Privacy Policy
What information Tomatino handles, where it’s kept and what you can do about it. Tomatino works without an account, and most of what you do stays in your browser.
Effective
1.At a glance
- You can use Tomatino without an account. Without one, your tasks, projects, focus history, templates and settings are stored in your browser on that device, and aren’t sent to us.
- If you create an account, we store your email address, your name if you give one, and the records listed under Accounts and sync, so they can sync across your devices.
- Like any website, Tomatino’s server handles some technical information when you visit, such as your IP address and browser details. See Security and server records.
- Tomatino’s server and database are hosted with Amazon Web Services (AWS) in London, and the website is delivered through Cloudflare. Account emails are sent through Mailgun’s EU service.
- Tomatino doesn’t include analytics, advertising or third-party tracking tools.
- You can back up or export your data at any time, and delete your account whenever you like.
2.Who we are
This policy explains how Tomatino handles information about you. In this policy, “Tomatino”, “we” and “us” mean the Tomatino service and the people who run it. You can reach us at [email protected].
It covers the Tomatino website and app, whether you use it in a browser or install it. Our Terms of Service cover using Tomatino.
3.Information stored on your device
Tomatino is built to work in your browser. Unless you create an account, what you put into it is saved in your browser’s storage on that device, and isn’t sent to us. That includes:
- Your tasks and projects.
- Your focus history: when each focus session ended, how long you focused, whether it ended early, and the task and project it counted for.
- Your daily goal, timer settings and saved templates.
- The timer itself: whether it’s running, and the setup for your next session.
- Preferences, such as your theme, Focus environment sound and volume, and whether away alerts are on.
- Information the app needs to work properly:
- a random identifier for this device, used to keep focus sessions recorded on different devices apart (it’s part of each focus session’s ID, so it syncs with your focus sessions if you have an account)
- when a focus length suggestion was shown, dismissed or used, so suggestions don’t repeat too often
- notes about what has and hasn’t synced, if you have an account
Your stats, Garden and streaks, and focus length suggestions, are worked out in your browser from your focus history. We don’t store them on our server.
Because this information lives in your browser, clearing your browser’s data for Tomatino deletes it, unless it’s also stored in an account. Some browsers may remove stored data on their own, so it’s worth keeping a backup (see Your choices).
Your browser also keeps a copy of Tomatino’s own files, and of any Focus environment sounds you’ve played, so the app can open and work offline. Focus environment sounds come from Tomatino’s own server.
If you turn on away alerts, some information about your timer is sent to us so the alert can be delivered; see Away alerts and email.
4.Accounts and sync
An account is optional. You only need one to keep your data in sync across devices.
When you create an account
We store your email address, your name if you give one, and your password as a secure hash (not the password itself). We also store when the account was created and updated, and keys that keep you signed in and let your devices check whether the account still exists.
We use your email address to create and secure your account, to let you sign in and reset your password, and to send the account emails described under Away alerts and email.
What syncs
While you’re signed in, these records are stored with your account, so every device you sign in on can have them:
- Tasks: title, estimate, project, order, whether it’s in Today, and when it was created, completed or archived.
- Projects: name, colour, and when it was created or archived.
- Focus sessions: when each one ended, how long you focused, whether it ended early, and the task and project it counted for.
- Templates you’ve saved: name, lengths and Focus environment.
- Your timer defaults and daily goal.
Some things stay on the device even with an account: the running timer and your next setup, sound and alert settings, your theme, and your stats, Garden and streaks.
How sync works
Focus sessions are history: once stored, they don’t change. For everything else, the most recently edited version is kept. Archiving a task or project keeps it in your account; deleting a template you saved is recorded, so an older copy doesn’t bring it back. Tasks, projects and focus sessions can’t currently be deleted one by one; they’re deleted when you delete your account.
When you sign in on a device that already has data, Tomatino shows you what’s on the device and in the account before anything is combined. You can combine both, or stay signed out.
Signing out
Signing out syncs your changes first. Once everything has synced, the account’s copy is removed from that device. If something can’t sync, Tomatino tells you, and lets you try again or keep those changes on the device for that account.
5.Away alerts and email
Away alerts
Away alerts are optional notifications for when the timer ends while Tomatino isn’t on screen. They work with or without an account, and your browser asks for your permission when you turn them on.
To send them, your browser gives us a push subscription: an address at your browser’s push service and keys for encrypting messages to it. We store it with a random secret for the device (kept as a hash). While the timer runs, the device tells us when it will end and which kind of alert to show. Alerts say only what happened, such as “Focus complete” and “Time for a 5-minute break.”, never task names or anything else you’ve written.
Away alert registrations belong to the device, not to your account. Alerts are delivered by your browser’s push service, which is run by the company behind your browser or operating system, such as Apple, Google, Mozilla or Microsoft. It receives the encrypted alert and when to deliver it.
Turning away alerts off removes this device’s registration from our server. Signing out, or deleting your account, turns alerts off on that device too, and your other devices do the same when they next check in. Because registrations belong to devices, it’s each device that removes its own; a device that never checks in again keeps its registration until it’s removed automatically after 90 days without use, along with its alerts.
If you have an account, we send these emails, and only these:
- a welcome email when you create an account
- a link to reset your password, when you ask for one
- a notice when your password has been changed
- a confirmation when your account has been deleted
We send them through Mailgun, using its EU service. Mailgun receives your email address and the email itself in order to deliver it, and keeps its own delivery records. We turn off Mailgun’s open and click tracking for these emails. Each one is labelled with its type, such as “password-reset”.
A password reset link works for 60 minutes. We keep a hash of the request (not the link itself) until it’s used or replaced by a new request; expired requests are cleared every day, and any request is removed if the account is deleted.
6.Security and server records
To work and stay secure, Tomatino’s server keeps some records about requests, whether or not you have an account:
- A session record for each visitor, linked to a session cookie. It holds your IP address and your browser’s user agent and, if you’re signed in, which account is yours. Session records expire after a period of inactivity and are then removed.
- Temporary counters that slow down repeated attempts, such as failed sign-ins. They’re keyed to your IP address (for sign-in, together with the email address entered) and expire within an hour.
- Application logs. If something goes wrong, details of the error are logged so it can be fixed; an entry can include your account’s ID if you were signed in. Away alerts are also logged when they’re planned and sent: an internal number for the device, when each alert was due and sent, and which push service delivered it.
We keep logs only as long as we need them to run Tomatino, keep it secure and fix problems. There isn’t a fixed period. Cloudflare, which every request to Tomatino passes through, and AWS, which hosts it, may also keep their own records of requests, such as IP addresses, as part of providing their services.
7.Cookies and browser storage
Tomatino sets a small number of cookies, all its own:
- tomatino-session: links your browser to its session record.
- XSRF-TOKEN: protects sign-in and account actions from being triggered by other websites.
- A sign-in cookie, only once you sign in. It keeps you signed in on that device until you sign out, for up to 400 days.
- appearance: remembers the theme you chose (light, dark or system), so pages open in it. It’s set only when you choose one.
Tomatino also uses your browser’s local storage and session storage for the information described under Information stored on your device, and cache storage, through a service worker, so it can work offline. These aren’t cookies, and what they hold stays in your browser.
Tomatino doesn’t use advertising, analytics or other third-party cookies.
8.Service providers
These providers receive information through Tomatino:
- Cloudflare delivers and protects the Tomatino website. Every request to Tomatino passes through Cloudflare’s network on its way to our server, so Cloudflare handles your IP address and the requests and responses themselves.
- Amazon Web Services (AWS) hosts Tomatino’s server and database in its London region (eu-west-2). They hold account and sync data, session records, away alert registrations and logs.
- Mailgun sends account emails through its EU service. It receives your email address and the email’s contents.
- Your browser’s push service delivers away alerts, if you turn them on. It receives the encrypted alert, its timing and your push subscription address.
Hosting in London and sending email through Mailgun’s EU service don’t guarantee that every provider handles information only in those places. Cloudflare may handle requests at locations outside the UK, your browser’s push service is chosen by your browser and may handle alerts elsewhere, and providers may use their own suppliers.
We may also disclose information if the law requires it.
9.Why we use information
Under UK data protection law, we need a reason to use personal information. Ours are:
- To provide your account, sync and account emails, because they’re needed for the service you’ve asked for.
- To deliver away alerts you’ve turned on, for the same reason.
- To keep Tomatino secure, prevent abuse and fix problems, which is in our legitimate interest in running a reliable service, and in yours.
- To meet legal obligations, where they apply.
10.Retention and deletion
- On your device: information stays until you delete it in Tomatino, clear your browser’s data for Tomatino, or your browser removes it.
- In your account: your account and synced records are kept until you delete your account. Archived tasks and projects stay in the account.
- Away alerts: as described under Away alerts and email.
- Session records, attempt counters and logs: as described under Security and server records.
- Password reset requests: as described under Away alerts and email.
Deleting your account
You can delete your account in Tomatino, under Account, after confirming your password. This permanently deletes from our database, in one step, your account, everything it synced, its sign-in sessions on every device, and any pending password reset. It can’t be undone. We then send one last email confirming the deletion.
The device you delete it from removes its copy of the account’s data straight away. Your other devices remove theirs the next time they’re online and check in. Backups and exports you’ve saved are your own files and aren’t affected.
Tomatino doesn’t currently run its own backups of its database. Records kept by our providers, such as Mailgun’s delivery records, and our logs, aren’t removed by deleting your account; they’re kept as described above.
11.Your choices
- Use Tomatino without an account, so your tasks and focus history stay in your browser.
- Back up everything to one file, or export your focus history as a CSV, from Your data in Tomatino. Both are made on your device and aren’t uploaded.
- Restore a backup, which combines it with what’s already there.
- Turn off away alerts, or focus length suggestions, in Settings.
- Delete your account at any time.
12.Your rights
Under UK data protection law, you have rights over your personal information. Depending on the circumstances, you can ask us to:
- give you a copy of the personal information we hold about you
- correct information that’s wrong, such as your email address
- delete your information
- restrict how we use it, or object to our using it
- give you information you provided in a portable format
These rights don’t apply in every situation. To make a request, email us at [email protected]. Much of this you can also do yourself in Tomatino: your data is in your browser, Your data exports it, and you can delete your account.
If you’re unhappy with how we’ve handled your information, you can complain to the Information Commissioner’s Office, the UK’s data protection regulator, at ico.org.uk. We’d appreciate the chance to help first.
13.Changes to this policy
If we change this policy, we’ll publish the new version here and update the date at the top. If a change significantly affects how we handle information in accounts, we’ll tell account holders before it takes effect.
14.Contact
Questions about this policy, or about your information:
- [email protected]