Privacy Policy
Daylines is designed as a private workspace. We collect the information needed to authenticate you, store your workspace, sync your changes, protect the service, and respond to your requests. We do not sell your personal information. We do not use your private workspace content to train AI models.
1. Who This Policy Covers
This Privacy Policy explains how Daylines handles information when you use the Daylines website and related services. It should be read together with our Terms of Service.
2. Information We Collect
| Category | Examples | Why we collect it |
|---|---|---|
| Account information | Email address, display name, Google account identifier, account creation time. | To create your account, identify you, show your profile, and support account recovery or deletion. |
| Authentication information | Session IDs, short-lived authentication challenges, passkey public keys, authenticator counters, user agent for sessions. | To sign you in, keep you signed in, verify passkeys, prevent replay attacks, and protect your account. We never receive your passkey private key. |
| Workspace content | Goals, notes, uploaded images, monthly and daily entries, metrics, focus session records, settings, and other content you add. | To store, display, sync, back up, and recover your workspace. |
| Technical information | IP address, request headers, device/browser information, error information, security logs. | To operate the service, troubleshoot issues, enforce rate limits, investigate abuse, and keep the service secure. |
| Local browser information | Theme preference, sidebar state, UI layout preferences, scroll restoration state. | To remember interface preferences on your device. This information is generally stored in your browser, not in your account record. |
3. How We Use Information
We use information to:
- provide, maintain, secure, and improve Daylines;
- authenticate you through Google Sign-In, sessions, and passkeys;
- save, sync, render, back up, and restore your workspace;
- detect abuse, debug problems, and protect users and the service;
- respond to support, privacy, account, deletion, export, or security requests;
- comply with legal obligations and enforce our Terms of Service.
4. How We Share Information
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
We may share information in these limited cases:
- Service providers. Hosting, storage, network, security, and infrastructure providers may process information only to help us operate Daylines.
- Google Sign-In. If you choose Google Sign-In, Google provides identity information such as your email address, verification status, name, and account subject identifier. Your use of Google is also governed by Google's own policies.
- CDN and browser-loaded resources. Fonts, editor libraries, icons, and UI modules are bundled and served by the app itself. The emoji picker's dataset is still loaded from a third-party CDN when you open it; that provider may receive technical information such as your IP address and request metadata for that one request.
- Legal and safety reasons. We may disclose information if required by law, legal process, or a good-faith belief that disclosure is necessary to protect rights, safety, security, users, or the service.
- Business transfer. If Daylines is transferred, merged, reorganized, or sold, information may transfer as part of that transaction, subject to this policy or a successor policy with notice where required.
5. Cookies and Local Storage
Daylines uses an HttpOnly session cookie to keep you signed in and a short-lived challenge cookie during sign-in or passkey registration. The app also uses browser storage for interface preferences such as theme, sidebar state, and scroll restoration. We do not use advertising cookies.
6. Data Retention
We keep account information and workspace content while your account is active or as needed to provide the service. Authentication challenges are short-lived. Sessions expire after a limited period. Workspace backups may be retained for recovery and then pruned according to operational limits. Uploaded images may be pruned when they are no longer referenced by your workspace.
When you request account deletion, we will delete or de-identify your account and workspace data within a reasonable period, except where retention is required for security, fraud prevention, legal compliance, backup integrity, or legitimate operational needs.
7. Security
We use technical and organizational measures designed to protect personal information, including server-side sessions, HttpOnly cookies, passkey public-key authentication, per-user workspace isolation, revision checks, and access controls for user images. No internet service is perfectly secure, so you should use a protected Google account, keep your devices secure, and remove passkeys from lost or shared devices.
8. Your Choices and Rights
You may update your display name in Settings. You may request access to your data, correction, export, or deletion by contacting us. Depending on where you live, you may have additional rights to know, access, correct, delete, or restrict certain uses of personal information. We will not discriminate against you for exercising privacy rights.
We do not sell personal information and do not share it for targeted advertising, so there is no sale or targeted-advertising sharing to opt out of.
9. Children
Daylines is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Daylines, contact us and we will take appropriate steps.
10. International Use
Daylines may be operated from, and information may be processed in, the United States or other locations where our service providers operate. If you use Daylines from another country, you understand that your information may be processed outside your country of residence.
11. Changes to This Policy
We may update this policy as the product or our practices change. If we make material changes, we will take reasonable steps to notify users, such as posting the updated policy in the service. The effective date above shows when this version took effect.
12. Contact
For privacy, security, account, export, or deletion requests, contact hello@frameworks.design.