FAQ: Privacy & Security
Q.Is my data safe?
Yes. Your data is encrypted in transit (TLS 1.3) and at rest. Security isn't a feature — it's a foundation we build everything on.
Q.Do you sell data to third parties?
Absolutely not. Dayopt's business model is simple: you pay for the product. No ads, no data selling. Your data is yours.
Q.Is my data used for AI training?
No. Dayopt has no AI analysis feature. The review metrics are calculated from your own records, nothing more.
MCP access on the Pro plan is a door for you to connect your own AI assistant to Dayopt. You decide whether to open it. Dayopt does not hand your data to anyone on its own.
Q.What happens when I delete my account?
All your data is permanently erased within 30 days of your deletion request. No lingering data after you leave.
Q.Can I export my data?
Yes. Your data is yours. You can export it anytime to migrate to other tools or analyze it yourself. No lock-in.
Q.Is Dayopt GDPR compliant?
Yes. We practice data minimization, obtain clear consent, and guarantee the right to deletion — in accordance with GDPR requirements.
Q.Where are your servers located?
We use reliable infrastructure that meets data safety and legal requirements. Please see our security page for details.
Q.Is there two-factor authentication (2FA)?
We prioritize security and employ secure authentication methods. Please check our security page for details.
Q.How are passwords managed?
Passwords are hashed with industry-standard algorithms. They are never stored in plain text.
Q.Is data backed up?
Yes. We perform regular backups to ensure data can be recovered in case of an incident.
Q.Do you undergo third-party security audits?
Security is an ongoing commitment. We implement best-practice security measures and review them regularly.
Q.How do you handle security incidents?
If a security incident occurs, we notify affected users promptly and respond with full transparency. We commit to honesty, not concealment.
Q.Is security reliable for an indie product?
Being indie means taking personal responsibility for every line of code. While we don't have a large security team, we apply industry-standard security practices — encryption, authentication, and access controls. Our small size also means faster decision-making and response times.
Q.How are cookies used?
Essential cookies support sessions and preferences. Browser Sentry, Vercel Analytics, and Speed Insights start only after you consent to analytics. Session Replay is disabled because the current SDK cannot guarantee removal of URL query strings from Replay payloads. In Production, sanitized server and edge error monitoring remains active regardless of that choice so we can diagnose service failures. Product and Website telemetry is kept in separate Sentry projects, and Sentry events exclude request bodies, email addresses, URL query strings, cookies, and authorization credentials. See our Cookie Policy and Privacy Policy for details.
Q.My company requires security approval. Can you provide documentation?
Of course. If you need detailed security documentation, please reach out. We'll provide information tailored to your company's security requirements.