Bidoro — Privacy Policy
Last updated: June 29, 2026
Bidoro ("the app", "we") is a personal focus-timer, task-matrix and calendar app with optional
social features (shared notes and friends). This policy explains what data the app handles.
Using Bidoro without signing in keeps your data on your device; signing in and the optional
features below are what involve our backend and other services.
1. Information we handle
- Your app data (tasks, focus sessions, calendar events, garden, settings) —
stored on your device and, if you sign in, synced to our backend (Supabase) so it is available
across your devices.
- Account profile — when you sign up you provide an email (for
sign-in) and may set a nickname and an avatar (an emoji). These
personalize your account and, for nickname/avatar, are shown to friends you connect with.
- Shared notes & replies (optional) — if you tap "Share" on a note, its text
(and emoji) is sent to our backend and may be shown anonymously to other Bidoro
users; you can likewise see and reply to notes others have shared. See section 3.
- Friends (optional) — if you add a friend by code or QR, the two of you can
share selected sections of your data (timeline, balance, routine, garden). See section 4.
- Calendar data (optional) — only if you connect Google Calendar or allow Apple
Calendar access. See section 5.
- Authentication tokens — for Google Calendar we store OAuth access/refresh
tokens on our backend so sync can run. We never see or store your Google or Apple password.
2. AI replies on shared notes
If a note you shared receives no human reply, an automated assistant may generate a short,
encouraging reply so the board doesn't feel empty. To do this the text of the shared
note is sent to our AI provider (OpenAI) to produce the reply. Only the shared note's
text is sent — not your email, name, tasks, or other app data. OpenAI processes it to return the
reply and, per their API terms, does not use API content to train their models. You can avoid this
entirely by not sharing a note.
3. Shared notes, moderation & safety
- Shared notes are visible to other users without your name or email (anonymous).
Do not put personal or sensitive information in a note you share.
- Notes and replies pass a basic profanity filter, can be reported by any user,
and are reviewed by a moderator who can return, hide or remove content and can
block a user from sharing or replying. There is no tolerance for objectionable content.
- You can stop sharing a note at any time, and you can report or hide replies you receive.
4. Friends
- Adding a friend is mutual and uses a friend code / QR you choose to share. Once connected, the
sections you each turn on (timeline, balance, routine, garden) become visible to
the other; turning a section off applies right away. Turning one on requires the friend's
approval.
- You can unfriend at any time, which stops the sharing.
5. Calendar data (Google & Apple)
- Google Calendar (optional) — only if you tap "Google Calendar" and sign in. We
request the
calendar.events scope to read your events and to create/update events you
make in Bidoro, so the two calendars stay in sync.
- Apple Calendar (optional) — on iPhone/iPad you may grant calendar access so
Bidoro can show your events and write events you create. This uses Apple's on-device EventKit;
you can revoke it in iOS Settings → Privacy → Calendars.
- Calendar data is used only to display and sync your schedule. We do not use it for
advertising, profiling, or any unrelated purpose, and we do not sell it.
6. Google Limited Use disclosure
Bidoro's use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements.
We do not transfer Google user data to third parties except as needed to provide the sync
feature, to comply with law, or as part of a merger; and we do not use it for ads or to train
generalized AI models.
7. Data security & protection of sensitive data
We apply the following measures to protect your data, including sensitive Google user data
(Google Calendar events) and the related OAuth tokens:
- Encryption in transit — all data, including Google Calendar data and OAuth
tokens, is transmitted only over encrypted connections (HTTPS/TLS).
- Encryption at rest — data stored on our backend provider
(Supabase) is encrypted at rest.
- Secure token handling — Google OAuth access/refresh tokens are stored
server-side with restricted access, are never exposed to the app client or to other
users, and are used only to perform the calendar sync you enabled.
- Access controls — backend data is protected by row-level security so each
account can access only its own data; Google Calendar data and tokens are not shared with other
users or with third parties.
- Retention & deletion — Google Calendar data and tokens are retained only
while the integration stays connected. When you disconnect Google access (section 10) or delete
your account, the stored tokens and synced calendar data are deleted.
- We do not sell Google user data, do not use it for advertising or profiling, and do not use it
to train AI models.
8. Storage & third parties
- Data is stored on your device and on our backend provider (Supabase). OAuth
tokens are kept server-side and are not exposed to other users.
- Shared-note text is processed by OpenAI only for the AI-reply feature
(section 2).
- We do not sell your data or share it with advertisers.
9. Children
Bidoro is intended for a general audience and is not directed to children under 13, and we do not
knowingly collect personal information from children under 13 without parental consent. If you
believe a child has provided us data, contact us and we will delete it.
10. Disconnecting & deleting your data
- You can revoke Google access at any time at
Google Account → Third-party access, and Apple Calendar access in iOS Settings. This stops
the respective calendar sync.
- You can delete your account and its synced data (profile, friendships, shared notes) from
within the app, or contact us (below) and we will remove it.
11. Focus Lock (Screen Time)
- Focus Lock lets you block distracting apps and websites during focus or study time. It uses
Apple's Screen Time / Family Controls framework. You authorize it once; you can
revoke that authorization any time in iOS Settings → Screen Time.
- The apps and websites you choose are represented by Apple's opaque, privacy-preserving
tokens. Bidoro never sees the names of the apps you select or how you use them, and this
information is stored only on your device — it is not transmitted to us or anyone else.
- An optional unblock password (e.g. set by a parent or partner) is stored on your
device only, as a one-way hash. We cannot read or recover it.
- An optional schedule (days/times) is stored on your device. Bidoro does not log,
share, or sell your app or web usage.
12. Contact
Questions or deletion requests: ebsmoon@gmail.com