Privacy Policy

Who we are

Attentify is operated by Luca Dominguez ("we", "us"). For any privacy question or request, email ludomi2502@gmail.com. If you are in the UK or EU, we act as the data controller for the personal data described here.

What stays on your device

The desktop app records what you do on your computer so it can show you analytics and decide when to step in. This includes the applications you use, window titles, page addresses, how long you spend on each, and the decisions the app makes about them.

This detailed record is stored locally, in a database on your own machine, and is not uploaded to us. If you use the app's history import, the browser history it reads is likewise processed locally and stays there. Uninstalling the app or clearing its data removes it.

What leaves your device

1. AI processing

Attentify's AI features are the core of the product, and they cannot run purely locally. When an AI feature runs, we send the following to our server, which forwards it to our AI provider:

We do not send your full browsing history, your files, your keystrokes, or the contents of pages beyond the title. AI requests are made per page assessed or per message you send, not continuously.

Our AI provider is OpenRouter, which currently routes these requests to DeepSeek models. That means the data listed above is processed on infrastructure operated by those companies, which may be outside your country, including outside the UK, EU and Canada. If you would rather not use a managed provider, the app and extension let you supply your own API key, in which case requests go directly from your device to the provider you chose and never reach our servers.

If you turn AI features off, or run out of credit, this stops. Your static rules, keyword blocks and built-in blocking keep working with no data leaving your device.

2. Your account

To sign in you give us an email address and a password. We store the email, and only a salted hash of the password, never the password itself. We also store a session token and the browser user agent that created it, so you can stay signed in.

3. Anti-abuse

Every account gets a small amount of free AI credit. To stop one person claiming it repeatedly we record a device fingerprint, a value derived from your installation, and check it has not claimed a trial before. On this website we also use Cloudflare Turnstile to tell humans from bots at sign-up. Turnstile runs checks in your browser; Cloudflare processes the result.

4. Payments

Payments are handled entirely by Stripe. We never see or store your card number. We keep your Stripe customer and subscription identifiers, your credit balance, and a ledger of credit movements so your account page and billing work.

5. Usage metering

Because AI is charged by usage, we record how much you used and what it cost: token counts, the model used, timestamps and the resulting credit debit. This is billing data, not content. We do not store the text of your AI requests once they have been answered.

6. Diagnostics, if you turn them on

Diagnostics are off unless you enable them. When enabled, crash reports and error details are sent, along with an installation identifier and, where relevant, an excerpt of the chat message involved. Because an account is required to use Attentify, this data is linked to you and we do not describe it as anonymous.

Who processes your data

We do not sell your personal data, and we do not share it for advertising.

How long we keep it

Your rights

You can ask us to give you a copy of your data, correct it, or delete it. You can withdraw consent for diagnostics at any time in Settings. Depending on where you live you may also have the right to object to or restrict processing, to data portability, and to complain to your local data protection regulator. Email ludomi2502@gmail.com and we will respond within 30 days.

Most of what Attentify knows about you is on your own computer, so the fastest way to erase it is to clear the app's data or uninstall it.

Children

Attentify is not intended for children under 16, and we do not knowingly collect their data.

Security

Passwords are hashed and salted. Traffic is encrypted in transit. API keys live only as server-side secrets and are never shipped inside the app, the extension or the website. No system is perfectly secure, and we cannot guarantee absolute security.

Changes

If we change this policy we will update the date at the top. For changes that materially affect what we collect or who processes it, we will tell you in the app or by email before they take effect.