Privacy Policy
When you use monkeydo, you are trusting me with your information. I understand this is a big responsibility, and I have tried to build the app so that most of your data never leaves your phone at all.
monkeydo is an independent iOS app made and run by one person. I am the data controller for the information described below, and the legal declaration of who I am is at the end of this document. By using monkeydo you agree to this Privacy Policy and to the Terms of Service. If you have any question about it, contact me at support@monkeydo.online.
You can use the entire app, meaning timers, tasks, monkeys and the tree, without an account and without sending me anything. Signing in is needed only for Squads and for syncing across devices. I do not sell your data.
Information monkeydo collects
If you never sign in
Nothing about you leaves your device. Tasks, focus history, monkeys, stardust and settings are stored locally in your phone's app storage. I cannot see any of it, and deleting the app deletes it.
The one thing the app fetches without an account is monkeydo's own announcements, the notices that appear under the bell, which it downloads from Firebase when it opens. That request contains nothing about you. Like any request on the internet, Google's servers see your device's IP address to answer it; I do not receive or store it.
If you sign in with Apple or Google
Your account. Firebase Authentication creates an account identifier when you sign in, so the app knows which data is yours. Apple or Google also provide your email address, used for account recovery and support. monkeydo never writes your email into its own database, and if you use Sign in with Apple's Hide My Email, I only ever see the relay address. I never see or store your password.
Your profile. The username you choose and the profile icon or drawing you pick are stored so your squadmates can see them. If you subscribe to monkeydo+, a single yes/no flag saying so is stored alongside them, because your name is drawn differently to everyone who sees it. That flag is all your squadmates learn — never the price you paid, when you subscribed, or anything Apple told the app about the purchase.
Your progress. Your stardust total, focus seconds, monkeys collected and museum are stored so that leaderboards, squad gardens and your profile work.
Your squads. Which squads you have joined, so the app can show them to you.
Your tasks and lists. Your tasks, lists, folders and sections are stored in your private area so every device you sign in on shows the same ones and a change on one reaches the others within seconds. Each copy carries when it was last changed and a random identifier for the installation that changed it, so your devices can tell which edit is newer. Nobody but you can read them. Tasks from Notion and events on your calendars are not included (see those sections below).
Live status. While a focus session is running, your app reports that you are studying about once a minute, so squadmates see the shared garden fill up. It is deleted when your session ends or your device disconnects.
Your session on your other devices (monkeydo+). With monkeydo+, a focus session you start on one device also appears on your other signed-in devices, which can pause, resume or stop it. While it runs, your private area of the Realtime Database holds its timing, which monkey it is growing, whether it is paused, the kind of device it is running on ("iPhone" or "iPad") and a random identifier for that installation. Only your account can read it, and it is deleted when the session ends.
Chat messages. The emotes and vector drawings you send in squad chat. These are deleted automatically every day. See Squad chat resets every day below.
Purchases. Apple tells the app which purchases you hold, so paid features unlock. I never see your card, name or billing address.
Referrals
At sign-up there is an optional box for a friend's username. It is optional, and leaving it empty changes nothing. If you fill it in, monkeydo stores one small record saying your account was referred by that account, so your friend gets their credit and you both get a free chat emote. Your friend sees only how many people used their code, never who. There are no invite links, no advertising identifiers and nothing that tries to work out where you came from.
Anonymous usage statistics, off unless you turn them on
monkeydo includes Google Analytics for Firebase. It is switched off and collects nothing at all unless you turn on Settings, Privacy, Share anonymous usage. A brand new install starts with it off, and so does a reinstall or a restored backup.
If you do turn it on, this is the complete list of what is sent. There is no free text field anywhere in it:
- a focus session finished, recorded as one of four length bands (under 15 min, 15 to 25, 25 to 60, over 60) and whether it was a quick start or a pomodoro. Never the exact duration;
- two monkeys merged, and the tier that was created;
- a card was pulled, and which of the three tiers it was;
- your monthly recap was opened or shared, and how many slides you looked at;
- a monkeydo+ page was shown or a subscription bought, and which limit you hit;
- you were placed in an A/B test, with the test's name and which version you saw.
Nothing else is attached to any of it. monkeydo does not set a Google Analytics user ID, so these events are not joined to your account, username or email. No content is ever included: not a task title, not a list name, not a message, not a squad name, not a drawing. Google assigns a random app-instance identifier so repeat events can be counted as one person rather than many, and it is not linked to you.
Turning the switch off again stops collection and resets that identifier on your device, so nothing that came after can be joined to anything that came before.
Diagnostics
If you leave Apple's "Share with App Developers" setting on, Apple may send me anonymised crash reports. These are aggregated by Apple and are not linked to your account.
Why monkeydo collects data
To provide the service. Your account, profile, progress and squad membership exist so that signing in, syncing across devices and focusing alongside other people work at all.
To keep it working and safe. To fix bugs, prevent cheating and respond to abuse reports.
To improve it. Only through the anonymous statistics described above, and only if you switch them on.
I will ask for your consent before using your information for a purpose not covered by this policy.
Screen Time and Deep Focus
Deep Focus uses Apple's Screen Time APIs, meaning Family Controls, Device Activity and Managed Settings, to show you your screen time numbers and to block apps you choose.
I cannot see any of it, and that is how Apple built the framework rather than a promise about my intentions:
- when you pick apps to block, iOS hands the app opaque tokens, not app names or bundle IDs, so I cannot tell which apps you chose. The icons you see are drawn by iOS from those tokens;
- your screen time figures are rendered by a separate system extension that runs outside the app, in a sandbox with no network access and no way to hand data back;
- none of it is transmitted anywhere. It never touches Firebase and it never leaves your device.
Granting Screen Time access is optional. Deep Focus is the only feature that uses it, and the rest of the app works without it. You can revoke access at any time in iOS Settings, Screen Time.
The one thing monkeydo does store is its own accounting of how long its own shields were active, kept on your device. That is a duration, not a record of what you did.
Blocking during calendar events. If you turn this on, monkeydo reads the start and end times of your events so it can raise the block while one is running. This happens entirely on your device: the times are used to schedule the block and are never sent anywhere. Only the times are used — titles, notes, locations and attendees are not read for this purpose. Turning the setting off stops it immediately.
Calendars
monkeydo can show your existing calendar alongside your tasks, so you are planning around commitments you already have rather than a blank day. Two kinds of calendar can be connected, and both are optional — the app works fully without either.
Apple Calendar (your device's calendars). With your permission, monkeydo reads events from the calendars already set up on your iPhone using Apple's EventKit framework. That includes anything your phone syncs — iCloud, an account you added in iOS Settings, subscribed holiday feeds. All of this happens on your device; it never leaves it.
monkeydo can also add and change events on those calendars, and only in the ways you ask for: an event you create in monkeydo is written to the calendar you pick for it, an edit you make here updates that same event, and deleting it here deletes it there. It never touches an event you did not create or open for editing, and it never writes to a calendar you have not chosen. Calendars that do not accept changes — holidays, birthdays, subscribed feeds, calendars shared with you read-only — are not offered at all.
Google Calendar. If you connect a Google account in Settings ▸ Integrations & Import ▸ Calendar, monkeydo requests these permissions from Google:
- See and edit events on your calendars (
.../auth/calendar.events). Reading lets your Google events appear on the monkeydo timetable. Writing lets an event you create in monkeydo appear on your real calendar, and lets an edit or deletion you make in monkeydo reach the copy there. - See the list of calendars you have (
.../auth/calendar.calendarlist.readonly). This is read-only, and it exists only so the app can show you your calendars by name and let you choose which to display.
How that data is handled. Every request goes directly from your phone to Google. Calendar data is never sent to, processed by, or stored on monkeydo's servers, or on any third party's. Events fetched for the dates on screen are held in memory and discarded. The only calendar-derived thing kept on your device is the id of events monkeydo itself created — without it the app cannot update or delete its own event later — plus your choice of which calendars to show.
Events are not stored in monkeydo's cloud at all. An event you create here lives on the calendar you put it on — your device's, or Google's — and that calendar is what syncs it to your other devices. monkeydo's own cloud backup covers your tasks and lists, not your events.
monkeydo only ever writes EVENTS, never tasks. A task has a list, a star and a completed state that a calendar has nowhere to put, so tasks stay in monkeydo.
Turning it off. Disconnect at any time in Settings ▸ Integrations & Import ▸ Calendar. That stops all access immediately. You can also revoke monkeydo from your Google Account's permissions page. Disconnecting does not delete events monkeydo already added to your calendar — those are yours, on your calendar, and you can remove them there.
monkeydo's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Notion
With monkeydo+, you can connect a Notion workspace in Settings ▸ Integrations & Import ▸ Notion and bring task databases in as lists. It is optional, and nothing happens until you connect.
What monkeydo can see. When you connect, Notion asks you to choose which pages and databases to share, and monkeydo can see only those. For each database you add as a list, monkeydo reads each task's title, its date, whether it is done, and who it is assigned to (so "Only tasks assigned to me" can show just yours). It never requests page content or comments, and when it reads tasks it asks Notion for those columns only. When monkeydo changes a page, Notion's reply contains that whole row; monkeydo keeps the four fields above and discards the rest without storing it.
What monkeydo can change, only when you do it in monkeydo, and only in databases you added: ticking a task marks it done in Notion; renaming or rescheduling it updates its page; a task you add to a Notion list becomes a new page (assigned to you when "Only tasks assigned to me" is on); and deleting one moves its page to Notion's trash, from which you can restore it. monkeydo never deletes anything permanently.
How that data is handled. Your tasks travel directly between your phone and Notion. Notion content is never sent to or stored on monkeydo's servers. Signing in to Notion needs a secret that cannot safely live inside an app, so the sign-in code and the tokens Notion issues pass through monkeydo's server on Google Cloud Functions, which forwards them to Notion and returns the answer. My code keeps nothing and logs none of it. The tokens are then stored in your iPhone's Keychain, on that device only.
On your phone, monkeydo also keeps which databases you added and, for each synced task, the last title, date and done state that both sides agreed on. That is how it tells which side changed. Tasks from Notion are not included in monkeydo's cloud backup; Notion keeps them.
Turning it off. Disconnect at any time in Settings ▸ Integrations & Import ▸ Notion. monkeydo revokes its access and removes the Notion lists from your phone. Your pages stay in Notion. You can also remove monkeydo in Notion under Settings ▸ Connections.
Notifications
monkeydo sends two kinds of notification, and they work differently.
Deep Focus unlock — local, and it never leaves your phone. When you ask to unlock a blocked app, the block screen cannot open monkeydo by itself, so the app asks iOS to post a notification. It is created on your device. No server is involved, no token is sent, and no content leaves the phone.
Squad notifications — these do use a push server. If you are signed in and you allow notifications, monkeydo registers with Apple Push Notification service through Firebase Cloud Messaging and stores the resulting device token in your private area of the database, where only you and my server can read it. That token is an address for your device, not an advertising identifier; it cannot be used to follow you between apps, and it is not shared with anyone.
My server sends you a push when:
- a squadmate sends an emote or a drawing to a squad you are in;
- a squad you are in is disbanded;
- you are added to or removed from a squad.
Squad chat carries no text, so these notifications say what kind of thing arrived — "someone drew something" — rather than quoting anything.
Turning notifications off in iOS Settings stops the pushes. Signing out deletes the token, and so does deleting your account.
What monkeydo never collects
Worth stating plainly, because many apps in this category collect all of it. monkeydo does not collect:
- your location, at any precision;
- your contacts, photos, camera or microphone;
- your calendar events. If you connect a calendar, monkeydo reads your events on your device to draw them on the timetable, and writes back the events you ask it to — but it never collects them: they are not sent to my servers or to anyone else's. See Calendars above;
- your age, gender, ethnicity, sexual orientation, or any health information;
- biometric information;
- your browsing or search history, or network activity;
- advertising identifiers. Google's ad storage, ad user data and ad personalisation consent flags are all set to denied in the app's code, and monkeydo asks for no tracking permission, so it never shows Apple's App Tracking Transparency prompt;
- your screens, taps or session recordings. There is no screen view tracking, no heatmap and no session replay;
- which apps you block or how much you use them. See Screen Time and Deep Focus above.
There are no advertising SDKs, no attribution SDKs and no data brokers in monkeydo, and nothing is sold. monkeydo shows no ads today. If that ever changes, this policy will be updated and you will see a notice in the app before the change takes effect.
Who else touches your data
- Google (Firebase Authentication, Cloud Firestore, Realtime Database) hosts your account, profile, progress, squads, presence and chat, and serves the in-app announcements. See firebase.google.com/support/privacy.
- Google (Google Sign-In) handles sign-in, if you choose Google. See policies.google.com/privacy.
- Google (Google Analytics for Firebase) receives the counted events listed above, and only if you switch statistics on.
- Apple (Sign in with Apple, In-App Purchase) handles sign-in and payments. See apple.com/legal/privacy.
- Apple (Screen Time APIs) is on-device only. No data reaches Apple or me.
- Notion (Notion Labs, Inc.) holds the tasks in any database you connect, and receives the changes described under Notion above. See notion.com/notion/privacy.
- Google (Cloud Functions) relays Notion sign-in codes and tokens, if you connect Notion. My code on it stores none of them.
Each is contractually bound to protect your data to at least the standard described in this policy. I share your data with no one else, and I will never sell it. If that ever changes, I will update this policy and ask for your consent before the change applies to data already collected.
Where your data is processed
Firebase stores this project's data in Google's us-central1 region, in Iowa, United States. If you are in the EEA or the UK, your data is therefore transferred to the United States. Those transfers rely on Google's Standard Contractual Clauses, which Google enters into as my data processor.
Squad chat resets every day
Squad chat is deliberately ephemeral. Every message in every squad is deleted once a day at 00:00 US Eastern time, the same instant for every user in the world, and the app shows you that moment in your own local time. Nothing is archived. Once a day rolls over, that conversation is gone from my systems for good.
How long I keep things
- Squad chat: until the next daily reset, so at most 24 hours.
- Live presence: until your session ends or your device disconnects.
- A session shown on your other devices (monkeydo+): until the session ends.
- Profile, stardust, monkeys, squad membership: until you delete your account.
- Referral records: kept after you delete your account, with your username erased from them. Deleting the record itself would silently take a credit back from the friend who earned it when you joined. What remains is an identifier pointing at a profile that no longer exists.
- Purchase records: held by Apple under Apple's own retention rules.
- Anonymous usage statistics: Google's shortest retention setting, 2 months, after which the rows are deleted automatically. Because no user ID is attached, they are not linked to your account and cannot be singled out afterwards.
- Everything, after you ask for deletion: erased within 30 days, except where the law requires me to keep it.
I never keep personal data longer than the purpose that justified collecting it. When a purpose ends, the data is deleted, not hidden.
Data deletion
You can delete your account inside the app at Sidebar, your profile, ..., Delete Account. This erases your profile, tasks, squad memberships and sign-in credential. It is immediate and irreversible, and it also switches usage statistics off and resets the app-instance identifier on your device.
Squad chat you sent may persist in other members' sessions until the next daily reset, and anonymised aggregate statistics that cannot identify you may be retained.
Your rights
Wherever you live, you can:
- see what I hold about you;
- correct it;
- delete it, in the app, as described above;
- export it. Email me and I will send you a machine-readable copy;
- withdraw consent for usage statistics at Settings, Privacy, Share anonymous usage, which is the same switch that granted it. For everything else, by deleting your account, or by signing out to stop all further syncing;
- complain to your local data protection authority.
If you are in the EEA or UK, my legal bases are contract for running the account and squad features you asked for, legitimate interest for keeping the service working and preventing abuse, and consent for anything optional. If you are in California, I do not "sell" or "share" personal information as the CCPA and CPRA define those terms. If you are in Korea, this policy is my notice under PIPA Articles 15 and 17.
I will answer any request at support@monkeydo.online within 30 days, free of charge.
Children
monkeydo is not directed at children under 13, and I do not knowingly collect personal information from them. This is the floor set by the US Children's Online Privacy Protection Act, which applies to me as a US developer. If you believe a child under 13 has created an account, email support@monkeydo.online and I will delete the account and its data promptly.
Users in the EEA and UK: where your national law sets a higher age of digital consent, between 13 and 16 depending on the country, that higher age applies to you.
Security
Data in transit is encrypted with TLS. Access is controlled by Firebase Security Rules so that only you and your squadmates can read your data. No system is perfect. If you find a weakness, please email me rather than exploiting it. I will fix it and credit you if you would like.
If a breach affects your personal data, I will notify affected users and the relevant authority within 72 hours of becoming aware of it, as GDPR Article 33 requires.
Changes to this policy
If I change this policy materially, I will raise the revision date below and show a notice in the app before the change takes effect. Please check back periodically to stay informed.
Data controller and contact
monkeydo is owned and operated by Sophie Hu, an individual developer in the United States, who is the data controller for the purposes of the GDPR and the UK GDPR.
If you have any question about your data, or want to exercise any of the rights above, email support@monkeydo.online.
Date of Last Revision: September 15, 2026