DayLoop - Privacy Policy
Effective date: September 8, 2026
The short version
- What DayLoop is. A chat-style calendar assistant. You describe an event by
text, voice, a photo of a flyer/ticket, or a document (PDF, calendar
.ics, or text file), and DayLoop reads the time, place, and details and adds it to your shared household calendar. - What we collect. Your phone number (to sign in), your name, timezone, and preferences, the events and messages you create, and a device token so we can send reminders - plus, only if you choose to send one, an optional problem report (see §7).
- Photos and documents aren't kept. A photo or document you send is passed to our AI once to read the event, then discarded - we don't store your images or files.
- AI does the reading, and AI can make mistakes. The text (and any photo or document) you send is processed by our AI providers to extract event details. Like all AI, it can occasionally get a date, time, or detail wrong, so please review each event before you rely on it. We don't use your content to train AI.
- Helping the assistant learn (the safe way). When the AI runs into a tricky or unusual case - say it's unsure about a time, or you correct an event after adding it - our system quietly notes that something was tricky. These notes are anonymous numbers and labels only (like "the time was ambiguous" or "the user edited the date") - never your actual event text, names, or photos. We use them to spot rough edges and make the assistant more accurate for everyone.
- Voice stays on your device. Speech-to-text happens on your phone; we only receive the text transcript.
- We don't sell your data, and we don't show ads.
- Sharing is within your household. Everyone in your household sees the shared calendar and the chat. Outside your household, your events are private.
- You're in control. Export your data or delete your account in the app (household owners remove members first).
- Please don't share secrets. DayLoop only needs the who/what/when/where of events - never put passwords, card numbers, or other sensitive info in chat.
- Questions? [email protected].
Full Privacy Policy
1. Who we are
DayLoop ("DayLoop," "we," "us") is operated by OptimAIze LLC. This policy explains what we collect, why, and your choices. DayLoop is a mobile app (available on Android; iOS planned) - our website is a marketing page and does not provide app functionality.
2. Information we collect
You give us:
- Phone number - for sign-in via one-time passcode (OTP).
- Profile - name, timezone, locale, notification preferences, display color, badge style.
- Event content - the events you create (title, date/time, location, recurrence, who an event is for) and the chat messages you send to add them.
- Subscription choices - the plan you pick (handled by Apple/Google; see §6).
- Launch waitlist email (optional) - if you enter your email address on our website to be notified when DayLoop is available, we store only that email, and only to send you that notification. You can ask us to delete it at any time (see §11).
Created automatically:
- Usage counters - the number of events you successfully add each month (to enforce plan limits).
- Device push token - to deliver reminders and your daily summary.
- Sign-in bot-protection check - when you request a sign-in passcode, a Cloudflare Turnstile check runs to confirm you are a person and not an automated bot (see §8 and §12). Cloudflare processes minimal technical signals from your device for this; we receive only a pass/fail token, not those signals, and Turnstile does not track you across sites.
- Diagnostics - crash reports and aggregate, anonymous usage metrics (no event content, no names - see §7).
- Problem reports (optional, only when you send one) - see §7. Unlike the diagnostics above, a problem report DOES include recent chat content, technical logs, and (only if you turn it on) a screenshot of your screen, shared with your explicit consent.
Sent for processing but not stored by us:
- Photos and documents (PDF, calendar
.ics, or text files) you submit to add an event are sent to our AI provider to extract details, then discarded after extraction. We do not retain source images or files.
3. How we use your information
- To read your events and add them to your calendar.
- To send reminders and a daily summary you've opted into.
- To operate your household's shared calendar and subscription.
- To keep the service secure, prevent abuse, and fix crashes.
- To comply with law.
We do not sell your personal information, and we do not use your content to train AI models.
Legal bases (EEA/UK users). Where the GDPR applies, we process your data on these bases: performance of our contract with you (reading your events, running your calendar, reminders, subscriptions); consent (optional problem reports, and notifications where consent is required - withdrawable any time); legitimate interests (keeping the service secure, preventing abuse, and improving accuracy using the anonymous signals described in §7 - interests we've balanced against your rights); and legal obligation (where retention or disclosure is required by law).
4. AI processing
To turn your message into a calendar event, the text and any photo or document you send are processed by our AI provider(s), each of which may process a given request: Google (Gemini via Google AI Studio), the OpenRouter gateway (which routes the request to the same Google models), and Groq (which runs an open-source model). This means your event-related text, images, and documents transit those providers to perform extraction. We instruct our providers not to train on this content, and source photos and documents are not retained by us. The morning daily summary is also generated by AI from your day's events, and uses OpenWeatherMap to add the day's weather - sending only a city name derived from your timezone (no names, phone number, or event content).
AI can be inaccurate. Because event details are generated by AI, they may be wrong or incomplete; the AI proposes events and you confirm every add, so please review each event before relying on it. We do not use automated processing to make decisions about you that produce legal or similarly significant effects.
5. Voice input
Speech-to-text is performed on your device using the operating system's built-in speech recognition. We do not use a cloud speech vendor; we receive only the resulting text transcript, which is then handled like any typed message.
6. Payments
Subscriptions are sold through Apple's App Store and Google Play, which act as the merchant of record - they collect payment and own the receipt. We do not receive or store your payment card details. We use RevenueCat to validate store receipts and manage your subscription entitlement; Apple and Google remain the merchant of record. We receive confirmation of your subscription status to grant your household access.
7. Analytics & crash reporting
- Crash reporting via Sentry - to diagnose errors. We configure it to avoid capturing your event content or personal identifiers.
- Aggregate metrics (e.g., total active households, events per month) for internal product decisions. These are counts only - no user content and no personally identifying information.
- Edge-case quality signals. To keep the AI accurate, our system records an anonymous signal when the assistant hits a corner case - for example, when it was uncertain about a field, had to ask you a clarifying question, or when you edited an event shortly after adding it. Each signal is just numbers and short labels (e.g., the input type "text" or "image", or a tag like "ambiguous time"). It contains no event titles, no message text, no names, no phone numbers, and no photos, and it is not linked to your identity. We review these signals in aggregate only, to find and fix rough edges so the assistant works better for everyone.
- Problem reports (optional). If something is not working, you can tap Report in the app. After an explicit confirmation, this sends the developer your household chat's most recent messages (up to 50, which can include messages written by other members of your household) plus basic app details (app version, device platform, timezone, plan), recent technical logs from the app, an optional note from you, and only if you turn it on, a screenshot of your current screen. Reports are reviewed only by the developer, only to fix the problem, are never used for anything else, and are deleted automatically within 30 days. If a chat message is deleted in the app, its content is also removed from any stored report. Sending a report is always optional - declining changes nothing about your service.
8. How information is shared
- Within your household. A household shares one calendar and one chat; all members can see all events and the assistant's responses. If you join a household, the events you previously added are merged into that shared calendar. If the household owner removes you, the events you added remain in the household's calendar.
- Service providers (processors) who help us run DayLoop: Supabase (database, authentication, realtime), Twilio (delivers your sign-in passcode, via Supabase), Railway (backend hosting), Google (Gemini), OpenRouter, and Groq (AI extraction), OpenWeatherMap (daily-summary weather - receives only a city name derived from your timezone; no names, phone, or event content), RevenueCat (subscription management and receipt validation), Sentry (crash reports), Expo (push notifications), Cloudflare (bot and abuse protection at sign-in, via Turnstile - see the Turnstile Privacy Addendum), Apple/Google (payments).
- Legal - if required by law or to protect rights and safety.
- We do not sell personal information or share it for cross-context behavioral advertising.
9. No external calendar sync
DayLoop's calendar is self-contained. We do not connect to or sync with Google Calendar, Apple Calendar, Outlook, or any other external calendar.
10. Data retention
We keep your account and event data - including your chat history - while your account is active. In the app, the chat shows your recent messages, going back up to 30 days; earlier messages remain stored (so your history stays complete for data export and account records) and are deleted when you delete your account. Source photos and documents are deleted immediately after extraction. Problem reports you send (including any screenshot and logs you include) are kept for at most 30 days, then deleted automatically. When you delete your account, we delete your personal data, except where we must retain limited records for legal, security, or accounting reasons. Backups are purged on a rolling basis.
11. Your rights & choices
- Export the data you created - your profile and the events and messages you've added - in the app (GDPR data portability).
- Delete your account in the app, which removes your personal data. If you are a household owner with other members, you'll first need to remove them (or have the household empty) before deleting your account.
- Notifications - control reminders and the daily summary in your profile.
- Timezone - set or auto-detect your timezone (used to schedule correctly).
- Depending on where you live (e.g., EEA/UK (GDPR) or California (CCPA/CPRA)), you may have rights to access, correct, delete, or restrict processing, to object to processing based on legitimate interests, to data portability, and to not be discriminated against for exercising any of these. Contact [email protected] - we respond within the time the applicable law requires (generally 30 days; up to 45 days for California CCPA/CPRA requests, extendable where the law allows), and we may verify your request using your account phone number. Where permitted, you may use an authorized agent; we will verify the agent's authority and your identity.
- EEA/UK: if you're unsatisfied with our response, you may lodge a complaint with your local supervisory authority (in the UK, the ICO). Withdrawing consent (e.g., for problem reports or notifications) doesn't affect processing that happened before withdrawal.
- Our app and website do not respond to browser "Do Not Track" signals; because we do not sell or share personal information, Global Privacy Control signals do not change any setting for DayLoop users.
California residents (CCPA/CPRA). In the prior 12 months we collect these categories of personal information: identifiers (phone number, device push token), customer records (name), commercial information (subscription status), internet/network activity (usage counters, crash diagnostics), coarse location (your timezone), and user content (the events and messages you create). We collect it from you and your device, and use it to provide and secure the Service (see §3). We do not sell or share your personal information (including for cross-context behavioral advertising), and we do not use it for profiling that produces legal or similarly significant effects. You have the right to know, access, correct, and delete your information and to not be discriminated against for exercising these rights. To make a request, contact [email protected]; we verify your request using your account phone number.
12. Security
We use encryption in transit (TLS) and at rest, row-level security on our database, least-privilege access controls, and rate limiting. To protect the sign-in step from automated abuse, we use Cloudflare Turnstile, a privacy-preserving bot-detection tool that processes minimal technical signals to tell people from bots without tracking you across sites; see Cloudflare's Turnstile Privacy Addendum. When a chat message is deleted for the household, its content is erased from our records, not just hidden (including from any stored problem report). If we ever discover a breach affecting your personal data, we will notify you and the relevant authorities as applicable law requires. No system is perfectly secure; please help protect yourself by never sharing passwords, card/bank numbers, or other secrets in the chat - DayLoop only needs event details.
13. Children
DayLoop is intended for users 18 and older, and the Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). It is designed for adults managing a household calendar - which may include events about children (for example, "Leo's soccer practice"), entered by adults; a child's first name in an event or member label is content the adult chose to add. We do not knowingly collect personal information from children. If you believe a child has provided us information directly, contact [email protected] and we will delete it promptly. Accounts found to belong to users under 18 may be terminated (see the Terms of Service, §2).
14. International transfers
We operate in the State of Wyoming (United States) and use service providers that may process data in the United States and other countries. Where personal data of users in the EEA, UK, or Switzerland is transferred internationally, we rely on appropriate safeguards - such as the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum - as incorporated in our providers' data-processing agreements. Contact [email protected] for more information.
15. Changes to this policy
We may update this policy. We'll post the new effective date and, for material changes, notify you in the app. Continued use after an update means you accept it.
16. Contact
Questions or privacy requests: [email protected], OptimAIze LLC, 30 N Gould St, Ste N, Sheridan, WY 82801. Your use of DayLoop is also governed by our Terms of Service.