LEGAL

PRIVACY
POLICY

LAST UPDATED: 27 APRIL 2026
EFFECTIVE DATE: 01 JUNE 2026

This Privacy Policy explains how TOCKLOG ("we", "our", "us") collects, uses, stores, and protects your personal information when you use the TOCKLOG mobile application, Apple Watch app, and associated services (collectively, the "Service"). By using TOCKLOG, you agree to the practices described in this policy.

1. INFORMATION WE COLLECT

We collect only what is necessary to operate TOCKLOG.

Account data: When you create an account, we collect your display name, email address, and encrypted password (or your Google account identifier if you use Google Sign-In).

Session data: Every focus session you log — including the content description, time window, category tag, and timestamp — is stored on our servers and linked to your account.

Usage data: We collect anonymised app usage events (screen views, feature interactions) to understand how the product is used. This data is never linked to your personal identity.

Device data: We collect your device model, operating system version, and app version for crash reporting and compatibility support. We do not collect your device's advertising identifier.

2. HOW WE USE YOUR INFORMATION

Your data is used exclusively to operate and improve TOCKLOG.

To provide the service: Your session data is processed by our AI engine to generate your daily intelligence reports, productivity scores, and peak-hours analysis.

To communicate with you: We use your email to send transactional messages (account verification, billing receipts, password resets) and, if you opt in, our weekly newsletter.

To improve the product: Anonymised, aggregated usage patterns help us understand which features are most valuable. No personal data is used for this purpose.

We do not use your data to serve advertising. We do not sell, rent, or trade your personal information with any third party for commercial purposes.

3. DATA STORAGE AND SECURITY

Your data is stored on servers located in India and the European Union, provided by Amazon Web Services (AWS). We use industry-standard encryption (AES-256) at rest and TLS 1.3 in transit.

Session content is processed on-device where possible. AI analysis that requires server processing is performed in an isolated compute environment and is not stored in identifiable form beyond what is necessary to generate your report.

Free plan users: Your session data is automatically deleted after 24 hours as described in the plan terms.

TRACK and PRO users: Your session data is retained indefinitely while your account is active, and for 90 days following account deletion (to allow recovery).

4. APPLE WATCH DATA

Data logged on Apple Watch is synced to your iPhone via WatchConnectivity and then to our servers using the same pipeline as iPhone-logged sessions. No additional data categories are collected via the Watch.

Health data is not collected by TOCKLOG. We do not request HealthKit access. Our Watch app operates independently of the Health app.

5. SHARING YOUR INFORMATION

We share your information only in the following limited circumstances:

Service providers: We use a small number of third-party services to operate TOCKLOG (cloud hosting, payment processing, crash analytics). These providers are contractually bound to process your data only on our behalf and in accordance with this policy.

Legal requirements: We will disclose information when required by law, regulation, or valid legal process. We will notify you of such requests where legally permitted.

Business transfers: In the event of a merger, acquisition, or sale of TOCKLOG, your data may be transferred as part of that transaction. We will provide notice before your data becomes subject to a different privacy policy.

We will never sell your personal data.

6. YOUR RIGHTS

You have the following rights with respect to your personal data:

Access: Request a complete export of all personal data we hold about you. Correction: Request correction of inaccurate or incomplete data. Deletion: Request deletion of your account and all associated data. Portability: Request your session data in a structured, machine-readable format. Objection: Object to processing of your data for any purpose other than service delivery.

To exercise these rights, contact us at privacy@tocklog.app. We will respond within 30 days.

7. CHILDREN'S PRIVACY

TOCKLOG is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact privacy@tocklog.app and we will delete it immediately.

8. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. We will notify you of material changes by email and by displaying a notice in the app at least 14 days before the changes take effect. Your continued use of TOCKLOG after the effective date constitutes acceptance of the revised policy.

9. CONTACT

For privacy-related enquiries:

Email: privacy@tocklog.app Response time: Within 30 business days

For general enquiries, see our Contact page.