◉ Focal Point

Privacy Policy

Effective Date: July 3, 2026  |  Last Updated: July 3, 2026  |  Version 2.1

Introduction

Mile High Software Solutions LLC ("we", "our", or "us") operates the Focal Point Productivity application ("the App"). This Privacy Policy explains how we collect, use, store, and protect your information when you use our App.

Focal Point is a productivity application designed for individuals, households, families, and small businesses. The App allows users to create tasks, notes, projects, trips, and documents, and to share content with other users. The App is intended for general audiences and is not directed to children.

We limit the collection of personal data to what is necessary to provide and improve the App.

Information We Collect

We collect the following categories of information:

Account Information

User Content

Usage Data

Location Data

Precise geolocation is treated as sensitive personal information under California and Colorado law. See California Privacy Rights below for how we limit its use.

Voice Input

Technical Data

Integration Data

When you connect a Google account, we request the following scopes:

Both scopes are optional. You can use Focal Point without either integration. Each scope can be connected or disconnected independently.

How tokens are stored. When you connect, Google issues an OAuth refresh token, which we store in Firestore under your Firebase user ID (users/{your_uid}/integrations/google). On mobile, the token exchange happens entirely server-side (via a Cloud Function), so the refresh token never passes through the app. On desktop, the app completes the OAuth exchange itself and briefly holds the tokens in memory while handing them to our backend for storage; the refresh token is not persisted on your device. In both cases the credential is scoped to your Firebase account, not to your device, and day-to-day API calls use only short-lived access tokens that are refreshed on demand by a Cloud Function.

Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), we process your data under the following legal bases:

Processing ActivityLegal Basis
Account creation and authenticationContract performance
Storing and syncing your contentContract performance
Third-party integrations (Calendar, YouTube)Consent (opt-in)
Contacts access (friend discovery, attendee suggestions)Consent (device permission prompt)
Phone number (friend discovery)Consent (optional, user-provided)
Crash reporting and operational usage loggingLegitimate interest
Push notificationsConsent (opt-in via device settings)
Security and fraud preventionLegitimate interest
Marketing communicationsConsent (opt-in)

Service Providers and Subprocessors

We use the following third-party service providers to operate the App. Each provider processes data on our behalf under appropriate data processing agreements:

ProviderPurposeData Processed
Google FirebaseAuthentication, database, storage, hostingAll user data
Google Gemini APIAI features (search, chat assistant, receipt scanning, suggestions, search indexing)Content you submit to AI features, and content you create in the App that is processed to power them (see "AI features" below)
Google Maps PlatformMaps display, place search, address lookup, driving directionsPlace searches, addresses, and trip stop coordinates
Firebase CrashlyticsCrash reportingError logs, device info
Apple (App Store)Authentication, paymentsApple ID, subscription status
Google (Play Store)Authentication, paymentsGoogle account, subscription status
Google Calendar APICalendar integrationCalendar events (read-only)
YouTube Data APIVideo previewsVideo metadata
ZeptoMail (Zoho Corporation)Transactional email delivery (welcome, verification, password reset, account and storage notices)Email address, display name, email delivery and bounce status
Apple WeatherKitWeather forecasts for your saved locations, events, and trip daysCoordinates of the places you save (never your device's live location)
The Odds APISports game schedules for game-day remindersRequests for the sports and teams you follow (requests may be made from your device, so your IP address reaches this provider)
OpenStreetMap NominatimBackup geocoding when Google's geocoder has no resultPlace names you enter (sent from our servers; no account information)

Google's Data Processing Terms apply to Firebase services. For details, see Firebase Data Processing Terms.

AI features (Google Gemini API): Content you submit to AI features — including messages you send to the Ask Focal Point assistant and the snapshot of app data needed to answer them — is processed by the Google Gemini API on a paid service tier. In addition, some processing happens automatically to power AI features you've enabled: for example, the text of notes, tasks, and similar content you create is converted into search embeddings (a numeric representation used for semantic search) as you save it, and certain trip and weather features generate descriptions in the background. Under the paid tier, Google does not use any of this content to train or improve its models and retains it only for a limited period solely to detect and prevent abuse. See Google's Gemini API Terms ("How Google Uses Your Data").

Data Storage and International Transfers

Storage Location: Your data is stored on Google Cloud/Firebase infrastructure primarily in the United States (us-central1 region).

International Transfers: If you are located outside the United States, your data will be transferred to and processed in the United States. For users in the EEA, UK, or Switzerland, these transfers are protected by:

For more information, see Google Cloud GDPR Compliance.

Data Retention

Data TypeRetention Period
Account and user contentUntil you delete your account
Deleted items (Trash)Items you delete move to Trash, where they can be restored for 30 days; after 30 days they are permanently deleted
AI assistant chat historyAutomatically deleted after 90 days by default; adjustable from 30 to 180 days in Settings
Cached integration dataDeleted immediately when you disconnect a service
AI usage & cost logsUp to 18 months, after which records are aggregated or deleted
Crash reports (Firebase Crashlytics)Up to 90 days, per Firebase Crashlytics defaults
Server logs (IP addresses)Up to 30 days
BackupsAutomatic infrastructure-level backups are managed by Google Cloud per their standard retention schedule. We do not maintain separate backups beyond this.
Inactive accountsFree-tier accounts with no sign-in activity for 24 consecutive months are permanently deleted. See the Account Inactivity section below for the full policy. Accounts with an active Premium subscription are exempt from inactivity deletion.

Account Inactivity

To keep our service efficient and to reduce the personal data we retain, we permanently delete free-tier accounts that have been inactive for an extended period.

Shared projects. A shared project is preserved as long as at least one of its administrators is not subject to inactivity deletion — that is, an administrator who is either a Premium subscriber or a free-tier user who has signed in within the last 24 months. A shared project is only deleted when every one of its administrators has themselves been deleted for inactivity. When you are deleted, references to your account are removed from any project you belonged to, whether the project is preserved or deleted.

Trip expense history. When you participate in a trip's expense tracking, your display name and email at the time of each entry are recorded on that entry. These records are preserved as a historical financial record even after your account is deleted. Past entries continue to show the name you used at the time, with a "deleted account" indicator beside the name. Existing settlement calculations are not recalculated.

Account Deletion

When you delete your account (or your account is deleted for inactivity):

To delete your account, go to Settings > Account > Delete Account, or contact us at support@milehighsoftwaresolutions.com.

Sharing and Collaboration

Focal Point allows you to share projects, tasks, notes, and whiteboard pages with other users.

Permission Levels (Projects & Tasks)

When you share a project, members receive edit access. A member's access becomes read-only if their Premium subscription lapses, or — on free accounts — for projects beyond the free editable-project limit. Read-only members can still view all shared content and mark tasks complete, check off checklist items, and update a task's kanban status, but cannot add, edit, or delete other content.

Notes Sharing

Individual notes can be shared directly with specific users. Shared notes are read-only for recipients — only the note owner can edit or delete a directly-shared note. To collaborate on a note with edit access, place it inside a shared project and grant Editor permission at the project level.

Whiteboard Pages

Whiteboard pages (sticky-note boards) are shared at the page level. Individual sticky notes inherit the page's sharing settings; you cannot share a single sticky note independently.

What Shared Users Can See

Warning: Be cautious about sharing content containing sensitive personal information. You are responsible for obtaining appropriate consent before sharing content that contains others' personal data.

Your Responsibility for Shared Content

When you share content with other users, you are responsible for the personal data contained within that content, including ensuring you have the necessary rights and consents to share such information. We act as a service provider facilitating this sharing and do not control the content users choose to share.

Third-Party Integrations

Google Maps

Google Calendar Integration

YouTube Integration

You can disconnect integrations at any time in Settings.

Google API Services — Limited Use Compliance

Focal Point's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we affirm that data obtained from Google APIs (including your Google Calendar events and YouTube subscription data) is used solely to provide user-facing features within Focal Point:

You can revoke Focal Point's access to your Google account at any time from within the app (Settings → Integrations → Disconnect Calendar or Disconnect YouTube) or directly at Google Account Permissions. When you revoke access — either in-app or via Google — we delete the OAuth credential record and any cached data associated with that integration within our normal processing window.

Phone Number & Friend Discovery

You may optionally provide your phone number in your profile to help friends find you on Focal Point. Your phone number is:

If you remove your phone number, you will no longer be discoverable by phone number.

Contacts Access

With your permission, Focal Point can access your device contacts for two purposes:

  1. Friend Discovery: Check which of your contacts are already using Focal Point
  2. Calendar Attendees: Suggest contacts when adding attendees to calendar events

When you use the friend discovery feature:

When you use contacts for calendar attendee suggestions:

You can revoke contacts permission at any time in your device settings (Settings > Focal Point > Contacts on iOS, or Settings > Apps > Focal Point > Permissions on Android). Revoking permission does not affect any other app functionality.

Document Storage

If your Premium subscription lapses and your stored documents exceed the free plan 250 MB limit, you enter a 90-day download grace period:

You can stop the process at any time before day 90 by deleting documents to bring your total under 250 MB, or by resubscribing to Premium. Notes, tasks, projects, bookmarks, and other non-document content are not affected at any stage; your account itself stays fully active.

Inherited overage from transferred content. If another user transfers project ownership to you (for example, when a collaborator deletes their account) and the inherited content pushes you above your storage cap, the same 90-day grace period and day-90 cleanup apply. There is no separate carve-out for inherited content; the limit and the process are the same regardless of how the content arrived in your account.

Documents within shared projects are not counted toward your personal storage quota. See Shared Project Data Access below for details on shared project documents.

Shared Project Data Access

Focal Point projects support collaboration between multiple users. Editing project content (tasks, documents, sticky notes, kanban boards, and notes) requires an active Premium subscription.

Editing within a shared project requires at least one project administrator with an active Premium subscription. If all project administrators' subscriptions lapse:

You may always:

Local Sync (Premium Feature)

Local Sync allows you to sync documents to a folder on your device:

Security Note: Local Sync is provided for convenience. If you store sensitive documents, ensure your device has appropriate security controls (encryption, access controls).

Data Security

We implement industry-standard security measures:

Note: Documents are encrypted at rest on our servers but are not end-to-end encrypted. We (the service operator) have technical ability to access user content for support and legal compliance purposes, though we do not routinely access user content.

Offline Cache on Your Device

To enable offline use, Focal Point keeps a local copy of your data (notes, tasks, projects, expenses, trip data) on your device. This local cache:

Desktop users: if you keep sensitive content in Focal Point, we strongly recommend enabling full-disk encryption — FileVault on macOS (System Settings → Privacy & Security) or BitLocker / Device Encryption on Windows (Settings → Privacy & security). Sign out on shared machines so the local cache is cleared.

Data Breach Notification

In the event of a data breach that affects your personal data:

Security concerns can be reported to support@milehighsoftwaresolutions.com.

Legal Requests and Disclosure

We may disclose your information if required to do so by law, subpoena, or other legal process, or if we believe such action is necessary to:

Sensitive Data

Focal Point is a general-purpose productivity tool. While you may store various types of content, we recommend:

Usage and Crash Reporting

We collect a limited amount of operational data to keep the App reliable and sustainable:

We do not use Firebase Analytics, advertising identifiers, or any third-party cross-app tracking. This operational data is used only to run and improve the App, never for advertising.

Payment Processing

Premium subscriptions are processed through:

We do not collect, store, or process payment card information. All payment processing is handled directly by Apple or Google. We only receive confirmation of subscription status.

Children's Privacy

The App is intended for general audiences and is not directed to children. You must be at least 13 years old — or the minimum age of digital consent in your country, which is up to 16 in parts of the European Economic Area — to create an account. We ask you to confirm your age when you sign up.

We do not knowingly collect personal data from children below the applicable minimum age. If we learn that we have collected such data, we delete the account and its data promptly.

If a parent or guardian permits a teen who meets the applicable minimum age to use Focal Point, they are responsible for supervising that use and consent to the processing of the teen's data as described in this policy.

If you believe a child below the applicable minimum age has created an account independently, please contact us immediately at support@milehighsoftwaresolutions.com and we will delete the account.

Your Rights

Depending on your location, you have the following rights:

How to Exercise Your Rights

You can exercise most rights directly in the App (Settings > Account). For formal requests:

  1. Email support@milehighsoftwaresolutions.com with your request
  2. Include the email address associated with your account
  3. We will verify your identity before processing
  4. Requests will be processed within 45 days (or 90 days for complex requests, with notice)

There is no fee for reasonable requests. We may decline requests that are manifestly unfounded or excessive.

California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights:

Sensitive Personal Information. The only sensitive personal information involving precise geolocation comes from optional photo features. When you add a trip idea from a photo, the photo's coordinates are sent to Google Maps to suggest a place and look up its address. The trip photo map ("Scan my photos") runs entirely on your device and sends no location data to us or any third party. We do not use this information to infer characteristics about you, and we do not sell or share it. Because our use is limited to providing the features you requested, the CPRA "right to limit the use of sensitive personal information" does not restrict any additional use. You can control the trip-idea feature in Settings → Trips → Read location from photos, and the photo map runs only when you tap "Scan my photos."

We Do Not Sell or Share Your Personal Information for cross-context behavioral advertising or other purposes that would constitute a "sale" or "share" under California law.

Do Not Track: The App does not respond to "Do Not Track" signals from browsers or devices.

To submit a request, email support@milehighsoftwaresolutions.com with subject line "California Privacy Request."

Colorado Privacy Rights (CPA)

If you are a Colorado resident, you have the rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data or use it for targeted advertising. Precise geolocation is treated as sensitive data and is processed only when you affirmatively enable the photo-location feature described above. To exercise your rights, email support@milehighsoftwaresolutions.com. If we deny a request, you may appeal by replying to our response; if the appeal is denied, you may contact the Colorado Attorney General.

Canada (PIPEDA & Quebec Law 25)

We process personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws, including Quebec's Law 25. We collect personal information only for the purposes described in this policy and rely on your consent or another lawful basis. Our Privacy Officer is responsible for our compliance with these laws and can be reached at support@milehighsoftwaresolutions.com (attn: Privacy Officer). You may request access to or correction of your personal information, and you may lodge a complaint with the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information.

International Users (GDPR)

If you are located in the EEA, UK, or Switzerland:

Marketing Communications

We may send you marketing communications about new features or offers if you have opted in. You can opt out at any time by:

Opting out of marketing does not affect transactional emails (account confirmations, security alerts, subscription receipts).

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice in the App and updating the "Last Updated" date at the top of this page, and — for changes that significantly affect your rights or how we process your personal data — by sending an email to your registered address.

Continued use of the App after changes take effect constitutes acceptance of the updated policy. Where a change would expand processing that relies on your consent (for example, using data you provided for one purpose for a new purpose), we will ask you to opt in before the new processing applies to you, rather than relying on your continued use. For significant changes, we will provide reasonable advance notice (typically 30 days) before the changes take effect.

Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets, user information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice in the App before your personal data becomes subject to a different privacy policy.

Contact Us

If you have questions about this Privacy Policy or our data practices:

Mile High Software Solutions LLC
2057 Arroyo Ct
Windsor, CO 80550
United States
support@milehighsoftwaresolutions.com