Last updated: March 2025
This Privacy Policy explains how SteadyFocus ("the App", "we", "us") collects, uses, stores, and protects your information. SteadyFocus is developed and operated by David Hildebrand, trading as Orivent Studios, based in Cape Town, South Africa.
We are committed to protecting your privacy. The core philosophy of SteadyFocus is that your personal habit data belongs to you. By default, your data never leaves your device. Cloud features are opt-in and require explicit sign-in.
By installing and using SteadyFocus, you agree to the practices described in this policy.
We categorise data into two types: data stored locally on your device only, and data that is transmitted to our cloud infrastructure when you use optional features.
The following data is stored exclusively on your device using a local database (Isar). It is never transmitted to any server unless you explicitly use a cloud feature:
This data remains on your device. It is removed when you uninstall the app. We recommend using the backup feature (Plus/Pro) to preserve this data before uninstalling.
When you sign in with Google and use cloud-connected features, the following data is stored in Firebase Firestore, Google's cloud database service:
When you use AI Coach features, a daily summary is written to Firestore containing:
This summary data is used exclusively to generate your personalised AI coaching reports. It is not used for advertising or shared with third parties for marketing purposes.
If you sign in with Google, Firebase Authentication stores your Google UID, email address, and display name. This is managed by Firebase/Google and subject to Google's Privacy Policy.
SteadyFocus uses the following third-party services. Each has its own privacy policy:
We use Firebase Authentication, Firebase Firestore, Firebase Cloud Functions, Firebase App Check, and Firebase Cloud Messaging (FCM). These are Google services subject to the Google Privacy Policy.
Pattern Scout and AI Coach features are powered by Google's Gemini AI model via Firebase Cloud Functions. Your habit summary data is sent to the Gemini API to generate coaching responses. This data is processed server-side and subject to Google's Privacy Policy. We do not use your data to train AI models.
In-app purchases (Plus upgrade, Pro subscription, Scout credit packs) are managed through RevenueCat. RevenueCat processes purchase receipt data and manages entitlements. See RevenueCat's Privacy Policy. No payment card information is processed by us or RevenueCat — payments are handled by Google Play.
The app is distributed via Google Play. Google may collect device information and analytics as part of their platform. See Google's Privacy Policy.
When you use Pattern Scout or AI Coach:
All AI responses are generated with a system instruction that strictly limits the scope to habit guidance only. The AI is hardcoded to refuse medical, financial, clinical, or any professional advice. These guardrails are enforced server-side and cannot be overridden by user input.
All payment processing is handled by Google Play and RevenueCat. We never see or store your payment card information. When you make a purchase:
SteadyFocus is not directed at children under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with data, please contact us at privacy@oriventstudios.com and we will delete it promptly.
You have the following rights regarding your data:
As a South African developer, we comply with the Protection of Personal Information Act (POPIA). Under POPIA:
We implement reasonable technical security measures including:
No system is perfectly secure. If you discover a security vulnerability, please disclose it responsibly by emailing security@oriventstudios.com.
We may update this Privacy Policy as the app evolves. Material changes will be communicated via an in-app notification. The "Last updated" date at the top of this page will always reflect the most recent version. Continued use of the app after changes constitutes acceptance of the updated policy.
For privacy-related questions, data access or deletion requests:
We aim to respond to all privacy requests within 10 business days.