Skip to content
Foremost
TermsPrivacy

Privacy Policy

Effective date: August 5, 2026

Foremost (“Foremost,” “we,” “us,” or “our”) is operated by Roman Gurov, an individual based in Bali, Indonesia. This Privacy Policy explains how information is handled when you use the Foremost mobile application and related services (the “Service”). Roman Gurov is the controller of personal information processed for Foremost.

1. Information We Handle

Account information

When you sign in with Apple, Apple and our authentication provider, Supabase, provide or process an account identifier, authentication tokens, and, depending on your Apple settings and what Apple makes available, your email address and name. We use this information to create and authenticate your Foremost account.

Onboarding and product-use information

During onboarding, you may answer questions about your goals, occupation, distractions, focus habits, tasks you postpone, prior focus methods, estimated time spent on distracting apps, and preferred task source. We also collect information about how the Service is used, such as onboarding progress; connection of a task service; task creation or completion events and the selected task-source type; Screen Time permission results; counts of selected apps and categories; block-list mode and schedule choices; trial and paywall interactions; product identifiers for purchases; and account-deletion events. We do not send task titles to our analytics provider through the product events implemented in the current version.

Tasks and task-service information

  • If you use manual tasks, task titles and app-generated task identifiers are stored on your device.
  • If you connect Apple Reminders, Foremost requests Reminders permission and accesses the selected reminder list, including list identifiers and names and the identifiers, titles, and completion status of reminders needed to display, create, rename, and complete tasks. The selected list identifier and name are stored on your device and made available to Foremost’s iOS extensions so they can recount unfinished reminders.
  • If you connect Todoist, Foremost receives and stores OAuth access and refresh tokens and the identifiers, names, and types of your selected Todoist source and destination. Foremost uses these credentials to read relevant projects, filters, and tasks and to create, rename, or complete tasks at your direction. Tasks created through Foremost receive a foremost label in Todoist. Todoist credentials and source details are also available to Foremost’s iOS extensions so the app can recount unfinished tasks while the main app is not open.

Screen Time and blocking information

If you grant Screen Time authorization, Apple’s Family Controls interface supplies Foremost with opaque tokens representing the apps, app categories, or web domains you select. Foremost stores those tokens with your block-list settings, including schedule, blocking mode, limits, status, and app/category counts. Foremost uses this information on your device through Apple’s Screen Time frameworks to apply blocks and usage limits. Foremost does not receive the content of what you do inside selected apps, and the current implementation does not send your opaque app-selection tokens to our backend or analytics provider.

Subscription information

If you view a paywall, buy or restore a subscription, or manage a subscription, Apple and RevenueCat process purchase and subscription information. Foremost receives entitlement and customer-status information needed to determine whether Foremost Pro is active. We also record paywall and purchase events, such as the product identifier, successful restore, dismissal, or an error message.

Device and interaction analytics

When analytics is configured, PostHog receives the Foremost account identifier and email address, product-use events described above, native app lifecycle events, and automatically captured touch interactions. Screen autocapture is disabled in the current version. The PostHog SDK also stores analytics state on your device.

2. How We Use Information

We use information to:

  • create, authenticate, support, and delete Foremost accounts;
  • provide task lists and carry out task actions you request;
  • configure and enforce your selected blocking schedules, limits, and task-completion rules;
  • maintain Todoist authorization and refresh access tokens;
  • determine trial and subscription access and provide purchase-management features;
  • understand onboarding, feature use, reliability, and conversion so we can operate and improve Foremost; and
  • protect the Service, diagnose errors, and respond to account-deletion requests.

3. Where Information Is Stored

Much of Foremost’s functional data is stored locally on your device. This includes manual tasks, block lists and schedules, selected Screen Time tokens, selected task-source configuration, Todoist credentials, Apple Reminders list metadata, onboarding status, and trial/access state.

On iOS, information required by Foremost’s extensions is also stored in Foremost’s App Group container. This may include block-list settings and opaque Screen Time tokens, unfinished-task counts, usage-limit counters and pass expiration, access state, Todoist credentials and source details, or selected Apple Reminders list details. The App Group is shared only among the Foremost app and its Foremost extensions under Apple’s entitlement system.

Account data is processed by Supabase. Analytics data is processed through PostHog Cloud in the United States. Subscription and entitlement data is processed by RevenueCat and Apple. Todoist data is processed by Todoist when you connect that service. Apple Reminders and Screen Time information is also subject to Apple’s operating-system controls.

4. When We Share Information

We disclose information only as needed to operate the Service with the following categories of recipients:

  • Supabase, for authentication, account deletion, and the server functions used in the Todoist OAuth and token-refresh flow;
  • PostHog, for product, interaction, and lifecycle analytics used to understand and improve Foremost;
  • RevenueCat and Apple, for purchases, subscriptions, entitlements, restore, and subscription management;
  • Todoist, if you connect Todoist, to authorize access and read or modify Todoist data at your direction; and
  • Apple services and device frameworks, if you use Sign in with Apple, Apple Reminders, Screen Time, or App Store purchases.

These providers process information under their own terms and privacy policies. We may also disclose information if required by law or when reasonably necessary to protect the rights, safety, and security of users, the Service, or others.

We do not sell personal information, use it for advertising, or share it for cross-context behavioral advertising.

5. Permissions and Your Choices

Screen Time and Reminders access are controlled through Apple’s permission and device-settings interfaces. You may decline Screen Time access or skip app selection, although blocking features will not work without an app selection and the required authorization. You may decline Reminders access and use manual tasks or another supported source.

You may disconnect Todoist or Apple Reminders and change your task source in Foremost settings. Disconnecting removes the saved connection configuration from Foremost on that device, but it does not delete information already held by Todoist or Apple or necessarily revoke access at the provider level. You can also manage connected-app access through the relevant provider or device settings.

You may delete your Foremost account from Settings. Account deletion deletes the Supabase authentication user and then removes Foremost’s device-local account data, connected-task configuration, manual tasks, block lists, schedules, and native task-sync configuration from that device. Deleting your Foremost account does not cancel an App Store subscription; subscriptions must be managed through Apple or the subscription-management interface provided in the app.

Foremost currently does not provide an in-app data-export tool or an analytics opt-out setting. You may ask to access, correct, delete, or restrict our use of your personal information, or object to its processing, by emailing rgurov@yahoo.com. We may need to verify your identity before completing a request. These choices do not limit rights that cannot lawfully be limited.

6. Retention

Device-local information is generally retained until you delete it through the relevant feature, disconnect an integration, sign out, delete your account, or remove the app, subject to device backups and operating-system behavior outside our control. Signing out and account deletion trigger removal of Foremost’s account-specific local data and blocking schedules from that device.

Supabase account data is retained while your Foremost account remains active and is deleted when you delete the account. Limited copies may remain temporarily in provider backups or security logs under the provider’s standard retention practices. Analytics is retained only for as long as reasonably needed to understand and improve Foremost and is then deleted or aggregated. Subscription, transaction, security-log, and provider records may be retained for the periods required by Apple, RevenueCat, Supabase, PostHog, applicable law, fraud prevention, or dispute resolution. Todoist and Apple may retain information under their own policies after you disconnect them from Foremost.

7. Security

We use technical measures visible in the Service’s implementation, including HTTPS connections for the remote endpoints used by Foremost, authenticated bearer tokens for protected requests, caller authentication before server-side account deletion, and Apple App Group entitlements to scope data shared between Foremost and its extensions. Some sensitive functional data, including authentication sessions and Todoist credentials, is stored in the app’s local storage; the current application code does not add a separate encryption layer to that storage. No method of storage or transmission is completely secure.

8. Children

Foremost is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided information to us, contact rgurov@yahoo.com.

9. International Processing and Legal Bases

Foremost is operated from Indonesia. Our service providers may process information in the United States and other countries where they operate. Those countries may have data-protection laws different from the laws where you live. Where applicable law requires it, we rely on contractual or other recognized safeguards for international transfers.

Where a legal basis is required, we process information as necessary to provide the Service and perform our agreement with you; to comply with legal obligations; with your consent when requested for device permissions or connected services; and for our legitimate interests in securing, maintaining, and improving Foremost, provided those interests are not overridden by your rights.

10. Changes to This Policy

We may update this Privacy Policy when our practices or the Service change. We will post the updated policy and change the effective date above. If applicable law requires additional notice or consent for a material change, we will provide it.

11. Contact

Roman Gurov
Tirta Property
Petulu, Ubud District
Gianyar Regency, Bali 80571
Indonesia
Email: rgurov@yahoo.com

© 2026 Foremost
HomeTerms of Service