with a subscription. You turn it on by hand in the More tab. While it is off, nothing described below happens, and tasks are parsed by rules on the phone itself.

When it is on and you add a task, the app sends a request to my server. The request contains exactly three fields:

WhatWhy
The task text — what you typed or dictatedThat is what has to be parsed into a title, a note, a due time and steps
The name of the language (for example, "English")So that the answer comes back in the same language
The same anonymous identifier used for purchasesTo check the subscription and count the daily request limit

No name, no email, no statistics, no other tasks and no other app content are included.

Where the text goes. The server is a function on Cloudflare that belongs to me. It passes your text to OpenAI (OpenAI, L.L.C., United States), model gpt-4o-mini, receives the parsed task and returns it to the app. The identifier is not passed to OpenAI: only the text and the language name go there.

What is stored. On my server the task text is not saved and not written to any log — it exists only for as long as the request is being handled. Only two housekeeping values are stored, and both are keyed to the anonymous identifier rather than to the text:

What OpenAI does with the text is governed by its developer terms, not by me. As of this revision, OpenAI states that data sent through the API is retained for a limited period for abuse monitoring and is not used to train its models. See the OpenAI privacy policy and the API data usage policies.

In relation to Cloudflare and OpenAI I am the controller and they are processors: they act on my instructions.

If you would rather no task text left your device at all — do not turn parsing on, or turn it off in the More tab. The app works fully without it: tasks, due times and steps can be entered by hand, and the app recognises a due time inside what you said on its own, on the device.

7. Notifications

Prizma can send you three kinds of notification, and all of them are local notifications scheduled on your own device:

There is no push server, the app is not registered for remote notifications, and it has no ability to send you a message from the outside. You can turn notifications off in Settings → Notifications → Prizma.

8. What Prizma does not do

Stated plainly, so there is no ambiguity:

9. Legal basis for processing (GDPR)

If you are in the European Economic Area, the United Kingdom or Switzerland, two things are processed on my behalf. First, the purchase data described in Section 4. Second, the task text and the anonymous identifier when a task is parsed, as described in Section 6 — and only if you have turned that feature on. The legal basis for both is performance of a contract — Article 6(1)(b) GDPR: without validating your receipt I cannot give you the Pro features you paid for or restore them later.

Providing that data is a contractual requirement: without it a paid subscription cannot be validated, activated or restored. You are under no obligation to provide it — the free timer, your statistics and the free daily sessions work without any purchase.

There is no processing based on consent and none based on legitimate interests, because there is no analytics, marketing or advertising. That is also why Prizma shows you no cookie or consent banner — there is nothing to consent to. No special categories of data under Article 9 GDPR are collected, and there is no automated decision-making or profiling.

10. International transfers

RevenueCat is based in the United States and stores data in data centres in the United States. When you buy or restore a subscription from the EEA, the UK or Switzerland, that purchase data is transferred to the United States. The transfer is covered by the Standard Contractual Clauses made available under RevenueCat's Data Processing Addendum. Data is encrypted in transit.

Task text sent for parsing (Section 6) passes through Cloudflare (Cloudflare, Inc., United States) and is forwarded to OpenAI (OpenAI, L.L.C., United States). For transfers out of the EEA, the UK and Switzerland both companies rely on the European Commission's Standard Contractual Clauses, included in their data processing agreements. The transfer is encrypted.

I am located in Kazakhstan, which is not covered by an EU adequacy decision. In practice this means the following: there is no store of your records on my side, and the little that does settle on my server — a housekeeping counter and a subscription flag, both keyed to the anonymous identifier — lives for hours, not years. The text of your tasks does not settle there at all. Beyond that, the only personal data I would ever hold about you is whatever you choose to write to me in an email.

11. How long data is kept, and how to delete it

Your subscription itself is managed by Apple. To cancel it, open Settings → your name → Subscriptions on your iPhone. Deleting the app does not cancel a subscription.

12. Your rights and how to use them

Depending on where you live, you have the right to: know what is processed and get a copy of it; correct inaccurate data; have data erased; restrict processing; object to processing; receive your data in a portable format; withdraw consent where processing is based on consent (without affecting what was lawful before); and lodge a complaint with the data protection authority in your country of residence, work or the place of the alleged infringement.

To use any of them, email asset1759@gmail.com. It is free, and I will reply within one month. If a request is complex, I may extend that period and will tell you why.

One honest limitation. Because there are no accounts, I have no way to identify you. Data on your device is only reachable by you — I cannot access it, produce it or delete it, and you can delete all of it yourself by deleting the app. For purchase data, I need something to look the record up by: please include the date of purchase and the Apple transaction ID from the receipt email Apple sent you. Without that I genuinely cannot find your record, and I will not ask you for identity documents to compensate.

13. Notice for California residents (CCPA / CPRA)

Whether or not the CCPA applies to a one-person developer of this size, here are the disclosures it asks for.

Category of personal informationDetails
IdentifiersAn anonymous, randomly generated App User ID. No name, email, account or device advertising ID.
Commercial informationRecords of subscriptions and purchases of Prizma Pro.
Internet or other network activityThe IP address of the connection, seen by RevenueCat when the app validates or restores a purchase.

You have the right to know, access, correct and delete your personal information, to opt out of sale and sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights. Submit requests to asset1759@gmail.com. An authorised agent may submit a request on your behalf, with proof of authorisation. There is no toll-free number, as I operate exclusively online.

14. Brazil (LGPD) and Kazakhstan

If you are in Brazil, the LGPD gives you the right to confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary data, portability, information about who your data is shared with, and the right to complain to the ANPD. Everything described in this policy applies to you, and every one of those rights is exercised through the same address: asset1759@gmail.com. I am the controller; there is no separate data protection officer.

As a controller resident in Kazakhstan, I also process data in line with the Law of the Republic of Kazakhstan “On Personal Data and Its Protection”. In practice this is simple: I hold no database of users, and the only personal data I could ever hold is an email you send me.

15. Children

Prizma is a productivity tool for people who want to concentrate. It is not designed for, marketed to, or directed at children, and it is not a parental-control product.

You must be at least 13 years old to use Prizma. If the country you live in sets a higher age for digital consent — in the European Union this is between 13 and 16 depending on the country — then that higher age applies to you.

I do not knowingly collect personal information from children under 13. The app's design makes this straightforward: there are no accounts, no profiles, no chats, no analytics and no advertising, and the only things that ever leave the device are an anonymous purchase record and, if parsing is switched on, the text of a task — a feature that is off by default and requires a subscription.

If you are a parent or guardian and believe a child has provided personal information through the app, write to asset1759@gmail.com and I will delete anything I can identify.

16. Security

Data on your device is protected by iOS: the app sandbox, the App Group container, device encryption and your device passcode. Purchase data travelling to RevenueCat, and task text travelling to my parsing server, are both sent over encrypted TLS connections.

The strongest protection here is structural rather than technical: I hold no database of your records, so there is no central store of your information that could be breached, leaked or subpoenaed. What does settle on my server is a housekeeping counter and a subscription flag, living for hours; the text of your tasks does not settle there at all. Perfect security does not exist, though — if I ever learn of an incident affecting your data, I will report it in the manner and within the time limits required by the applicable law.

17. Third parties and equal protection

There are three third parties: RevenueCat, Inc. for purchases and subscriptions; Cloudflare, Inc., which hosts my task-parsing server; and OpenAI, L.L.C., the language model that performs the parsing. The latter two receive data only if you have switched task parsing on.

RevenueCat, Inc. receives purchase data. RevenueCat is contractually bound, through its Data Processing Addendum, to process that data solely on my instructions and to provide protection for user data that is the same as or equal to the protection described in this policy, including under the GDPR. Payment is handled by Apple under its own terms. I do not use analytics tools, advertising networks or any other third-party SDKs that collect data, and I will not pass your data to advertisers or data brokers.

18. Changes to this policy

If the app changes in a way that affects your privacy, I will update this page and change the effective date at the top. Material changes will also be pointed out inside the app or in the release notes. The current version is always the one published here.

19. Contact

Asset Kudaibergenov, individual developer
Kazakhstan
asset1759@gmail.com

Questions, privacy requests, complaints and corrections all go to the same address, and they all reach the same person: me.