dōro Privacy Policy
Effective date: August 27, 2026
Last updated: August 27, 2026
Version: 2.3 — US-only; Polar has no country lock; we reject non-US billing
Organization 4901, LLC (“we,” “us,” or “4901”) operates dōro (also written “Doro”), a focus timer available at trydoro.app, timer.trydoro.app, and any related sites, APIs, or mobile apps we make available (the “Service”).
This Privacy Policy explains what we collect, why we collect it, and what we do with it. If you do not agree, do not use the Service.
Contact: [email protected]
This is a notice at collection for California and similar U.S. state laws. We collect the categories below, for the purposes below, and keep them for the periods below. We do not sell personal information and we do not share it for cross-context behavioral advertising.
Where we operate. We offer accounts and paid access only to people located in the United States. We do not target, market to, or offer the Service to people in the European Economic Area, the United Kingdom, or Switzerland. If you are located there, do not create an account, do not sign in, and do not submit personal information through checkout.
Do not circumvent the region lock. Do not use a VPN, proxy, false location, or false billing details to sign up or pay from the EEA, the UK, or Switzerland. If we learn an account is in a place we do not serve, or was created by circumventing the lock, we will delete it and the personal information we control, except records we must keep (for example a fraud or abuse record).
Polar does not let us disable other countries at checkout. Polar may still collect a billing country. We will not complete paid access if that country is not the United States, and we will ask Polar to cancel or refund. A Polar checkout page is not an offer of the Service in the EEA, UK, or Switzerland.
This policy is written for US users. It is not an offer of the Service in the EEA, UK, or Switzerland and is not intended to establish GDPR targeting.
1. Who is responsible
Organization 4901, LLC is a Delaware limited liability company. For personal information we collect through the Service, 4901 is the controller (or “business”).
Paid subscriptions are sold by Polar Software, Inc. (“Polar”) as merchant of record. Polar (and its payment processors) is the controller of payment-card and checkout data it collects at purchase. Polar’s privacy policy is at polar.sh/legal/privacy. We are not responsible for Polar’s handling of that payment data.
2. Information we collect
2.1 Account information (Google sign-in)
You sign in with Google through Firebase Authentication. Depending on what you authorize, we receive:
- your Google account email
- your name
- your profile photo
- a unique account identifier
We do not receive your Google password.
2.2 Service data
When you use the timer we store the data needed to run the product, which may include:
- focus sessions (start/stop, duration, pauses, skips)
- categories or labels you attach to sessions
- daily and weekly progress metrics
- account settings and preferences
- technical identifiers needed to keep you signed in
2.3 Technical and usage data
We automatically collect:
- IP address and approximate location derived from it
- device, browser, and operating-system information
- pages viewed, referring URL, and timestamps
- cookies or similar identifiers required for login and basic operation
2.4 Communications
If you email us, we keep the content of that message and your contact details so we can respond.
2.5 Payment information (collected by Polar, not by us)
If you start a paid subscription, Polar’s checkout collects your email, billing country (and billing address where required), and payment-card details. Polar processes cards through its payment partners (including Stripe). We do not receive or store your full card number. We may receive from Polar limited billing records we need to unlock the Service (for example: email, subscription status, plan, renewal date, last four digits, and country).
2.6 What we do not collect on purpose
We do not ask for government ID, precise geolocation, payment-card PAN, or special-category data (health, race, religion, union membership). Do not put that into labels or notes.
3. How we use information
We use the information above only to:
- create and maintain your account
- provide the timer, saved sessions, and progress metrics
- authenticate you and keep the Service secure
- determine whether your account is on a trial or paid plan (using Polar status)
- respond to support requests
- detect abuse, fraud, and technical problems
- comply with law and enforce our Terms of Use
- understand how the Service is used, in aggregate and de-identified form, so we can improve it
We do not sell your personal information.
We do not share it for cross-context behavioral advertising.
We do not use your session history, categories, or labels to train general-purpose machine-learning models.
We do not use that Service data to advertise third-party products to you.
4. Legal bases (EEA / UK)
If European or UK data-protection law applies, we process personal information on these bases:
- Contract: to provide the Service you asked for
- Legitimate interests: security, preventing abuse, and de-identified product improvement
- Legal obligation: records we must keep
- Consent: where a law requires it (for example certain non-essential cookies), which you can withdraw
5. How we share information
We share information only as described here. These are our current subprocessors and service providers:
| Provider | Role | Data |
|---|---|---|
| Google LLC / Firebase | Sign-in and authentication | Account identifiers, email, name, photo |
| Cloudflare, Inc. (Workers, D1, and related) | Hosting, security, application data | Account and Service data, technical data |
| Polar Software, Inc. | Merchant of record, checkout, subscriptions, invoices | Email, plan/status, limited billing records |
| Polar’s payment processors (including Stripe, Inc.) | Card processing on Polar’s checkout | Payment data Polar collects (not stored by us) |
We may add or replace a provider that performs a similar function. Material changes will be reflected in this policy.
Other disclosures. We may disclose information if required by law or legal process, to protect 4901, you, or others from harm or fraud, or if we sell or reorganize the business (the buyer must honor this policy or give you notice before using your information in a new way).
We do not share your session history or categories with advertisers.
6. Cookies
We use cookies and similar technologies that are necessary to sign you in and operate the Service. We may also use limited first-party analytics to see that the Service loads and is used. We do not use advertising pixels or third-party ad networks on the Service.
You can block cookies in your browser. Some features, including staying signed in, will not work if you do.
7. Retention and deletion
- Account and session data are kept while your account is open.
- Billing records we receive from Polar are kept as long as needed for accounting, tax, chargebacks, and legal claims (typically up to seven years where tax or card-network rules require it).
- Support email is kept as long as needed to finish the request, then deleted or archived with other business records.
To delete your account, email [email protected] from the address on the account. We will delete or de-identify Service data we control within 30 days, except records we must keep. Polar keeps payment records under its own policy. We cannot delete data Polar is legally required to retain.
8. Security and breach notice
We use reasonable administrative and technical measures (including HTTPS and provider-side access controls) to protect personal information. No internet service is perfectly secure.
If we become aware of a breach of personal information we control that is reasonably likely to cause you serious harm, we will notify you at the email on your account and any regulator the law requires, without unreasonable delay and in any event as required by applicable law (including, where it applies, within the statutory period under U.S. state or EU/UK rules).
9. Children
The Service is not directed to children under 13. We do not knowingly collect personal information from anyone under 13. We do not have actual knowledge that we collect personal information from anyone under 16 for “sale” or “share” purposes, because we do not sell or share.
If you are under 13, do not use the Service and do not sign in with Google. If you are 13–17, you may use the Service only with a parent’s or guardian’s permission, and you may not start a paid subscription.
If we learn that we have collected personal information from a child under 13, we will delete the account and that information as soon as reasonably possible. Email [email protected].
You must be 18, or the age of majority where you live, to start a paid subscription.
10. Your rights
Depending on where you live (including California and other U.S. states, the EEA, and the UK), you may have the right to:
- know and access the personal information we hold about you
- correct it
- delete it
- export a copy in a portable format
- object to or restrict certain processing
- appeal a denied request, where the law gives you that right
- opt out of any “sale” or “share” (we do not sell or share; this is a confirmation)
Email [email protected]. We will need enough information to verify it is you. We will not discriminate against you for exercising these rights. We will respond within the time the law requires (generally 45 days in California, 30 days in the EEA/UK, subject to permitted extensions).
You may also have an authorized agent submit a request. We will still verify you.
For payment-card data and Polar checkout records, contact Polar as well (see polar.sh/legal/privacy) or ask us and we will point you to the right place.
If you are in the EEA or UK, you may also complain to your local supervisory authority.
11. International transfers
We and our providers operate in the United States and other countries. If you use the Service from elsewhere, your information will be processed in the United States, which may have different data-protection rules than your country. Where a law requires a transfer mechanism, we rely on the provider’s appropriate safeguards (for example Standard Contractual Clauses used by Google, Cloudflare, or Polar).
12. Do not sell or share
We do not sell personal information and we do not share it for cross-context behavioral advertising as those terms are used in California and similar state laws. We have no consumer who we have actual knowledge is under 16 whose information is sold or shared, because we do not sell or share.
If that ever changes, we will update this policy and offer any required opt-out, including a “Do Not Sell or Share My Personal Information” link, before the change takes effect.
13. Changes
We may update this policy. The “Last updated” date will change. For a material change, we will post a notice on the Service or email the address on your account at least 7 days before it takes effect, unless a faster change is required by law or to address a security issue. If you do not agree, stop using the Service and request deletion. Continued use after the effective date means you accept the revised policy.
14. Contact
Organization 4901, LLC
Email: [email protected]
Web: trydoro.app
Do not send payment-card numbers to this address.