DailyFlux
LEGAL

Privacy Policy

This policy explains what DailyFlux collects, why, who processes it, and how you control it. It covers the DailyFlux web app, the Android app (com.dailyflux.app), and the desktop app.

Effective 8 August 2026 DRAFT Last updated 8 August 2026 · Values in square brackets are not settled yet.

Summary

IN SHORT Your tasks live on your device DailyFlux is offline-first. Your tasks are kept in a local database and synchronised to our server so that several devices can share one account.
IN SHORT No analytics, no advertising No tracking SDKs and no advertising identifiers. We do not sell or rent your data, and we do not use your task content for advertising or to train machine-learning models.
IN SHORT No permissions we do not need We never ask for your location, contacts, camera, microphone, photos or the files on your device.
02

What we collect

2.1 Account data

Collected when you register and while you use your account:

DataWhy
Email addressAccount identity, sign-in, email verification, password reset, service notices
Name (display name)Shown in the app interface
PasswordStored only as a bcrypt hash — we never store or can read your password
Email verification status, account status, last-active timestampAccount security, abuse prevention, support
Preferences (theme, calendar, notification and planning settings)Delivering the app as you configured it

2.2 Content you create

Everything you enter into the app: tasks (titles, descriptions, dates, times, priorities, estimates, recurrence rules, reminders, locations), projects, sections, labels, and time-tracking entries.

We treat this as private content. It is accessible to your account, and to nobody else — except where you deliberately grant access (see section 6) or where the law compels disclosure.

2.3 Technical data needed to run the service

DataWhy
Device identifier generated by the app, platform (web/android)Multi-device sync, delivering notifications to the right device, de-duplicating reminders
Push subscription data (web push endpoint and keys, or Firebase Cloud Messaging token)Delivering task reminders you enabled
Synchronisation commands and change metadataApplying offline edits, resolving conflicts between devices
Activity log of changes to your own data (action, entity type and name, device, timestamp)Letting you and our support trace what changed and from which device
IP addressProcessed transiently for rate limiting and abuse prevention; it may also appear in short-lived server logs. It is not part of your account record

If an administrator performs an account action (for example suspending an account for abuse), that action is logged with the administrator identity, the affected account, and the change made.

2.4 What we do not collect

No analytics or telemetry SDKs, no advertising identifiers, no cross-site or cross-app tracking, no location tracking, no access to your contacts, camera, microphone, or files on your device.

04

Data stored on your device

DailyFlux is offline-first, so a copy of your data lives locally:

  • Web — a local SQLite database in the browser's Origin Private File System (or IndexedDB as a fallback), plus app state in localStorage.
  • Android — a local SQLite database, protected by Android's app sandbox and by your device lock screen. Session tokens are held in the platform's secure storage.
  • Desktop — a local SQLite database in the application data directory.

The local database is not encrypted at rest. On Android it is protected by the app sandbox and your lock screen, not by encryption of the file itself.

Uninstalling the app, or clearing site data in a browser, removes this local copy. It does not delete your account or the server-side copy — see section 9.

05

Who processes data for us

We use a small number of processors. They act on our instructions and only for the purposes below.

ProcessorPurposeData involved
ResendSending transactional emailEmail address, message content (verification and password-reset links)
Google Firebase Cloud MessagingDelivering push notifications to Android devicesDevice push token, notification payload
Browser push services (Google, Mozilla, Apple, depending on your browser)Delivering web push notificationsPush endpoint, notification payload
NeonManaged PostgreSQL database hostingAll server-side account and content data
HetznerServer hosting (Germany)Application traffic and server-side processing

Notification payloads may contain the task title you are being reminded about. If you do not want task titles to leave the device through these services, turn off push notifications.

We do not sell your data, and we do not share it with advertisers or data brokers.

06

Third-party apps you authorise

DailyFlux can issue access to third-party applications (including AI assistants connecting over the Model Context Protocol) through OAuth 2.0. This happens only when you explicitly approve a consent screen, and the access is limited to the scopes shown on that screen.

You can review and revoke connected applications at any time in the app's settings. Revoking access stops future access; it does not retrieve data the application already received.

What a connected application does with your data is governed by its own privacy policy, not by this one.

07

International transfers

Our servers are located in Germany (EU). Some processors listed in section 5 may process data outside the European Economic Area. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or another valid transfer mechanism. [Transfer mechanism, to confirm per processor]

08

How long we keep data

  • Account data and your content — for as long as your account exists.
  • Synchronisation and reminder bookkeeping records — for a limited period needed to keep sync and reminders correct. [Retention period]
  • Activity and administrative logs — [Retention period]
  • Backups — deleted data may persist in backups for up to [Backup retention period] before being overwritten.

When you delete your account, we delete your account data and content from the live database, subject to the backup window above and to any records we must keep by law.

09

Deleting your account and data

You can request deletion of your account and all associated data at any time by emailing privacy@dailyflux.io from the address registered to the account. We will confirm the request and complete the deletion within 30 days.

A self-service deletion option inside the app is in development; until it ships, the email route above is the way to request deletion.

Deleting your account removes: your profile, preferences, tasks, projects, sections, labels, time entries, push subscriptions, authorised third-party application grants, and activity logs tied to your account.

10

Your rights

If you are in the EEA or the UK, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, and to receive a portable copy. You can exercise any of these by writing to privacy@dailyflux.io.

You also have the right to lodge a complaint with your local data protection authority. [Supervisory authority]

11

Security

  • All traffic between apps and our servers uses HTTPS/TLS, and the connection from our server to the database is TLS-encrypted.
  • Passwords are stored as bcrypt hashes.
  • Sign-in uses short-lived access tokens (15 minutes) with refresh tokens; you can sign out of all sessions, which revokes them.
  • Access to production systems is limited to the people who operate the service.
  • The local database on your device is not encrypted at rest (see section 4).

No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant supervisory authority as required by law.

12

Children

DailyFlux is not directed at children under 16, and we do not knowingly collect data from them. If you believe a child has created an account, contact privacy@dailyflux.io and we will delete it.

13

Changes to this policy

If we change this policy in a way that materially affects you, we will notify you in the app or by email before the change takes effect. The "last updated" date at the top always reflects the current version.

14

Contact

Questions about this policy, a data export, or a deletion request go to the address below.

DATA CONTROLLER [Legal entity name] [Registered address]
PRIVACY REQUESTS privacy@dailyflux.io
GENERAL SUPPORT support@dailyflux.io