Privacy policy
Last updated 5 October 2026
focusmigo helps people find others to study, work or read alongside, in person. This policy explains what personal information we collect, how we use it, who can see it, and the rights you have, wherever you live. It applies to the focusmigo website (focusmigo.com) and the focusmigo mobile apps (together, the "service").
Who we are. focusmigo ("we", "us") is the controller of your personal information, which means we decide how and why it is used. Privacy questions and requests: hello@focusmigo.com.
The short version
- We collect what is needed to run the service: your email, your profile, your date of birth (to confirm you are 18+), and the sessions, requests and messages you create.
- Other signed-in people see your profile and the sessions you host. Your email, date of birth, gender and verification photos are never shown to them.
- No advertising, no ad trackers, no analytics cookies. We do not sell or share your personal information for advertising.
- Verification selfies and ID photos are reviewed by a person and deleted after the decision. We do not use facial recognition.
- You can see, correct, download or delete your information at any time by emailing hello@focusmigo.com.
1. Information we collect
Information you give us
- Account: your email address, used to sign you in with a one-time link or code (we never store a password). If you choose "Continue with Google", we receive the name, email address and profile picture Google shares with your permission. In our iPhone app you can also use Sign in with Apple, which shares your name and email address and lets you hide your real email address.
- Profile: display name, city, and a profile photo or illustrated avatar. Optional: bio, headline, occupation, topics, how you like to sit, languages, and Instagram and LinkedIn handles.
- Date of birth (required): used only to confirm you are 18 or over. Never shown to other people.
- Gender (optional): used only to decide who can see and join women-only sessions. Never shown to other people. The administrator who reviews a photo verification sees it alongside your selfie.
- Verification (optional): a selfie with a hand gesture, compared with your profile photo by a person; or a student email address or a photo of your student ID. While a student email code is valid we keep the address; after that we keep only a one-way coded fingerprint (hash) of it, so one student email cannot verify several accounts, plus your university name (from the email domain) for your badge.
- Sessions and activity: sessions you post (title, description, venue, map location, times, optional photo of the spot), requests to join and your note to the host, group chat messages, check-ins, attendance reports, venue ratings and tips, saved sessions and spots, reports and blocks.
- Messages to us: anything you send to our support email.
Information collected automatically
- Location (only if you allow it): your device's location is used to centre the map and find sessions near you. It is sent to our database for that search, and (rounded to about 1 km) to our place-search provider to suggest nearby places. It is not stored. When you drop a pin for a session, its coordinates are sent to the place-search provider to look up the address. The city on your profile is stored to about 1 km.
- Camera and photos (only when you use them): to take or choose a profile photo, a spot photo or a verification photo. We only receive the photo you choose to upload.
- Push notifications (apps, only if you allow them): a device token so we can send you notifications about your sessions.
- Technical data: IP address, device and browser type, and error and security logs, kept by our hosting and database providers to run and protect the service.
Information from other people
Other members may report you, say whether you attended a session, or mention you in a session chat. If you sign in with Google or Apple, we receive the details described above from them.
Your email address and date of birth are needed to create an account; without them we cannot provide the service. Everything marked optional is up to you.
2. How we use it, and our legal bases
We use personal information only for the purposes below. We do not use it for advertising, we do not build advertising profiles, and we do not sell it. Some privacy laws (such as the GDPR in the European Union and United Kingdom) require us to name a legal basis for each use:
Create your account, sign you in and run the service: show sessions near you, let you post, request, join and chat, and send sign-in emails, session notifications and reminders
Information used: Account, profile, sessions and activity, device token
Legal basis: Performing our contract with you (our Terms)
Use your device location to centre the map and suggest nearby places
Information used: Location
Legal basis: Your consent (the location permission on your device or browser)
Confirm you are 18 or over
Information used: Date of birth
Legal basis: Legitimate interests (keeping minors off a service for meeting adults) and our contract
Women-only sessions
Information used: Gender, photo verification result
Legal basis: Your consent (remove your gender in Edit profile at any time to withdraw it)
Photo and student verification, and badges
Information used: Selfie, student email or ID photo, profile photo
Legal basis: Your consent (verification is optional)
Keep people safe: blocks, reports, reliability scores, moderation, enforcing our Terms
Information used: Profile, activity, reports, attendance reports, check-ins
Legal basis: Legitimate interests (a safe community) and our contract
Secure the service and prevent abuse, such as rate limits and investigating misuse
Information used: Technical data, activity
Legal basis: Legitimate interests (security)
Answer your questions and requests
Information used: Messages to us, account details
Legal basis: Our contract and legitimate interests
Comply with the law and defend legal claims
Information used: Any relevant information
Legal basis: Legal obligation and legitimate interests
| Purpose | Information used | Legal basis |
|---|---|---|
| Create your account, sign you in and run the service: show sessions near you, let you post, request, join and chat, and send sign-in emails, session notifications and reminders | Account, profile, sessions and activity, device token | Performing our contract with you (our Terms) |
| Use your device location to centre the map and suggest nearby places | Location | Your consent (the location permission on your device or browser) |
| Confirm you are 18 or over | Date of birth | Legitimate interests (keeping minors off a service for meeting adults) and our contract |
| Women-only sessions | Gender, photo verification result | Your consent (remove your gender in Edit profile at any time to withdraw it) |
| Photo and student verification, and badges | Selfie, student email or ID photo, profile photo | Your consent (verification is optional) |
| Keep people safe: blocks, reports, reliability scores, moderation, enforcing our Terms | Profile, activity, reports, attendance reports, check-ins | Legitimate interests (a safe community) and our contract |
| Secure the service and prevent abuse, such as rate limits and investigating misuse | Technical data, activity | Legitimate interests (security) |
| Answer your questions and requests | Messages to us, account details | Our contract and legitimate interests |
| Comply with the law and defend legal claims | Any relevant information | Legal obligation and legitimate interests |
Where we rely on legitimate interests, we have weighed them against your rights; you can object (see Your rights). Where we rely on consent, you can withdraw it at any time; this doesn't affect what was done before. We send service messages only, never marketing emails.
3. Who can see your information
- Other signed-in members can see your profile and city, sessions you host (including the venue and its map location, which should be a public place), your badges and student university, your reliability score, how many sessions you've hosted and joined, and your three most frequent spots (updated weekly).
- A host sees your profile and your note when you ask to join their session.
- People in the same session (the host and approved guests) see who is sitting and the group chat.
- Anyone with a shared link sees a short preview of a session: title, type, venue name, time, how many are sitting and the spot photo if there is one. No names and no exact address. Women-only sessions are never previewed.
- Venue tips are shown without your name.
- Profile and spot photos are stored at web addresses that anyone who has the link can open, so they can be seen outside focusmigo if someone shares the link.
- Never shown to other members: your email address, date of birth, gender, verification photos and saved list.
5. International transfers
Our database is in Singapore, and some providers above process information in other countries. These countries may have different data protection laws from yours. When we transfer personal information from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on the data processing terms of Supabase, Vercel and Resend, which include the European Commission's Standard Contractual Clauses and the UK Addendum, and on equivalent safeguards offered by our other providers. You can ask us for more information about these safeguards at hello@focusmigo.com.
6. How long we keep it
- Account and profile: until your account is deleted.
- Verification selfies and ID photos: deleted once reviewed, or straight away if the submission doesn't go through.
- Student email address: deleted as soon as you verify it, or within about a day if you don't finish; after that only the coded fingerprint is kept, until your account is deleted.
- Sessions, chats, check-ins, ratings, saves, reports and blocks: while your account exists, because they form part of other people's sessions and the venue information they rely on.
- Verification records (type, result, date, reviewer's note, the gender you declared and which profile photo was checked): kept until your account is deleted, so badges and women-only access stay valid. The photos themselves are deleted after review.
- Reminder records: which reminders were sent, kept so nobody gets the same reminder twice; deleted with your account.
- Location from your device: not stored.
- Technical and email delivery logs (including the address a sign-in or verification code was sent to): kept by our providers only for the short period their services set for security and troubleshooting, typically a few days.
- Support emails: as long as needed to handle your request and any follow-up.
When your account is deleted, we delete your profile, private details, photos, the sessions you host, your messages, check-ins, ratings, saves, reports and blocks within 30 days. Copies may remain in routine backups for a short period until they are overwritten. We may keep limited information longer only if the law requires it or to resolve a dispute or safety issue that is already under way.
7. Your rights and choices
Wherever you live, you can ask us to:
- access your personal information and get a copy, including in a portable, machine-readable format;
- correct it (you can edit most of it yourself in Edit profile);
- delete your account and personal information;
- withdraw consent for anything based on consent, such as gender, verification or location;
- object to or restrict how we use it, including uses based on legitimate interests;
- have a person review an automated result about you, such as your reliability score.
How to make a request: email hello@focusmigo.com from the email address on your account (so we can confirm it's you). You can also use someone you authorise to act for you; we'll ask them for proof of that and may ask you to confirm. We reply without undue delay and within one month. For complex requests we may extend this by up to two more months where the law allows, and we'll tell you if so. Requests are free.
If we decline, we'll explain why. You can appeal by replying to our decision; we'll answer your appeal within 45 days. You can also complain to your local data protection authority at any time (see Information for specific regions).
Device permissions: you can turn location, camera, photos and notifications on or off at any time in your phone or browser settings. focusmigo still works without them; you can search by city instead of using your location. We will never treat you differently for exercising your rights.
8. Automated decisions
Reliability score: after a session, people check in and can say whether others showed up. Your score ("showed up to 4 of 5 sessions") is calculated automatically from those reports and your own check-ins, a week after each session. If you checked in as attended, a session counts against you only if at least two people report you didn't show and they outnumber those who say you did by more than one. If you didn't check in, it counts against you when "didn't show" reports outnumber "showed up" reports. If you check in as not attended, it counts as not attended. Hosts see it when you ask to join and decide for themselves whether to approve.
Who can see a session: blocks, women-only and verified-only settings automatically decide which sessions you can see and join. You can ask for a person to review any of these results at hello@focusmigo.com.
9. Security
Information is encrypted in transit (HTTPS) and stored encrypted at rest by our database provider. Database rules limit every person to reading and changing only what they are allowed to. Verification photos are stored privately, can only be viewed by the administrator reviewing them, and are deleted after review. Sign-in uses one-time links and codes, not passwords. Administrator access is limited and protected. No system is perfectly secure: if a breach puts your information at risk, we will notify you and the relevant authorities as the law requires.
11. Age requirement
focusmigo is only for people aged 18 and over. We do not knowingly collect information from anyone younger. If we learn that an account belongs to someone under 18, we delete it. If you believe a minor is using focusmigo, tell us at hello@focusmigo.com.
12. Information for specific regions
European Economic Area, United Kingdom and Switzerland
The GDPR, UK GDPR and Swiss data protection law apply to you. Our legal bases are listed in section 2 and your rights in section 7, which also include the right to data portability. You can complain to the data protection authority where you live or work, or where you think a breach happened; in the UK that is the Information Commissioner's Office (ico.org.uk). We'd appreciate the chance to fix things first, at hello@focusmigo.com.
United States
This section applies to residents of California and other US states with consumer privacy laws (including Colorado, Connecticut, Virginia, Texas, Oregon and others).
- Categories we collect (in the last 12 months, as described in section 1): identifiers (email, name, IP address, device token); personal records (photos); characteristics such as age and, if you add it, gender; professional information (occupation, LinkedIn handle); education information (student status and university); internet activity (how you use the service, technical logs); approximate geolocation (city; device location used for a search and not stored); and inferences limited to your reliability score.
- Sources: you, your device, other members (reports, attendance reports) and, if you use them, Google or Apple sign-in.
- Purposes: the business purposes in section 2. We disclose these categories to the service providers in section 4 for those purposes only.
- No sale, no sharing: we do not sell personal information or share it for cross-context behavioural advertising, and have not done so in the last 12 months. We do not knowingly sell or share information of anyone under 16.
- Sensitive personal information (such as the contents of session chat messages, and gender if you add it) is used only to provide the service you ask for and keep it safe, not to infer characteristics about you.
- Your rights: to know and access, delete, correct and get a portable copy of your information, and not to be discriminated against for using these rights. Make a request as described in section 7; you can use an authorised agent. If we deny your request, you can appeal as described in section 7, and if you're not satisfied with the outcome you can contact your state attorney general.
- Retention: see section 6.
Everywhere else
The rights in section 7 apply to everyone, including under Brazil's LGPD, India's Digital Personal Data Protection Act, Singapore's PDPA, Australia's Privacy Act, Canada's PIPEDA and similar laws. Where your local law gives you more rights than this policy describes, we will honour them. You can also contact your local data protection authority.
13. Changes to this policy
If we change this policy in a way that matters, we will tell you in the app or by email before the change takes effect, and update the date at the top. Where the law requires your consent to a change, we will ask for it.
14. Contact
Email hello@focusmigo.com for any privacy question, request or complaint.
