Daydash Privacy Policy

Effective Date: September 4, 2025

Last Updated: September 5, 2026

Axil LLC (“we,” “our,” or “us”) values your privacy. This Privacy Policy explains how we collect, use, and protect information about you when you use our mobile application, Daydash (the “App”). By using the App, you agree to the terms of this Privacy Policy.


1. Information We Collect

We may collect the following types of information:

  • Personal Information: Information you provide directly, such as your name, email address, phone number, or account credentials when creating an account or contacting support.
  • Usage Data: Information about how you use the App, including log data, device type, operating system, app version, IP address, and browsing activity within the App.
  • Location Data (if applicable): Approximate or precise location data if you enable location services on your device.
  • Cookies & Similar Technologies: We use cookies and similar on-device storage to keep you signed in and for the analytics described in Section 3. That includes a first-party analytics cookie, set on daydash.io and on the App’s sign-in pages, that holds a random identifier so we can count visits and, if you go on to create an account, link that visit to it. We do not use advertising cookies or mobile advertising identifiers.
  • AI Assistant Conversations: If you use the AI assistant, the messages you send and the responses you receive. Conversations are stored encrypted, as described in Section 5.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the App.
  • Improve, personalize, and expand our services.
  • Communicate with you (including customer support, updates, and promotional messages if you opt in).
  • Monitor usage and analyze trends to improve performance and features.
  • Detect, prevent, and address technical or security issues.

3. Sharing Your Information

We do not sell your personal information, and we do not track you across other companies’ apps or websites for advertising purposes. We may share your information only in the following circumstances:

  • Service Providers: With third-party vendors and partners who help us operate the App (e.g., hosting, analytics, customer support).
  • Legal Compliance: If required by law, regulation, or legal process.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred.

Third-Party Service Providers

We use the following third-party services to operate and improve DayDash:

Sentry (Crash Reporting & Performance Monitoring)

  • Provider: Functional Software, Inc. (Sentry)
  • Purpose: Captures crash reports, error logs, and performance data to help us identify and fix technical issues.
  • Data Collected: Error logs, stack traces, device metadata (OS version, app version, device model), session context, and anonymized session replays for debugging purposes.
  • Identifiers: Error reports are tagged with your DayDash account identifier so we can trace a crash back to the affected account. This is a stable account ID — not an anonymous or randomly generated value, and not a device advertising identifier.
  • Data NOT Collected: We do not send your name or email address to Sentry, and we do not enable Sentry’s optional automatic collection of personal information. Health data is not intentionally sent to Sentry.
  • Privacy Policy: https://sentry.io/privacy/

PostHog (Product Analytics)

  • Provider: PostHog, Inc. (hosted on PostHog’s US cloud)
  • Purpose: Helps us understand how the daydash.io website and the App are used (page and screen views, product events, and which campaign or referring site brought you to DayDash) so we can improve them.
  • Data Collected: On daydash.io and on the App’s sign-in pages, before you sign in: page views recorded under a random first-party cookie identifier; no profile is built for signed-out visitors. Once you sign in: your DayDash account identifier, screen and page views, and account-level product properties (your selected interests, whether account setup is complete, and account timestamps). When you create an account we also record, once, the campaign parameters, referring site, and landing page of the visit that led to sign-up, and the earlier anonymous visit is linked to your account.
  • Data NOT Collected: We do not send your name or email address to PostHog. Automatic capture of clicked-element text is deliberately disabled so that labels you write yourself (such as dashboard or widget names) never reach analytics, and your dashboard data itself is never sent to PostHog.
  • Privacy Policy: https://posthog.com/privacy

MailerLite (Email Communications)

  • Provider: MailerLite
  • Purpose: Sends account and marketing email (such as onboarding and product updates) and manages your email preferences.
  • Data Collected: Email address, name, DayDash account identifier, account status (such as whether setup is complete and when you were last active), and your selected interests.
  • Data NOT Collected: Your dashboard data, health data, and AI conversations are never sent to MailerLite. You can opt out of marketing email at any time via the unsubscribe link in those messages, and deleting your account removes you from our marketing systems.
  • Privacy Policy: https://www.mailerlite.com/legal/privacy-policy

Clerk (Authentication)

  • Provider: Clerk, Inc.
  • Purpose: Provides secure user authentication, account management, and session handling.
  • Data Collected: Email address, authentication tokens, and account preferences.
  • Privacy Policy: https://clerk.com/privacy

RevenueCat (Mobile In-App Purchase Processing)

  • Provider: RevenueCat, Inc.
  • Purpose: Processes and manages subscriptions purchased as in-app purchases through the Apple App Store or Google Play, and keeps your subscription status in sync with your DayDash account.
  • Data Collected: Purchase and subscription status (product, renewal, and expiration information) and app user identifiers. Your payment details are handled by Apple or Google; neither RevenueCat nor DayDash receives your payment card information.
  • Privacy Policy: https://www.revenuecat.com/privacy

Amazon Web Services (Cloud Hosting & AI Processing)

  • Provider: Amazon Web Services, Inc. (AWS)
  • Purpose: Hosts our servers, databases, and file storage, and provides the managed AI service (Amazon Bedrock) behind the AI features described in Section 5.
  • Data Collected: DayDash data is stored on AWS infrastructure, encrypted as described in Section 4. When you use AI features, the content described in Section 5 is processed by Amazon Bedrock inside our AWS environment. Amazon Bedrock does not use your content to train models.
  • Privacy Policy: https://aws.amazon.com/privacy/

4. Data from Connected Third-Party Services

When you choose to connect third-party services to DayDash (such as financial institutions, health providers, or productivity tools), we access your data via their respective APIs solely to display your personal dashboard metrics.

  • Encryption & Key Management: We securely store your synchronized data (including financial plans, transaction history, and health metrics) to provide a responsive experience. All third-party data is encrypted at rest with encryption keys that belong to you. During account setup you choose how account recovery works, and that choice determines who can ever access your keys:
    • You hold your recovery code (the default, recommended option): DayDash keeps no copy of your recovery code or decryption keys. Your keys exist only on your devices and in your saved Emergency Kit, and DayDash personnel and systems cannot decrypt your stored data.
    • DayDash-managed recovery (optional): If you instead choose to let DayDash hold your recovery code (so that new devices can set themselves up automatically, with no Emergency Kit to manage), we store an encrypted copy of your recovery code on our servers. In this mode our systems can technically recover your decryption keys. Access is restricted to automated device-setup processes, but because recovery is tied to your account, anyone who gains control of your DayDash account (for example, through a password reset) could decrypt your synchronized data. You can switch back to holding your own recovery code at any time in account settings.
  • Security & Limited Access: We do not have access to your external login credentials or passwords. Once stored, your synchronized data is technically unreadable to our staff and systems unless you have opted into DayDash-managed recovery; data passes through our servers transiently during synchronization (and, if you choose to use them, during the AI features described in Section 5), but it is never stored unencrypted.
  • Data Usage: Data synced from third-party integrations is used exclusively for display within your personal DayDash dashboard and, when you choose to use them, for the AI features described in Section 5. We do not sell, share, or aggregate this data for any third-party advertising or market research.

Health Data from Apple Health (HealthKit) and Android Health Connect

When you choose to connect Apple Health or Android Health Connect, DayDash requests read-only access to health data categories that you explicitly select. DayDash does not write or modify any data in Apple Health or Health Connect. The specific categories of health data we may access include:

  • Activity & Fitness: Steps, active and basal calories burned, distance (walking, running, cycling, swimming), flights climbed, workouts, exercise time, move time, stand time, VO2 max, running speed, cycling cadence
  • Body Measurements: Weight, height, BMI, body fat percentage, lean body mass, waist circumference
  • Vitals: Heart rate, resting heart rate, heart rate variability (HRV), blood pressure (systolic and diastolic), blood glucose, oxygen saturation, body temperature, skin temperature, respiratory rate
  • Nutrition: Dietary calories, protein, carbohydrates, fat, fiber, water/hydration, sugar, sodium, caffeine
  • Sleep: Sleep analysis, sleep stages, time in bed
  • Reproductive Health: Menstrual flow, basal body temperature, ovulation tests, cervical mucus, intermenstrual bleeding
  • Hearing: Environmental and headphone audio exposure levels
  • Mobility: Walking and running metrics, wheelchair pushes

How Health Data Is Used:

  • Health data is accessed solely to display on your personal DayDash dashboard and to provide health and wellness visualizations. If you choose to ask the AI assistant about your health data, that data is also processed to generate the response, as described in Section 5.
  • Health data is never sold, traded, or shared with any third party, including advertisers, data brokers, or analytics providers. When you choose to use the AI assistant on your health data, it is processed by Amazon Bedrock acting as our service provider, as described in Section 5. It is never shared with advertisers or data brokers and is never used to train AI models.
  • Health data is never used for advertising, marketing, or to build user profiles for non-health purposes.
  • Health data is encrypted at rest with your own encryption keys, with key custody as described in “Encryption & Key Management” above. Under the default recovery option (you hold your recovery code), DayDash cannot decrypt your stored health data.
  • DayDash requests only the specific health categories you select — we do not request access to categories you have not chosen to sync.

Background Sync: With your permission, DayDash may sync health data in the background to keep your dashboard up to date. Background sync accesses only the health categories you have previously authorized.

Revoking Access: You may revoke DayDash’s access to your health data at any time:

  • iOS: Go to Settings > Privacy & Security > Health > DayDash
  • Android: Go to Settings > Health Connect > App permissions > DayDash
  • You may also disconnect the health data source within the DayDash App.

Specific Disclosure: You Need A Budget (YNAB)

To comply with YNAB’s API Terms of Service, we explicitly disclose the following regarding data accessed via the YNAB integration:

  • Data Accessed: We access your Budget/Plan names, account balances, category balances, and transaction history (payees, amounts, dates, and memos).
  • Storage & Retention: YNAB data is encrypted at rest with your encryption keys, with key custody as described in “Encryption & Key Management” above (under the default recovery option, DayDash cannot decrypt it). We retain this data only until you explicitly delete the YNAB data source or your DayDash account.
  • No Third-Party Sharing: We do not sell, share, or transfer your YNAB data to any third parties, including advertisers or data brokers.
  • Deletion: You may delete your YNAB data from our systems at any time by removing your YNAB data source within the DayDash App or deleting your DayDash account.

5. AI Assistant and AI Features

DayDash includes optional AI features: an AI assistant you can chat with about your data, and small AI-powered configuration helpers (for example, suggesting column types when you import a spreadsheet). These features are powered by large language models running on Amazon Bedrock, an AWS service, inside our own AWS environment.

The AI assistant is the one part of DayDash where our usual “your stored data is unreadable to us” model does not fully apply, and we want to be clear about it. Here is exactly what happens when you use the assistant:

  1. Your messages go to the model. When you ask the assistant a question, your message and the conversation history are sent from your device through our servers to Amazon Bedrock to generate a response.
  2. Data lookups run on your device. If the assistant needs your data to answer, it reads that data locally on your device, where it is decrypted with your key. The AI data flow never transmits your encryption key: neither our servers nor Amazon Bedrock receive it. (How your key itself is managed, including the optional DayDash-managed recovery mode, is described in Section 4.)
  3. The relevant results are sent to the model. The results of those lookups (the data relevant to your question, not a bulk copy of your data) are sent through our servers to Amazon Bedrock so the model can generate the answer. During this step your decrypted data is processed in the cloud. Our servers relay it in memory without storing it, and the processing happens under our Business Associate Agreement with AWS.
  4. Conversations are stored encrypted. Finished messages are encrypted so that they are readable only on your devices. Our servers store only the encrypted form and cannot read your conversation history.

What this means in practice:

  • If you ask the assistant about your data, including health or financial data, that data is decrypted and processed in the cloud to generate the response. If you do not want specific data processed this way, do not ask the assistant about it. Outside of the AI features described in this section, DayDash never sends your decrypted stored data to an AI model.
  • AI processing happens inside our AWS environment via Amazon Bedrock, not on a third-party consumer AI service. Amazon Bedrock does not use your data or conversations to train models, and the companies that make the underlying models do not receive access to them. Amazon may retain AI inputs and outputs for a limited period to detect abuse, in accordance with AWS policies.
  • We never use your conversations or other AI inputs for advertising, and we never sell them.
  • To enforce monthly usage allowances, we record usage measurements for AI assistant requests (such as token counts, request size, computed cost, and which conversation they belong to). These records do not contain the content of your messages or your data.
  • The first time you use the assistant, the App shows a disclosure explaining this data flow. You can review it again at any time from the assistant screen.

AI configuration helpers: Some setup features send small samples of data to Amazon Bedrock to make configuration easier. For example, importing a spreadsheet may send the sheet name, column headers, and a sample of rows to suggest column types, and creating a data source may send its name and field labels to suggest a color scheme or default settings. The same protections apply: no model training, no advertising, no sale of your data.

Deleting AI conversations: You can delete any conversation in the App at any time. Deleting your account deletes all of your conversations. See Section 8 for retention details.

For a plain-language walkthrough of DayDash encryption and the AI data flow, see How DayDash Protects Your Data.


6. Data Security

We use reasonable administrative, technical, and physical safeguards to protect your information. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.


7. Your Privacy Rights (GDPR & CCPA)

Depending on your location, you may have specific rights regarding your personal information under laws such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

Your rights include:

  • Right to Access: You have the right to request copies of your personal data.
  • Right to Rectification: You have the right to request that we correct inaccurate information or complete incomplete information.
  • Right to Erasure (Right to be Forgotten): You have the right to request that we erase your personal data under certain conditions.
  • Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data.
  • Right to Object to Processing: You have the right to object to our processing of your personal data.
  • Right to Data Portability: You have the right to request that we transfer your data to another organization or directly to you.

California Residents (CCPA/CPRA):

  • Health data collected through Apple Health and Health Connect is classified as sensitive personal information under the California Consumer Privacy Act.
  • Do Not Sell or Share: We do not sell or share your personal information, including health data, with third parties for cross-context behavioral advertising or any other purpose.
  • Right to Limit Use of Sensitive Personal Information: You have the right to limit our use of sensitive personal information to only what is necessary to provide the DayDash service.
  • To exercise any CCPA rights, contact us at support@daydash.io or use the account management features within the App.

Managing Your Choices:

  • Access & Update: You can update or delete your account information directly within the App settings or through the account management portal.
  • Opt-Out: You may opt out of receiving promotional communications by following the unsubscribe instructions in those messages.
  • Health Data Permissions: You can manage or revoke health data permissions through your device settings (iOS: Settings > Privacy & Security > Health; Android: Settings > Health Connect > App permissions).
  • Other Permissions: You can manage or revoke other app permissions (such as notifications) through your device settings.

To exercise any of these rights, please contact us at support@daydash.io. We will respond to your request within the timeframes required by applicable law.


8. Data Retention Policy

We retain your personal information and synchronized third-party data only for as long as is necessary for the purposes set out in this Privacy Policy.

  • Account Data: We retain your account information (such as email and preferences) for as long as your account is active.
  • Synchronized Data: Data synced from third-party integrations (such as YNAB, Apple Health, or Health Connect) is retained until you explicitly delete the specific data source or delete your account. Disabling an integration stops new data synchronization but preserves your existing historical data for analysis until you choose to delete it.
  • AI Assistant Conversations: Conversations are retained, encrypted, until you delete the individual conversation or your account. AI usage records (such as token counts and computed cost, with no message or data content) are retained to enforce usage allowances and prevent abuse, and may be retained as aggregate, contentless records after account deletion.
  • Legal Obligations: We may retain certain information for longer periods if required to do so for legal compliance or dispute resolution.

Account Deletion: When you delete your DayDash account, we permanently delete all associated data, including:

  • All health data synced from Apple Health and Health Connect
  • All financial data synced from connected services
  • All AI assistant conversations
  • All dashboards, data sources, and configuration
  • All access credentials and device registrations
  • All stored files and encryption keys
  • Your information from our marketing systems

Account deletion begins immediately upon request, and your data is then permanently removed from our active systems. If you have a subscription purchased through the Apple App Store or Google Play that is still set to auto-renew, you must cancel its auto-renewal (through your Apple or Google account) before account deletion can proceed — this prevents you from continuing to be billed for a deleted account. Deleted data may persist in routine encrypted backups of our systems for a limited period before those backups expire; we do not use backups to restore deleted user data except as required for disaster recovery or legal compliance. To delete your account, use the account management portal accessible from within the App, or contact us at support@daydash.io.


9. International Data Transfers

DayDash is operated in the United States. If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, please note that your information will be transferred to and processed in the United States.

To ensure your data is protected during these transfers, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (or equivalent mechanisms for the UK/Swiss jurisdictions). These legal safeguards ensure that your data receives an equivalent level of protection to that provided by local data protection laws.


10. Children’s Privacy

The App is not directed to children under 13 (or under 16 in certain jurisdictions). We do not knowingly collect personal information from children. If we learn we have done so, we will delete such information promptly.


11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of changes by updating the “Last Updated” date and, if material, by providing additional notice (such as through the App or email).


12. Contact Us

If you have questions about this Privacy Policy, please contact us at:

Axil LLC

11801 Domain Blvd 3rd Fl Austin, TX 78758

support@daydash.io