Privacy Policy
Effective date: September 1, 2026
This Privacy Policy explains how Michael Prince, a sole proprietor trading as DayKeep ("we", "us", or "our"), collects and uses your information when you use DayKeep (the "Service"). We aim to collect only what we need to run the Service.
1. Information we collect
- Account information: the email address you register with and a securely hashed password. We never store your password in plain text. If you sign in with Google, we receive your email address and a Google account identifier from Google instead of a password. We never see or store your Google password.
- Wait-list email address: while sign-ups are closed you can join a wait list. We store only the address you give us, so that we can send you an invitation when a place opens. Joining sends you no mail at all, not even a confirmation, and the address is not added to any marketing list. Ask us and we will remove it.
- Content you create: your lists, tasks, subtasks, notes, file attachments, and any event or workout data you log. This is the data the Service exists to store for you.
- Technical and log data: limited information such as IP address, timestamps, and basic request details, used to operate, secure, and troubleshoot the Service (for example, rate limiting and abuse prevention).
- Billing information: if you buy a paid plan, your payment details are collected directly by our payment processor, Stripe (see "Service providers" below). We store only your subscription status and a Stripe customer reference, never your card number.
2. Cookies
We use first-party cookies only. We do not use advertising
cookies, analytics cookies, or any cross-site tracking. All three of the cookies below are
HttpOnly, meaning no script on the page can read them:
session: keeps you signed in. It is a persistent cookie so that an installed app survives a device restart without asking you to sign in again.google_oauth_state: set only when you begin a Google sign-in. It is limited to the sign-in path, expires after 10 minutes, and is deleted the moment the sign-in finishes. Its only purpose is to protect that sign-in against cross-site request forgery.oauth_consent: set only while you are on the screen approving another app or agent's request for access to your account. It is limited to the approval path, expires after 10 minutes, and is cleared when you finish.
Separately, the app stores your data and preferences locally in your browser (local storage and IndexedDB) so it keeps working offline. That is on your device, not a cookie, and clearing your browser data removes it.
3. How we use your information
We use your information to provide, maintain, and secure the Service; to sync your data across your devices; to send you transactional email such as account verification, password resets, and reminders you enable; and to comply with legal obligations. We do not use your task content for advertising.
4. Visitor counting
We count unique visitors so we can see whether the Service is being used. This is our own counting. There is no third-party analytics provider, no analytics cookie, and no profile is built.
- When you are signed in, the count keys on your account.
- When you are not signed in, it keys on a one-way hash of your IP address mixed with a secret that rotates every day. That makes a day's visitors countable but deliberately unlinkable from one day to the next: we cannot tell that yesterday's anonymous visitor and today's are the same person, and we chose that trade-off on purpose.
5. Content loaded from other services
Two parts of the app cause your browser or our server to contact someone else:
- Exercise videos (YouTube). Exercises can carry a video. Thumbnails load
from YouTube's image servers, and playing one loads a YouTube player in privacy-enhanced
mode (
youtube-nocookie.com). When that happens, your browser contacts Google directly and Google receives your IP address and the video requested, under its own privacy policy. Nothing about your tasks or notes is sent. - Weather. Forecasts come from the US National Weather Service. Those requests are made by our servers, not your browser, so your device and IP address are never exposed to them; only the location whose forecast is needed.
6. Links you choose to share
If you publish a share link for a list, a task or a note, anyone who has that link can read what you shared, without signing in. That is what the feature is for, but it means the decision to make something readable is yours, not ours. You can revoke a link at any time, which stops it working immediately.
7. Apps and agents you connect
You can issue API tokens, or approve another application or AI agent, to work with your data on your behalf. Anything you grant can read (and, if you allow it, change) the data covered by that grant, and what it then does with the data is governed by that party, not by us. You can see and revoke every token and connected app from your settings at any time.
8. Service providers (sub-processors)
We share limited information with service providers who process it on our behalf, only as needed to run the Service:
- Resend: sends our transactional email (verification, password reset, and notification messages). Your email address and message contents are processed to deliver that mail.
- Stripe: processes payments for paid subscriptions. Checkout and billing management happen on Stripe-hosted pages, so your card details go directly to Stripe and are never sent to or stored on our servers. We receive only what we need to operate your subscription (such as your subscription status and a customer reference), and Stripe handles your payment information under its own privacy policy at stripe.com/privacy.
- Google: if you choose to sign in with Google, Google authenticates you and tells us your email address and an account identifier. Google's handling of that is covered by its own privacy policy at policies.google.com/privacy. Exercise video playback also involves Google, as described above.
- US National Weather Service: receives the location a forecast is needed for, from our servers. No account information is sent.
- Hosting and infrastructure: our servers and database, which store your account and content so the Service can operate.
These providers are bound to use the information only to provide their services to us.
9. We do not sell your data
We do not sell or rent your personal information, and we do not share it with third parties for their own marketing.
10. Data retention and deletion
We keep your information for as long as your account is active. You can delete individual data from within the app, or request deletion of your entire account by emailing support@daykeep.io. When you request deletion, we remove your personal data from the live Service within a reasonable period. Copies may survive for a while in our database backups, which are kept on our own servers and are pruned automatically as newer ones are taken; deletion reaches those copies when they age out rather than immediately.
11. Your choices and rights
You can access and update your data in the app, export it at any time using the built-in export feature, and request correction or deletion by contacting us. Depending on where you live, you may have additional rights under applicable privacy laws; we honor those rights as required.
12. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. Family plan seats are for household members invited by an adult account owner. If you believe a child has provided us information, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you.
14. Contact
Questions about your privacy or this policy? Email us at support@daykeep.io.