Legal
Tomori Privacy Policy
Effective date: 28 July 2026
Product: Tomori (iOS & Android)
Contact: [email protected]
Tomori is a local-first focus companion. This policy describes what data stays on your device, what you can optionally share, and how backups work.
Data stored on your device
By default, Tomori stores the following only on your device:
- Focus session history (start/end times, duration, completion, optional intention)
- Companion state (selected companion, mood, bond progress)
- Streak progress
- Preferences (theme, reminders, soundscape autoplay, smart break reminders, display name)
This core loop works fully offline.
Optional cloud features (off by default)
You may enable any of the following in Profile. None are required to use Tomori.
| Feature | What is sent | Provider |
|---|---|---|
| Cloud Sync | Focus sessions, companion state, streak record, and a preferences subset (including optional display name) under an anonymous Firebase Auth User ID | Firebase Authentication + Cloud Firestore |
| Usage Analytics | Product interaction events associated with a Firebase Device / installation ID | Google Analytics for Firebase |
| Crash Reports | Crash / diagnostic reports associated with a Crashlytics installation ID | Firebase Crashlytics |
These optional cloud identifiers are treated as linked to your account or device for App Store privacy declarations. They are not used for cross-app tracking or advertising.
You can turn these off at any time. Turning off Cloud Sync stops future syncing but does not delete an existing backup. Delete Cloud Backup & Sign Out removes your anonymous Firebase backup and signs out of cloud sync; local on-device data is kept.
Purchases
Tomori offers one optional in-app purchase, the Atelier Soundscapes unlock. Purchases are processed by Apple or Google — Tomori never sees or receives your payment details.
Purchase status is managed for us by RevenueCat, which receives a purchase identifier and device information in order to record what you own and restore it if you reinstall or change device. This happens only when you interact with purchasing: the billing SDK stays dormant until you open the purchase sheet, restore a purchase, or the app re-checks something you already own. If you never buy anything, it never starts.
If you enable Cloud Sync, your anonymous Firebase User ID is also shared with RevenueCat so a purchase can be restored on your other device. Nothing you own is stored in Cloud Firestore — the billing provider is the only record of it.
Your data controls
- Export My Data saves a readable JSON copy of local focus sessions, companion and streak state, and preferences.
- Erase Local Focus Data removes local focus history, streak, and companion progress. It keeps settings, turns Cloud Sync off, and does not delete a retained cloud backup.
- Delete Cloud Backup & Sign Out deletes cloud-synced records and the current anonymous Firebase account while keeping local data.
These controls are separate so you can choose exactly which copy to keep. Export a copy before deletion if you may need the information later.
Retention and privacy requests
Local data remains until you erase it in Tomori or remove the app and its data. Active Cloud Sync records remain while the anonymous backup exists and are deleted when Delete Cloud Backup & Sign Out succeeds. If disaster-recovery backups are enabled, deleted records may remain in protected backup copies for up to 7 days; those copies are not used for normal syncing or to restore an individually deleted account.
Firebase Analytics and Crashlytics data follows the retention settings configured for those services. To request access, correction, deletion assistance, or portability beyond the in-app controls, email [email protected]. Include your platform and app version, but do not send passwords, authentication tokens, or sensitive session intentions by email. We respond according to applicable privacy law.
Device / OS backups
- Android: Tomori disables Auto Backup (
allowBackup=false) and excludes local database / preference files from backup rules. Cloud recovery requires optional Cloud Sync. - iOS: Tomori marks its Application Support / SwiftData store as excluded from iCloud and iTunes device backups. Cloud recovery requires optional Cloud Sync.
Notifications
If you enable Daily Focus Reminder or Smart Break Reminders, Tomori schedules local notifications on your device. Notification content is generated locally and is not uploaded unless a separate opt-in cloud feature is enabled.
App Check
When Firebase is configured, Tomori uses Firebase App Check (Debug / Play Integrity / App Attest) to help protect backend resources from abuse. App Check tokens are handled by Firebase SDKs.
Children
Tomori is not directed at children under 13 (or the equivalent minimum age in your region).
Changes
We may update this policy as Tomori evolves. Material changes will be reflected in this document and the in-app Privacy Policy link.
Questions? Email [email protected].