Privacy Policy
Last updated: September 23, 2026
This Privacy Policy explains how LUMIC, INC. ("Doomo", "we", "us"), the operator of the Doomo mobile application for iOS (the "App") and the website at doomoapp.com (together, the "Services"), collects, uses, shares and protects information when you use the Services. Doomo is built to put your information to as little use as possible — most usage data stays on your device.
1. Who we are
LUMIC, INC. operates the App under the name Doomo. Our mailing address is 3395 Nostrand Ave, Apt 1H, Brooklyn, NY 11229-4041, United States. You can reach us at vitaliy@fylyk.com.
2. Information we collect
The categories below describe everything we collect. We do not collect data we don't need.
2.1 Account information
When you sign in we receive identifiers from your chosen provider:
- Sign in with Apple — a stable Apple user identifier, your email (real or relay), and optionally your full name on first sign-in.
- Sign in with Google — your Google user ID, email and profile name.
- Email & password — your email address and a password. The password travels over TLS and is stored by our authentication provider (Supabase) only as a salted hash; we never store or log it in plain text.
Your locale and IANA timezone are also recorded so reminders fire at the right local time.
2.2 On-device usage data
Doomo uses Apple's Screen Time and DeviceActivity APIs to detect when you open apps you've explicitly added to your shield list. Apple processes this data on-device — Doomo never receives the content of your screens, your messages, your browsing history, or apps you didn't add to the shield list.
From this the App keeps simple daily totals: how many times you opened shielded apps, and the focused minutes you reclaimed. Doomo does not measure or record how long you spend inside an app — it knows only that a shield came down, not what you did after it. It also keeps per-app open counts — how many times you opened one particular app you added a rule for. These counts are Doomo's own record of the shields it put up and you tapped through; they are not read from Apple's Screen Time reports, which Apple keeps sealed on your device and which no app, including this one, can send anywhere.
Your rules and focus schedules do sync to your Doomo account while you are signed in. A synced rule carries the app's name and bundle identifier (for example "Instagram" and com.burbn.instagram) alongside its price, daily limit and unlock length. It does not carry the Screen Time token that actually identifies the app to iOS: Apple keeps that on-device and it cannot be moved, which is why a new iPhone asks you to pick the app again before that rule can shield anything.
While you are signed in, those daily totals — opens, focused minutes, and your per-app open counts, keyed by calendar date — sync to your Doomo account (hosted on Supabase) roughly twice a day, so your streaks and history survive a reinstall or a new iPhone. These daily-total rows contain counts, calendar dates, your account identifier, and rule identifiers. A per-app count is filed under the rule identifier of the rule you created for that app — an identifier your account already holds, alongside the app name you already chose to sync with the rule itself. These counts add how often you opened each app to the rule information your account already holds. No screen content is included, and the Screen Time token is never among them. They are deleted with your account, as are your synced rules and schedules.
Why we keep them at all: so the app can show you your own history — which apps you reached for most, and what that cost you — after you reinstall Doomo or move to a new iPhone. That is the only use. Per-app counts are never sold, never shared for advertising, and never used to build a profile of you.
Your opens log — kept on your iPhone, never uploaded
So the App can draw you a timeline of your own day, your iPhone keeps a record of every open it granted you — whether you paid for it, got it free, took the emergency escape, or were only practising, and whether or not an investing account is connected. Each entry holds the moment the open started, the local calendar day it started on, how many minutes it bought, when it ended, the name the App had for that app at the time, and — where the open placed one — a reference to the resulting order.
This log stays on your iPhone. It is not uploaded to your Doomo account, it is not sent to us or to anyone else, and no part of it is used for advertising or profiling. Apple's own guidance is that data processed only on device is not "collected"; we describe it here anyway, because it is a record of your behaviour and you should know it exists.
It stays on your iPhone when you sign out, so the timeline you built is still there when you sign back in. It is kept under your own account identifier, and no other account signing in on that iPhone can read it. If an account is not used for 30 days, its log is deleted from the device on the next launch — and signing a different account into the App erases the previous one's log outright, along with everything else that account left behind.
You can delete it sooner. In Settings, under Your timeline, the switch "Keep a log of my opens on this phone" stops the App writing new entries and deletes the ones already there. Deleting the App removes it along with everything else it kept on the device.
2.3 Purchases
Doomo does not currently sell anything in the App. If we offer an in-app purchase in the future, it will be processed by Apple, we will never see your payment card, and this policy will be updated before it launches.
2.4 Push notifications
With your permission, the App registers an Expo push token associated with your account. We use it only to deliver notifications you have opted into (focus reminders, streak updates, Doomo Investing status, weekly summaries).
2.5 Doomo Investing data (only if you opt in)
The investing feature is optional. It connects Doomo to an investing account you already own through a third-party account-connectivity service. When you enable it:
- Identity verification ("KYC") happens directly with your own brokerage, outside Doomo. Doomo does not collect or store your government ID, SSN or tax forms.
- Doomo receives the minimum data needed to display your account state: account status, cash balance, positions, recent orders.
- So your data follows you across devices and survives reinstalling the app, a snapshot of your holdings — your positions and portfolio value — and your unlock orders are stored in your Doomo account (on Supabase), linked to your user ID. Your brokerage account number is stripped out before this snapshot leaves your device. This is your own data in your own account; it is never sold or shared for advertising.
Doomo never sees or stores your account username or password. The connection is authorised by you through the provider's portal, and Doomo holds only a connection reference — never those credentials.
2.6 Diagnostics & analytics
We use the following diagnostic tools:
- Sentry for crash reports. Stack traces are automatically scrubbed of API keys, tokens, secrets, tax IDs and SSNs before being transmitted.
- No product analytics. The App does not send usage analytics to any analytics company, collects no advertising identifier, and does no cross-app tracking. If that ever changes, this policy will be updated first.
- Supabase as our application database for your account, profile, preferences, the synced daily activity totals described in section 2.2, and — if you use Doomo Investing — the holdings snapshot and orders described in section 2.5.
3. How we use your information
- To run the App: authentication, focus sessions, shield rendering, ledger math.
- To provide the investing feature if you opted in: relay the order instruction you approved to your own brokerage, and display your positions.
- To send notifications you've turned on.
- To detect and fix crashes and bugs.
- To understand which features are used so we can improve them.
- To enforce our Terms and prevent abuse.
We do not sell or rent your personal information. We do not use your data to train third-party advertising models, and we do not run third-party advertising in the App.
4. Legal bases (EEA / UK users)
Where the GDPR or UK GDPR applies, our legal bases are: performance of contract (running the App and Doomo Investing), consent (notifications, optional analytics), legitimate interests (crash diagnostics, fraud prevention), and compliance with legal obligations (financial recordkeeping for Doomo Investing).
6. Data retention
Account data is kept while your account is active. If you delete your account we erase your profile, focus history and ledger within 30 days, except records we must keep to satisfy legal obligations (e.g. financial recordkeeping under SEC and FINRA rules for Doomo Investing transactions, which can be up to seven years).
Crash and analytics events are retained for a maximum of 12 months.
Your opens log (§2.2) is not kept by us at all, so there is no period for us to state: it lives on your iPhone and nowhere else. On the device it is kept for as long as you keep using the App, and deleted after 30 days with no activity on that account — the same as if the App had been removed. You can end it sooner by turning off the switch in Settings › Your timeline, which deletes it immediately, or by deleting the App.
7. Security
Sessions use PKCE; data in transit is encrypted with TLS 1.2+; Supabase databases are encrypted at rest. API keys, OAuth tokens and any credentials you provide are stored in iOS Keychain via expo-secure-store. No security is absolute — please use a strong, unique passcode on your device and notify us promptly if you suspect unauthorised access.
8. Your rights
Depending on where you live, you may have the right to access, correct, port, delete or restrict processing of your information, and to object to certain processing. You also have the right to lodge a complaint with your local data protection authority.
Email vitaliy@fylyk.com from the address associated with your account to exercise any of these rights — we respond within 30 days.
California residents: we do not "sell" or "share" personal information as those terms are defined under the CCPA / CPRA. We do not process sensitive personal information for purposes that would trigger the right to limit. You retain all access, deletion and correction rights described above.
9. Children
Doomo is not directed to children under 13, and Doomo Investing is restricted to users 18 or older. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
10. International transfers
Our processors are mostly based in the United States. Where applicable we rely on the EU Standard Contractual Clauses and equivalent UK addenda to lawfully transfer personal information outside the EEA / UK.
11. Apple-specific disclosures
Doomo uses Apple frameworks subject to additional Apple guidelines:
- Family Controls / Screen Time / DeviceActivity — used solely to detect and shield apps you select. The data Apple gives these APIs stays on-device: the Screen Time tokens that identify your apps to iOS cannot be moved off the phone, and the DeviceActivity reports run in a sealed extension that is not allowed to make network requests at all. Doomo's own tally of the shields it raised — see 2.2 — is the only thing that reaches your account, and none of it is used for advertising, retargeting, or sold to third parties, in compliance with Apple's Family Controls Distribution policy.
- Sign in with Apple — we only request your name and email; we honour Apple's relay-email forwarding.
- App Tracking Transparency — Doomo does not track you across apps or websites owned by other companies, and therefore does not show the ATT prompt.
12. Changes to this policy
We will revise this policy from time to time. Material changes will be announced in-app at least 14 days before they take effect. Continued use of the Services after a change means you accept the revised policy.
13. Contact
Doomo · Attn: Privacy
3395 Nostrand Ave, Apt 1H
Brooklyn, NY 11229-4041
United States
vitaliy@fylyk.com