Privacy Policy
GDPR & US Compliant
1. Introduction
Welcome to DAYR ("we," "our," or "us"). We are deeply committed to protecting your privacy and ensuring that your personal data is handled securely and transparently. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our productivity and habit-tracking application.
2. EU Data Residency & GDPR
All User Data is Stored in the European Union. We utilize enterprise-grade cloud infrastructure located exclusively within the European Union. We do not transfer your personal data, daily reflections, or task matrices outside of the European Economic Area (EEA).
We operate in strict accordance with the General Data Protection Regulation (GDPR). You retain absolute sovereignty over your data, including the right to access, rectify, port, or permanently erase your digital footprint from our servers.
3. Data We Collect
- Account Information: Name, email address, and encrypted master password payloads.
- System Telemetry & Logs: Tasks, habits, system reflections, mood indicators, and energy levels entered explicitly by you.
- Technical Data: Minimal diagnostic data (IP address anonymization enabled) required to maintain system security and uptime.
4. Legal Basis for Processing
Under the GDPR, we process your data based on: your consent (when you create an account), the performance of our contract (providing the DAYR service to you), and our legitimate interests (securing our systems, preventing fraud, and improving algorithmic accuracy).
5. Algorithmic Processing
DAYR utilizes smart algorithms to generate insights (e.g., Optimal Sleep, Energy Peaks) based purely on the matrix of data you provide. This analysis occurs within your isolated data silo. We do not use your personal reflections or habit data to train public AI models, nor do we sell this data to third-party data brokers.
6. US State Privacy Rights (CCPA/CPRA)
We do not sell or share your personal information for cross-context behavioral advertising. California residents and users in applicable US states have the right to request access to the specific pieces of personal information we have collected, request deletion, and opt-out of any potential data sharing. To exercise these rights, please contact our Data Protection Officer.
7. Children's Privacy
DAYR is not intended for individuals under the age of 13 (in the United States) or 16 (in the European Union). We do not knowingly collect personal data from children. If we become aware that we have collected such data, we will immediately initiate a cryptographic wipe of that information from our servers.
8. Data Retention & Erasure
We retain your information only as long as your account is active. If you initiate a "Terminate Account" sequence or request data deletion via support, all associated tasks, habits, and reflections will be subjected to a cryptographic wipe and permanently deleted from our primary and backup EU servers within 30 days.
9. Contact & Data Protection Officer
To exercise your privacy rights, or if you have questions regarding this policy, please contact our Data Protection Officer at:
privacy@dayr.app
Last Updated: May 17, 2026