Privacy Policy
Our Core Privacy Commitment
Daylign™ is built on a privacy-by-design architecture. We never sell, monetize, rent, or trade your personal data, habit logs, or notes with third-party data brokers or advertisers. Your productivity records are strictly user-scoped and encrypted.
1 Introduction
Welcome to Daylign™ ("Daylign", "we", "our", or "us"). Daylign provides a serene, lightweight personal habit and activity tracking web application. This Privacy Policy details how we collect, handle, store, and protect your information when you access or use https://daylign.pages.dev.
By accessing or using Daylign, you agree to the collection and use of information in accordance with this policy.
2 Information We Collect
We practice data minimization and only collect information essential for core application functionality. Daylign operates on a free-tier model and does not collect payment card information or billing addresses.
- Account Data: Email address, display name, and unique Firebase User ID (UID). Guest users receive a temporary anonymous UID.
- Habit & Productivity Logs: Categories, checklists, routines, completion logs, reset cadences (daily, weekly, monthly), notes, and timer logs.
- Timestamps: Used to compute streaks, completion percentages, and cadence resets.
- Technical Metadata: IP address (processed at Cloudflare network edge for DDoS mitigation), browser type, and device OS.
- Local Storage & Essential Cookies: Minimal browser local storage items (
daylign-theme) and Firebase session tokens to preserve login state. No advertising cookies are used.
3 How We Use Your Data
- Synchronize habits, checklists, and notes across your devices in real-time.
- Authenticate your identity and safeguard your account against unauthorized access.
- Calculate automated cadence resets based on your local timezone.
- Maintain infrastructure security, uptime, and edge network stability.
- Respond to user-initiated feedback and technical inquiries.
4 Third-Party Infrastructure & Subprocessors
| Subprocessor | Purpose | Security Standards |
|---|---|---|
| Cloudflare Pages (Cloudflare, Inc.) | Global Edge CDN, Static Hosting & SSL/TLS Termination | SOC 2 Type II, ISO 27001, Edge Encryption |
| Google Firebase (Google LLC) | Authentication & Cloud Firestore User-Scoped Database | GDPR Compliant, AES-256 at rest, TLS 1.3 |
5 Data Security & User-Scoped Isolation
We maintain high-standard security defenses including:
- Firestore Security Rules: Programmatically restrict database read/write access so each user can only access records matching their verified authenticated UID.
- Encryption: HTTPS/TLS encryption in transit and AES-256 encryption at rest.
- Browser Protections: Strict Content Security Policy (CSP) and anti-clickjacking headers.
6 Your Rights (GDPR & CCPA/CPRA)
Regardless of your location, Daylign honors universal data protection rights:
- Access & Portability: Request a copy of your stored records and habit data.
- Rectification: Correct or update any inaccurate personal details.
- Erasure / Deletion: Request full permanent deletion of your account and all associated habit tracking history.
- Non-Discrimination: We will never penalize you for exercising your lawful privacy rights.
To exercise any privacy right or request account deletion, email us at daylign.help@gmail.com.
7 Children's Privacy
Daylign is not intended for or directed to children under 13 years of age (or under 16 in the EEA). We do not knowingly collect personal data from children.
Contact & Inquiries
For any questions regarding this Privacy Policy or Daylign's privacy practices, please contact us at:
Email: daylign.help@gmail.com