Privacy Policy

When you use monkeydo, you are trusting me with your information. I understand this is a big responsibility, and I have tried to build the app so that most of your data never leaves your phone at all.

monkeydo is an independent iOS app made and run by one person. I am the data controller for the information described below, and the legal declaration of who I am is at the end of this document. By using monkeydo you agree to this Privacy Policy and to the Terms of Service. If you have any question about it, contact me at support@monkeydo.online.

You can use the entire app, meaning timers, tasks, monkeys and the tree, without an account and without sending me anything. Signing in is needed only for Squads and for syncing across devices. I do not sell your data.

Information monkeydo collects

If you never sign in

Nothing about you leaves your device. Tasks, focus history, monkeys, stardust and settings are stored locally in your phone's app storage. I cannot see any of it, and deleting the app deletes it.

The one thing the app fetches without an account is monkeydo's own announcements, the notices that appear under the bell, which it downloads from Firebase when it opens. That request contains nothing about you. Like any request on the internet, Google's servers see your device's IP address to answer it; I do not receive or store it.

If you sign in with Apple or Google

Your account. Firebase Authentication creates an account identifier when you sign in, so the app knows which data is yours. Apple or Google also provide your email address, used for account recovery and support. monkeydo never writes your email into its own database, and if you use Sign in with Apple's Hide My Email, I only ever see the relay address. I never see or store your password.

Your profile. The username you choose and the profile icon or drawing you pick are stored so your squadmates can see them. If you subscribe to monkeydo+, a single yes/no flag saying so is stored alongside them, because your name is drawn differently to everyone who sees it. That flag is all your squadmates learn — never the price you paid, when you subscribed, or anything Apple told the app about the purchase.

Your progress. Your stardust total, focus seconds, monkeys collected and museum are stored so that leaderboards, squad gardens and your profile work.

Your squads. Which squads you have joined, so the app can show them to you.

Your tasks and lists. Your tasks, lists, folders and sections are stored in your private area so every device you sign in on shows the same ones and a change on one reaches the others within seconds. Each copy carries when it was last changed and a random identifier for the installation that changed it, so your devices can tell which edit is newer. Nobody but you can read them. Tasks from Notion and events on your calendars are not included (see those sections below).

Live status. While a focus session is running, your app reports that you are studying about once a minute, so squadmates see the shared garden fill up. It is deleted when your session ends or your device disconnects.

Your session on your other devices (monkeydo+). With monkeydo+, a focus session you start on one device also appears on your other signed-in devices, which can pause, resume or stop it. While it runs, your private area of the Realtime Database holds its timing, which monkey it is growing, whether it is paused, the kind of device it is running on ("iPhone" or "iPad") and a random identifier for that installation. Only your account can read it, and it is deleted when the session ends.

Chat messages. The emotes and vector drawings you send in squad chat. These are deleted automatically every day. See Squad chat resets every day below.

Purchases. Apple tells the app which purchases you hold, so paid features unlock. I never see your card, name or billing address.

Referrals

At sign-up there is an optional box for a friend's username. It is optional, and leaving it empty changes nothing. If you fill it in, monkeydo stores one small record saying your account was referred by that account, so your friend gets their credit and you both get a free chat emote. Your friend sees only how many people used their code, never who. There are no invite links, no advertising identifiers and nothing that tries to work out where you came from.

Anonymous usage statistics, off unless you turn them on

monkeydo includes Google Analytics for Firebase. It is switched off and collects nothing at all unless you turn on Settings, Privacy, Share anonymous usage. A brand new install starts with it off, and so does a reinstall or a restored backup.

If you do turn it on, this is the complete list of what is sent. There is no free text field anywhere in it:

Nothing else is attached to any of it. monkeydo does not set a Google Analytics user ID, so these events are not joined to your account, username or email. No content is ever included: not a task title, not a list name, not a message, not a squad name, not a drawing. Google assigns a random app-instance identifier so repeat events can be counted as one person rather than many, and it is not linked to you.

Turning the switch off again stops collection and resets that identifier on your device, so nothing that came after can be joined to anything that came before.

Diagnostics

If you leave Apple's "Share with App Developers" setting on, Apple may send me anonymised crash reports. These are aggregated by Apple and are not linked to your account.

Why monkeydo collects data

To provide the service. Your account, profile, progress and squad membership exist so that signing in, syncing across devices and focusing alongside other people work at all.

To keep it working and safe. To fix bugs, prevent cheating and respond to abuse reports.

To improve it. Only through the anonymous statistics described above, and only if you switch them on.

I will ask for your consent before using your information for a purpose not covered by this policy.

Screen Time and Deep Focus

Deep Focus uses Apple's Screen Time APIs, meaning Family Controls, Device Activity and Managed Settings, to show you your screen time numbers and to block apps you choose.

I cannot see any of it, and that is how Apple built the framework rather than a promise about my intentions:

Granting Screen Time access is optional. Deep Focus is the only feature that uses it, and the rest of the app works without it. You can revoke access at any time in iOS Settings, Screen Time.

The one thing monkeydo does store is its own accounting of how long its own shields were active, kept on your device. That is a duration, not a record of what you did.

Blocking during calendar events. If you turn this on, monkeydo reads the start and end times of your events so it can raise the block while one is running. This happens entirely on your device: the times are used to schedule the block and are never sent anywhere. Only the times are used — titles, notes, locations and attendees are not read for this purpose. Turning the setting off stops it immediately.

Calendars

monkeydo can show your existing calendar alongside your tasks, so you are planning around commitments you already have rather than a blank day. Two kinds of calendar can be connected, and both are optional — the app works fully without either.

Apple Calendar (your device's calendars). With your permission, monkeydo reads events from the calendars already set up on your iPhone using Apple's EventKit framework. That includes anything your phone syncs — iCloud, an account you added in iOS Settings, subscribed holiday feeds. All of this happens on your device; it never leaves it.

monkeydo can also add and change events on those calendars, and only in the ways you ask for: an event you create in monkeydo is written to the calendar you pick for it, an edit you make here updates that same event, and deleting it here deletes it there. It never touches an event you did not create or open for editing, and it never writes to a calendar you have not chosen. Calendars that do not accept changes — holidays, birthdays, subscribed feeds, calendars shared with you read-only — are not offered at all.

Google Calendar. If you connect a Google account in Settings ▸ Integrations & Import ▸ Calendar, monkeydo requests these permissions from Google:

How that data is handled. Every request goes directly from your phone to Google. Calendar data is never sent to, processed by, or stored on monkeydo's servers, or on any third party's. Events fetched for the dates on screen are held in memory and discarded. The only calendar-derived thing kept on your device is the id of events monkeydo itself created — without it the app cannot update or delete its own event later — plus your choice of which calendars to show.

Events are not stored in monkeydo's cloud at all. An event you create here lives on the calendar you put it on — your device's, or Google's — and that calendar is what syncs it to your other devices. monkeydo's own cloud backup covers your tasks and lists, not your events.

monkeydo only ever writes EVENTS, never tasks. A task has a list, a star and a completed state that a calendar has nowhere to put, so tasks stay in monkeydo.

Turning it off. Disconnect at any time in Settings ▸ Integrations & Import ▸ Calendar. That stops all access immediately. You can also revoke monkeydo from your Google Account's permissions page. Disconnecting does not delete events monkeydo already added to your calendar — those are yours, on your calendar, and you can remove them there.

monkeydo's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Notion

With monkeydo+, you can connect a Notion workspace in Settings ▸ Integrations & Import ▸ Notion and bring task databases in as lists. It is optional, and nothing happens until you connect.

What monkeydo can see. When you connect, Notion asks you to choose which pages and databases to share, and monkeydo can see only those. For each database you add as a list, monkeydo reads each task's title, its date, whether it is done, and who it is assigned to (so "Only tasks assigned to me" can show just yours). It never requests page content or comments, and when it reads tasks it asks Notion for those columns only. When monkeydo changes a page, Notion's reply contains that whole row; monkeydo keeps the four fields above and discards the rest without storing it.

What monkeydo can change, only when you do it in monkeydo, and only in databases you added: ticking a task marks it done in Notion; renaming or rescheduling it updates its page; a task you add to a Notion list becomes a new page (assigned to you when "Only tasks assigned to me" is on); and deleting one moves its page to Notion's trash, from which you can restore it. monkeydo never deletes anything permanently.

How that data is handled. Your tasks travel directly between your phone and Notion. Notion content is never sent to or stored on monkeydo's servers. Signing in to Notion needs a secret that cannot safely live inside an app, so the sign-in code and the tokens Notion issues pass through monkeydo's server on Google Cloud Functions, which forwards them to Notion and returns the answer. My code keeps nothing and logs none of it. The tokens are then stored in your iPhone's Keychain, on that device only.

On your phone, monkeydo also keeps which databases you added and, for each synced task, the last title, date and done state that both sides agreed on. That is how it tells which side changed. Tasks from Notion are not included in monkeydo's cloud backup; Notion keeps them.

Turning it off. Disconnect at any time in Settings ▸ Integrations & Import ▸ Notion. monkeydo revokes its access and removes the Notion lists from your phone. Your pages stay in Notion. You can also remove monkeydo in Notion under Settings ▸ Connections.

Notifications

monkeydo sends two kinds of notification, and they work differently.

Deep Focus unlock — local, and it never leaves your phone. When you ask to unlock a blocked app, the block screen cannot open monkeydo by itself, so the app asks iOS to post a notification. It is created on your device. No server is involved, no token is sent, and no content leaves the phone.

Squad notifications — these do use a push server. If you are signed in and you allow notifications, monkeydo registers with Apple Push Notification service through Firebase Cloud Messaging and stores the resulting device token in your private area of the database, where only you and my server can read it. That token is an address for your device, not an advertising identifier; it cannot be used to follow you between apps, and it is not shared with anyone.

My server sends you a push when:

Squad chat carries no text, so these notifications say what kind of thing arrived — "someone drew something" — rather than quoting anything.

Turning notifications off in iOS Settings stops the pushes. Signing out deletes the token, and so does deleting your account.

What monkeydo never collects

Worth stating plainly, because many apps in this category collect all of it. monkeydo does not collect:

There are no advertising SDKs, no attribution SDKs and no data brokers in monkeydo, and nothing is sold. monkeydo shows no ads today. If that ever changes, this policy will be updated and you will see a notice in the app before the change takes effect.

Who else touches your data

Each is contractually bound to protect your data to at least the standard described in this policy. I share your data with no one else, and I will never sell it. If that ever changes, I will update this policy and ask for your consent before the change applies to data already collected.

Where your data is processed

Firebase stores this project's data in Google's us-central1 region, in Iowa, United States. If you are in the EEA or the UK, your data is therefore transferred to the United States. Those transfers rely on Google's Standard Contractual Clauses, which Google enters into as my data processor.

Squad chat resets every day

Squad chat is deliberately ephemeral. Every message in every squad is deleted once a day at 00:00 US Eastern time, the same instant for every user in the world, and the app shows you that moment in your own local time. Nothing is archived. Once a day rolls over, that conversation is gone from my systems for good.

How long I keep things

I never keep personal data longer than the purpose that justified collecting it. When a purpose ends, the data is deleted, not hidden.

Data deletion

You can delete your account inside the app at Sidebar, your profile, ..., Delete Account. This erases your profile, tasks, squad memberships and sign-in credential. It is immediate and irreversible, and it also switches usage statistics off and resets the app-instance identifier on your device.

Squad chat you sent may persist in other members' sessions until the next daily reset, and anonymised aggregate statistics that cannot identify you may be retained.

Your rights

Wherever you live, you can:

If you are in the EEA or UK, my legal bases are contract for running the account and squad features you asked for, legitimate interest for keeping the service working and preventing abuse, and consent for anything optional. If you are in California, I do not "sell" or "share" personal information as the CCPA and CPRA define those terms. If you are in Korea, this policy is my notice under PIPA Articles 15 and 17.

I will answer any request at support@monkeydo.online within 30 days, free of charge.

Children

monkeydo is not directed at children under 13, and I do not knowingly collect personal information from them. This is the floor set by the US Children's Online Privacy Protection Act, which applies to me as a US developer. If you believe a child under 13 has created an account, email support@monkeydo.online and I will delete the account and its data promptly.

Users in the EEA and UK: where your national law sets a higher age of digital consent, between 13 and 16 depending on the country, that higher age applies to you.

Security

Data in transit is encrypted with TLS. Access is controlled by Firebase Security Rules so that only you and your squadmates can read your data. No system is perfect. If you find a weakness, please email me rather than exploiting it. I will fix it and credit you if you would like.

If a breach affects your personal data, I will notify affected users and the relevant authority within 72 hours of becoming aware of it, as GDPR Article 33 requires.

Changes to this policy

If I change this policy materially, I will raise the revision date below and show a notice in the app before the change takes effect. Please check back periodically to stay informed.

Data controller and contact

monkeydo is owned and operated by Sophie Hu, an individual developer in the United States, who is the data controller for the purposes of the GDPR and the UK GDPR.

If you have any question about your data, or want to exercise any of the rights above, email support@monkeydo.online.

Date of Last Revision: September 15, 2026