Privacy Policy
Last updated
The short version
- This website has no analytics, no tracking scripts, no forms and no cookies. Visiting it leaves nothing behind but a standard server log.
- Your tasks, timers and focus stats stay on your device. We never receive them and could not read them if we wanted to.
- The app sends anonymous usage and crash data to Google Firebase so we can see which features get used and fix crashes. That is separate from your task content.
- No account is required, so we hold no name, email or password for you.
- We do not sell your data, show ads, or build advertising profiles. Ever.
1. Who we are and what this covers
Don't Forget is an ADHD focus timer built by Francesco Leoni, an independent app developer. This policy explains what happens to your information when you use either of the following:
- This website — dontforget.francescoleoni.com, including the blog.
- The Don't Forget app — for iPhone, iPad, Mac and Apple Vision Pro.
The two are very different in how much data they involve, so we keep them clearly separated throughout this policy.
2. Information we collect
2.1 When you visit this website
We collect nothing directly. This site is a set of static pages. It runs no analytics, contains no contact or signup forms, sets no cookies, and stores nothing in your browser.
The site is hosted by Netlify. Like every web host, Netlify records standard server request logs when a page is served. These typically include your IP address, browser type and version, the page requested, and the date and time. We use these only in aggregate, and only to keep the site running. We do not use them to identify individual visitors.
The fonts used on this site are served from our own domain, not from Google Fonts, so loading a page makes no request to Google.
2.2 When you use the app
Your task content never leaves your device. It stays on your device. The tasks you write, the timers you run, your focus sessions and your progress statistics are stored locally on your device. We have no server holding them and no way to read them.
Separately from that, the app sends limited diagnostic and usage information to Google Firebase:
- Firebase Analytics — anonymous usage events, such as which screens are opened and which features are used, along with general device information like device model, operating system version, language, and an app-instance identifier. Firebase also derives an approximate region from your IP address. This tells us which features people actually use. It does not tell us what your tasks say.
- Firebase Crashlytics — crash reports, which include the technical stack trace, the app version, and the device state at the moment of the crash. These let us find and fix bugs.
2.3 When you contact us
If you email us, we receive your email address and whatever you choose to put in the message. We use it to answer you, and we keep the correspondence only as long as it is useful for support history.
2.4 What we never collect
- No account, username or password — the app does not have accounts.
- No name, postal address or phone number.
- No payment card details (see the third-party section).
- No precise GPS location.
- No contacts, photos, microphone or camera access.
- No content of your tasks, notes, timers or statistics.
3. How we use collected information
We use the limited information described above only to:
- Deliver and maintain the website and the app.
- Understand, in aggregate, which features are useful so we can decide what to build and improve.
- Diagnose crashes and fix bugs.
- Respond to you when you get in touch.
- Meet legal obligations where they apply to us.
We do not sell or rent your data, share it with data brokers, serve advertising, build advertising or marketing profiles, or attempt to identify individual users from analytics.
4. Cookies and tracking technologies
This website sets no cookies. It also uses no local storage, no session storage, no tracking pixels, no fingerprinting and no advertising tags. That is why you will not see a cookie consent banner here — there is nothing to consent to.
The blog has share buttons for X and LinkedIn. These are ordinary links: nothing is loaded from those companies unless you click, and no tracking script from them runs on the page.
The app does not use cookies. Firebase identifies an installation using an app-instance identifier rather than a cookie, as described above. This identifier is reset if you delete and reinstall the app.
5. Third-party services and data sharing
We keep the number of third parties deliberately small. These are all of them:
| Service | Used for | What it involves |
|---|---|---|
| Google Firebase | App analytics and crash reporting | Anonymous usage events, device model and OS, app-instance ID, approximate region, crash stack traces |
| Apple | App distribution and any purchases | Apple handles downloads and payments under its own policy. We receive only anonymous sales and download reports, never your payment details. |
| Netlify | Website hosting | Standard server request logs, including IP address and browser type |
We may also disclose information if the law requires it, for example in response to a valid legal request, or to protect our rights or the safety of others. If the app or website were ever transferred to a new owner, this policy would travel with it and you would be told before anything changed.
The site links out to places like the App Store, our other app at getbraindump.com, and our social profiles. Once you follow a link, you are on someone else's site under their privacy policy, not this one.
6. Data storage and security
Your task data is stored on your own device and is protected by your operating system's built-in protections, including your device passcode and disk encryption. Because it never reaches us, it cannot be exposed by a breach on our side.
Analytics and crash data are held on Google's infrastructure under Google's security practices. Access to the Firebase console is restricted to the developer and protected by a Google account with two-factor authentication.
This website is served over HTTPS. No method of transmission or storage is completely secure, so while we take reasonable measures to protect information, we cannot guarantee absolute security.
7. Data retention
- On-device app data — kept until you delete it in the app or remove the app. Deleting the app removes it from your device.
- Firebase Analytics data — retained according to the retention period set in our Firebase console.
- Crashlytics reports — retained under Google's standard Crashlytics retention schedule, then deleted automatically.
- Netlify server logs — retained short-term by Netlify under its own log retention practice.
- Support email — kept while it remains useful for support history, then deleted.
8. International data transfers
We are based in the European Union. Google, Apple and Netlify are United States companies and may process the data described above on servers outside the EU, including in the United States. These providers rely on their own safeguards for such transfers, such as the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Their privacy policies, linked in the table above, describe those safeguards in detail.
9. Your privacy rights and how to exercise them
Because we hold almost nothing about you, most of your control is immediate and direct:
- Delete your data — delete individual tasks in the app, or remove the app to erase all of it from your device. No request to us is needed.
- Ask us anything about your data — email leoni.francesco98@gmail.com and we will respond within 30 days.
Depending on where you live, you may have additional rights under laws such as the EU and UK GDPR or the California Consumer Privacy Act. These generally include the right to access the personal data held about you, to have it corrected or deleted, to object to or restrict its processing, to receive it in a portable format, and to withdraw consent. Californian residents also have the right not to be discriminated against for exercising these rights; note that we do not sell personal information, so there is nothing to opt out of.
To exercise any of these, email us at leoni.francesco98@gmail.com. Please keep in mind that we cannot identify you from analytics data, so for some requests there may genuinely be nothing on our side to retrieve. If you are in the EEA or the UK and are unhappy with how we have handled a request, you have the right to complain to your national data protection authority.
10. Children's privacy
Don't Forget is not directed at children under 13, or under 16 in the European Economic Area, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us at leoni.francesco98@gmail.com and we will delete it.
11. Changes to this Privacy Policy
We may update this policy as the app evolves or the law changes. When we do, we will revise the “Last updated” date at the top of this page. If a change materially affects how we handle your information, we will make that clear in the app or on this site rather than relying on the date alone. We encourage you to check back occasionally.
12. Contact us
If you have questions about this policy or about how your data is handled, please get in touch:
- Email: leoni.francesco98@gmail.com
We read every message and aim to reply within 30 days.

