Privacy Policy
How Dayopt handles your personal information
Last Updated: 2026-08-17
Introduction
Dayopt (the "Service") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, and protect your personal information.
Information We Collect
- Account Information (email address, name, profile picture)
- Service Usage Data (tasks, calendar, settings)
- Contact correspondence (name, email address, category, message, and, for authenticated Product submissions, limited application and browser environment details)
- Minimal Technical Diagnostics (application version, route path, browser or device type, and error or trace identifiers). Sentry events exclude request bodies, email addresses, URL query strings, cookies, and authorization credentials.
- Cookies and similar technologies
How We Use Your Information
- Providing, operating, and improving the Service
- User support and responding to inquiries
- Preventing unauthorized use and maintaining security
- Production server and edge error monitoring for service reliability, plus browser error monitoring and performance analytics only after analytics consent
- Sending important notices and service updates
Third-Party Services
We work with the following service providers:
- Supabase (authentication & database)
- Vercel (hosting; Vercel Analytics and Speed Insights only after analytics consent)
- Sentry (Production server and edge error monitoring; browser error monitoring only after analytics consent; Session Replay is disabled). Product and Website data are kept in separate Sentry projects.
- Resend (outbound contact and transactional email delivery)
- Cloudflare Email Routing (routing inbound support email to the support mailbox)
- Google Gmail (access-controlled destination mailbox for support correspondence)
- Cloudflare Turnstile (bot protection for forms)
These providers manage information according to their respective privacy policies.
Data Ownership
You retain full ownership of all data you create, upload, or store through the Service. Dayopt does not claim any intellectual property rights over your data.
- You may export your data at any time through the account settings page. Exports are available in standard formats (JSON, CSV) to ensure portability.
- Upon account deletion or service discontinuation, you will have at least 30 days to export your data before it is permanently removed from our systems.
Sub-Processors
We use the following providers to assist in providing the Service:
- Supabase, Inc. — Authentication and database services. Data location: AWS US-East-1 (N. Virginia, USA)
- Vercel, Inc. — Hosting, serverless functions, and edge delivery. Vercel Analytics and Speed Insights run in the browser only after analytics consent. Data location: Global Edge Network
- Functional Software, Inc. (Sentry) — Sanitized Production server and edge error monitoring runs regardless of analytics consent. Browser error monitoring runs only after analytics consent. Session Replay is disabled because the current SDK cannot guarantee removal of URL query strings from Replay payloads. Product and Website data are kept in separate projects. Sentry events exclude request bodies, email addresses, URL query strings, cookies, and authorization credentials. Data location: United States
- Stripe, Inc. — Payment processing and subscription management. Data location: United States. Stripe is PCI DSS Level 1 certified. We do not store credit card numbers on our servers.
- Anthropic, PBC — AI-powered features (chat, weekly review insights). Data location: United States. Your data is processed under Anthropic's API terms and is not used for model training.
- OpenAI, LLC — AI-powered features (optional, when user provides their own API key). Data location: United States. Data processed via API is not used for model training per OpenAI's API data usage policy.
- Resend, Inc. — Outbound contact and transactional email delivery (including account notifications and billing confirmations). Data location: United States
- Upstash, Inc. — Rate limiting and abuse prevention via serverless Redis. Data location: United States. Hashed technical request identifiers and request counts are stored temporarily.
- Cloudflare, Inc. — Email Routing receives mail addressed to support@dayopt.app and forwards it to the access-controlled support mailbox. Data is processed on Cloudflare's global network.
- Google LLC — Gmail is the access-controlled destination mailbox used to receive, manage, and reply to support correspondence. Data location depends on Google's infrastructure and account configuration.
- Cloudflare, Inc. — Turnstile bot protection for forms. A Turnstile token and the requester's IP address are sent to Cloudflare for verification. Data is processed on Cloudflare's global network.
- Axiom, Inc. — Storage and search of runtime and build logs delivered via Vercel Log Drains. Includes our application's structured logs and Vercel request log metadata such as IP address and browser/user-agent information. Request log path and query strings are excluded from what we send. Data location: United States.
We will notify you at least 30 days before engaging a new sub-processor or making material changes to existing sub-processor arrangements.
International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence.
- Primary data storage: AWS US-East-1 (N. Virginia, USA) via Supabase. Edge caching and serverless functions are distributed globally via Vercel.
- For transfers from the EU/EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate data protection.
- For transfers from Japan, we comply with the Act on the Protection of Personal Information (APPI) requirements for cross-border data transfers, including obtaining consent and ensuring the recipient country provides an equivalent level of protection.
Legal Basis for Processing
We process your personal data on the following legal bases (as applicable under GDPR and similar regulations):
- Contract Performance — Processing necessary to provide the Service you have signed up for, including account management, task storage, and calendar synchronization
- Consent — Browser Sentry, Vercel Analytics, and Speed Insights run only after you opt in to analytics
- Legitimate Interests — Sanitized Production server and edge error monitoring, security monitoring, and fraud prevention, where these interests are not overridden by your rights
- Legal Obligation — Where processing is required to comply with applicable laws, regulations, or legal proceedings
Data Processing Details
The following describes how we process each category of personal data:
- Account Data (email, name, avatar) — Processed to create and manage your account, authenticate your identity, and communicate service-related notices
- Usage Data (tasks, plans, calendar entries, settings) — Processed to provide core Service functionality, generate productivity insights, and improve features
- Minimal Technical Diagnostics (application version, route path, browser or device type, and error or trace identifiers) — Sanitized server and edge diagnostics are processed in Production to investigate unexpected failures. Browser diagnostics and performance data are processed only after analytics consent. Sentry events exclude request bodies, email addresses, URL query strings, cookies, and authorization credentials.
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you. AI-powered features (such as weekly review insights) provide suggestions only and do not make decisions on your behalf.
You can export your data in standard formats (JSON, CSV) at any time from your account settings. We support data portability to ensure you can move your data to another service if desired.
AI-Powered Features
The Service includes optional AI-powered features that process your data to provide productivity insights and suggestions:
- When you use AI features, the following data may be sent to our AI providers (Anthropic or OpenAI): task titles and descriptions, time tracking data, energy mapping data, and calendar entries. This data is used solely to generate contextual suggestions and insights.
- Your data is NOT used to train AI models. Both Anthropic and OpenAI process API requests without using the data for model training or improvement, as specified in their respective API data usage policies.
- You may optionally provide your own API key (Bring Your Own Key) for OpenAI or Anthropic. When using your own key, requests are sent directly to the provider under your own API agreement. Your API key is encrypted and stored locally on your device, not on our servers.
- AI-generated content is provided for informational purposes only. We do not guarantee the accuracy, completeness, or reliability of AI outputs. You should review all AI-generated suggestions before acting on them.
- AI features are optional. You can use the Service without enabling any AI functionality. Free tier users are limited to 30 AI interactions per month.
Google Calendar Integration
If you connect a Google account, Dayopt reads your calendars so you can plan your day around commitments you already have. This is optional and one-way: Dayopt never creates, modifies, or deletes anything in your Google Calendar.
- What we access — the email address and account identifier of the Google account you connect, the list of your calendars so you can choose which ones to import, and the events on the calendars you select.
- The connected account — we store the account's email address and its stable Google account identifier. We show you the email address so you can tell your connected accounts apart, and we use the identifier to confirm a reconnection is for the same account. The email address and the account identifier are deleted the moment you disconnect the account. Any technical records that might otherwise remain are removed by routine automated cleanup.
- What we store — from each event, we keep its identifier, title, description, start and end time, whether it is active or cancelled, and the identifier and name of the calendar it came from, together with the usual account and sync bookkeeping we attach to any record we store (which of your connections it belongs to and when it was last synced). For a calendar someone shared with you, that identifier may be the sharing account's email address. Attendees, guest email addresses, locations, conferencing links, and attachments are never used, stored, or logged.
- Your calendar selection — separately from the events, we store which calendars you chose (each one's Google identifier and name) along with a sync token that lets the next sync fetch only what changed. This is deleted when you deselect the calendar, disconnect the account, or delete your Dayopt account.
- How much we read — the 90 days before and after now. Most syncs only ask Google what changed since the last one; about once a day we re-read the whole window, so the range keeps up with the current date. All-day events are not imported.
- How we use it — to help you plan around commitments you already have. We show these events alongside your own plan in your Dayopt timeline. Imported events are visible only to you, and we never share them with anyone else unless you set up a way for us to — for example by granting another application permission to read your entries, or by turning on a calendar feed you subscribe to from another calendar app.
- How it is protected — the credentials that let Dayopt read your calendar are encrypted before they are stored.
- How to stop it — disconnect the account at any time from Settings. We first delete every imported event you have not built on; if that step fails, we stop there and nothing else changes, so you can safely try again. Once it succeeds, we ask Google to revoke our access and delete the stored credentials and the connected account's email address. If Google had just issued us a replacement key, that replacement stays in an internal queue, encrypted, for up to 24 hours so that we can revoke it as well. If you have already turned an imported event into an entry of your own, we keep both, so we are not deleting part of your history without asking.
- If you delete your Dayopt account — everything above is deleted, including imported events we would otherwise have kept. We keep a record that the revocation happened, including the identifier of the Google account it applied to, for up to 90 days, so that we can confirm it was carried out and notice if it silently failed.
- Revoking from Google's side — you can remove Dayopt's access directly from your Google account's security settings at any time, without going through us.
Dayopt's use of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. We do not sell this data, do not use it for advertising, and do not use it to train AI or machine learning models.
Data Retention
- We retain your data while your account is active
- Data is permanently deleted within 30 days after account deletion
- Support correspondence is reviewed periodically and deleted after the inquiry is resolved when it is no longer needed, except where retention is required for legal, security, or dispute-handling purposes
- Except where retention is required by law
Your Rights
- Right to access your personal information
- Right to correct your personal information
- Right to delete your personal information (right to be forgotten)
- Right to data portability
- Right to object to processing
- Right to lodge a complaint with a supervisory authority (e.g., your local data protection authority under GDPR, or the Personal Information Protection Commission in Japan)
To exercise these rights, please contact us through the settings page or contact form.
Security Measures
We implement industry-standard security measures to protect your personal information from unauthorized access, loss, damage, alteration, and disclosure.
- SSL/TLS encryption for data transmission
- Access control and authentication systems
- Regular security audits
About Cookies
We use essential cookies and local storage to operate the Service. Optional browser telemetry is controlled by your analytics consent.
- Essential Cookies (maintain login state)
- Optional Analytics Technologies (browser Sentry, Vercel Analytics, and Speed Insights)
- Preference Cookies (save user settings)
If you decline analytics, optional browser telemetry does not start and core features remain available. Sanitized Production server and edge error monitoring continues because it is required to diagnose service failures.
For detailed information about our use of cookies, please see our Cookie Policy.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33
- Inform affected users without undue delay when the breach is likely to result in a high risk to their rights and freedoms
- Document all breaches, including the facts, effects, and remedial actions taken
- Take immediate steps to contain and remediate the breach, and implement measures to prevent recurrence
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know — You have the right to request information about the categories and specific pieces of personal information we have collected about you
- Right to Delete — You have the right to request deletion of your personal information, subject to certain exceptions
- Right to Opt-Out of Sale — We do not sell your personal information to third parties. We do not share your personal information for cross-context behavioral advertising.
- Right to Non-Discrimination — We will not discriminate against you for exercising any of your CCPA/CPRA rights
- Categories of personal information we collect: identifiers (email, name), commercial information (subscription status), internet activity (usage data, device info), and inferences drawn from the above
To exercise your California privacy rights, contact us at support@dayopt.app or through your account settings.
Children's Privacy
Our Service is not intended for children under 13 years old, and we do not knowingly collect personal information from them.
Policy Changes
This Privacy Policy may be updated due to legal changes or business reviews. We will notify users in advance of any significant changes.
Contact Us
If you have any questions or concerns about privacy, please contact us at:
Email: support@dayopt.app
Website: https://dayopt.app