Konjo ("we", "our", "the app") is an ADHD-friendly productivity application designed to help you manage tasks, build habits, and stay focused. This Privacy Policy explains what data we collect, how we process and protect it, and your rights as a user.
By using Konjo, you agree to the collection and use of information as described in this policy.
| Data | Purpose | Storage |
|---|---|---|
| Email address | Authentication, account recovery | Server (PostgreSQL) |
| Password | Authentication | Server (Argon2id hash — we never store plaintext) |
| First name, last name | Personalization (optional) | Device only |
| Profile photo | Display in app (optional) | Server (encrypted storage) |
| Data | Purpose | Storage |
|---|---|---|
| Tasks | Task management (title, description, due dates, priority) | Device + Server (synced) |
| Habits | Habit tracking (name, frequency, completions, streaks) | Device + Server (synced) |
| Focus sessions | Pomodoro timer tracking (start, duration, completion) | Device + Server (synced) |
| XP events | Gamification progress (points earned, level, streaks) | Device + Server (synced) |
| Quick Notes | Fast text/image capture | Device + Server (synced) |
| Data | Purpose | Storage |
|---|---|---|
| Encrypted notes | Private note storage | Server (AES-256-GCM encrypted, per-user key) |
| Vault files | Private file storage | Server (encrypted storage) |
Vault data is protected by biometric authentication (fingerprint/face) on your device. Without biometric verification, vault content cannot be accessed — even by us.
| Data | Purpose | Storage |
|---|---|---|
| Push notification token | Sending bedtime reminders and habit reminders | Server |
| Device type (Android) | Compatibility | Not stored persistently |
We do NOT use your data for:
Konjo is designed to work offline. Your data is stored locally on your device (SQLite database) as the primary source of truth. When internet is available, data syncs to our servers every 30 seconds.
| Layer | Protection |
|---|---|
| In transit | HTTPS/TLS for all server communication |
| Passwords | Argon2id hashing (16-byte salt, 64MB memory, 3 iterations) |
| Vault notes | AES-256-GCM with per-user key derived via HKDF |
| Vault files | Stored in encrypted S3-compatible storage |
| Tokens | JWT access tokens (15-min expiry) + opaque refresh tokens in Redis |
| Device storage | Hardware-backed keystore for tokens (Android Keystore) |
When you use Konjo on multiple devices or after being offline:
We do NOT share your personal data with third parties, with the following exceptions:
We do NOT:
You have the right to:
| Right | How to Exercise |
|---|---|
| Access your data | Export available in-app (planned) |
| Correct your data | Edit tasks, habits, notes directly in the app |
| Delete your data | Delete your account — all data removed within 30 days |
| Portability | Request a copy of your data in machine-readable format |
| Withdraw consent | Uninstall the app and/or delete your account |
To exercise data portability or account deletion, contact: admin@konjo.com.es
Konjo is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us immediately at admin@konjo.com.es and we will delete it.
We may update this Privacy Policy from time to time. Changes will be posted in the app and on this page. Your continued use of Konjo after changes constitutes acceptance of the updated policy.
Material changes (e.g., new data collection, sharing with third parties) will be communicated via in-app notification at least 14 days before taking effect.
For privacy questions, data requests, or concerns:
We aim to respond to all privacy requests within 30 days.
This policy is governed by the laws of Spain and the European Union. For EU residents, data processing complies with GDPR requirements.
© 2026 Konjo. All rights reserved.
konjo.com.es