Last updated: July 20, 2026
Cyberdoro ("we", "us", "our") is a cyberpunk/lofi focus desktop. This page explains what information we collect, why, and what choices you have about it - in plain language, not legal filler.
1. Who we are
Cyberdoro is built and run by a small independent team based in the Czech Republic.
2. What we collect
If you don't sign in: nothing personal. Your timer, tasks, notes, and preferences stay only in your own browser and never leave your device.
If you create an account (Google, Discord, or email code), we store: your email and, if applicable, your name/photo from that provider; profile info you add (display name, bio, country, avatar); app content (tasks, notes, setups, presets, saved links) - synced across devices on Premium, kept local-only on free; activity/stats (focus minutes, streaks, XP, level); social features you use (friends, messages, room chat); and billing is handled entirely by Paddle - we never see your card details.
3. How we use it
To sign you in and sync your data, show your stats/streaks/leaderboard position, power social features you opt into, send account emails (sign-in codes, a welcome email), and fix bugs. We don't sell your data and we don't show ads.
4. Legal basis for processing (EU/EEA/UK users)
We rely on different legal bases depending on why we're processing your data: Contract - creating your account, syncing your data, and running your Premium subscription. Legitimate interest - keeping the service secure, preventing abuse, and improving Cyberdoro (kept balanced against your rights, and you can object - see "Your rights" below). Consent - optional things like adding a public bio/avatar, or opting into social features. Legal obligation - things like tax records for payments, handled by Paddle as Merchant of Record.
5. Who we share it with
A small set of trusted providers, each only getting what it needs: Supabase (database, auth, storage), Google/Discord (sign-in, if you choose), Resend (account emails), Paddle (payments), Netlify (hosting), and YouTube/SoundCloud/Spotify/Apple Music (embedded playback you choose, governed by their own policies).
Your display name, level, streaks, and public profile (if filled in) may be visible to other users via the leaderboard, Focus Rooms, and Focus Friends - private rooms and direct messages are visible only to those involved.
6. International data transfers
Some of our providers (including Supabase, Resend, Paddle, and Netlify) may process data on servers located outside the EU/EEA, including in the United States. Where that happens, we rely on the safeguards those providers have in place - such as Standard Contractual Clauses (SCCs) approved by the European Commission, or the provider's own compliance with equivalent frameworks - to keep your data protected to EU standards. You can contact us for more detail on the specific safeguards used by a given provider.
7. Cookies & local storage
We use browser local storage (not tracking cookies) to remember your preferences and, when signed out, your tasks/notes. No third-party ad or tracking cookies.
8. Data retention & deletion
We keep your account data as long as your account exists, so the app keeps working the way you left it. Roughly: profile, tasks, notes, presets, stats/XP - kept until you delete them or your account; room chat & direct messages - kept until you or the other party delete them, or your account is deleted; billing records - kept by Paddle for as long as required by tax/accounting law (typically several years), independent of your Cyberdoro account. You can delete your account any time from Account → Edit Profile → Delete Account, or by emailing us - this removes your personal data from our systems, aside from anything Paddle must legally retain for billing/tax purposes.
9. Your rights
If you're in the EU/EEA or UK, you have GDPR rights to access, correct, delete, or export your data, restrict or object to certain processing, and withdraw consent at any time where we rely on it. Contact us to exercise these - if unsatisfied, you can complain to your local data protection authority (in Czechia, the Úřad pro ochranu osobních údajů).
10. Children's privacy
Cyberdoro isn't directed at children under 16, and we don't knowingly collect their data. Contact us if you believe a child has created an account.
11. Security
We rely on our providers' security infrastructure and practices like row-level access controls. No online service can guarantee perfect security, but we take reasonable steps to protect your data.
12. Changes to this policy
We may update this policy as Cyberdoro grows. Significant changes update the date above and, where appropriate, we'll let you know in the app.