Privacy Policy
This policy explains what DailyFlux collects, why, who processes it, and how you control it. It covers the DailyFlux web app, the Android app (com.dailyflux.app), and the desktop app.
Summary
What we collect
2.1 Account data
Collected when you register and while you use your account:
| Data | Why |
|---|---|
| Email address | Account identity, sign-in, email verification, password reset, service notices |
| Name (display name) | Shown in the app interface |
| Password | Stored only as a bcrypt hash — we never store or can read your password |
| Email verification status, account status, last-active timestamp | Account security, abuse prevention, support |
| Preferences (theme, calendar, notification and planning settings) | Delivering the app as you configured it |
2.2 Content you create
Everything you enter into the app: tasks (titles, descriptions, dates, times, priorities, estimates, recurrence rules, reminders, locations), projects, sections, labels, and time-tracking entries.
We treat this as private content. It is accessible to your account, and to nobody else — except where you deliberately grant access (see section 6) or where the law compels disclosure.
2.3 Technical data needed to run the service
| Data | Why |
|---|---|
| Device identifier generated by the app, platform (web/android) | Multi-device sync, delivering notifications to the right device, de-duplicating reminders |
| Push subscription data (web push endpoint and keys, or Firebase Cloud Messaging token) | Delivering task reminders you enabled |
| Synchronisation commands and change metadata | Applying offline edits, resolving conflicts between devices |
| Activity log of changes to your own data (action, entity type and name, device, timestamp) | Letting you and our support trace what changed and from which device |
| IP address | Processed transiently for rate limiting and abuse prevention; it may also appear in short-lived server logs. It is not part of your account record |
If an administrator performs an account action (for example suspending an account for abuse), that action is logged with the administrator identity, the affected account, and the change made.
2.4 What we do not collect
No analytics or telemetry SDKs, no advertising identifiers, no cross-site or cross-app tracking, no location tracking, no access to your contacts, camera, microphone, or files on your device.
Legal bases (GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the app, account, and sync | Performance of a contract (Art. 6(1)(b)) |
| Transactional email (verification, password reset, essential service notices) | Performance of a contract (Art. 6(1)(b)) |
| Push reminders you enabled | Performance of a contract, and your consent at the operating-system permission prompt |
| Security, rate limiting, abuse prevention, activity logging | Legitimate interests (Art. 6(1)(f)) — keeping the service available and accounts safe |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
Data stored on your device
DailyFlux is offline-first, so a copy of your data lives locally:
- Web — a local SQLite database in the browser's Origin Private File System (or IndexedDB as a fallback), plus app state in localStorage.
- Android — a local SQLite database, protected by Android's app sandbox and by your device lock screen. Session tokens are held in the platform's secure storage.
- Desktop — a local SQLite database in the application data directory.
The local database is not encrypted at rest. On Android it is protected by the app sandbox and your lock screen, not by encryption of the file itself.
Uninstalling the app, or clearing site data in a browser, removes this local copy. It does not delete your account or the server-side copy — see section 9.
Who processes data for us
We use a small number of processors. They act on our instructions and only for the purposes below.
| Processor | Purpose | Data involved |
|---|---|---|
| Resend | Sending transactional email | Email address, message content (verification and password-reset links) |
| Google Firebase Cloud Messaging | Delivering push notifications to Android devices | Device push token, notification payload |
| Browser push services (Google, Mozilla, Apple, depending on your browser) | Delivering web push notifications | Push endpoint, notification payload |
| Neon | Managed PostgreSQL database hosting | All server-side account and content data |
| Hetzner | Server hosting (Germany) | Application traffic and server-side processing |
Notification payloads may contain the task title you are being reminded about. If you do not want task titles to leave the device through these services, turn off push notifications.
We do not sell your data, and we do not share it with advertisers or data brokers.
Third-party apps you authorise
DailyFlux can issue access to third-party applications (including AI assistants connecting over the Model Context Protocol) through OAuth 2.0. This happens only when you explicitly approve a consent screen, and the access is limited to the scopes shown on that screen.
You can review and revoke connected applications at any time in the app's settings. Revoking access stops future access; it does not retrieve data the application already received.
What a connected application does with your data is governed by its own privacy policy, not by this one.
International transfers
Our servers are located in Germany (EU). Some processors listed in section 5 may process data outside the European Economic Area. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or another valid transfer mechanism. [Transfer mechanism, to confirm per processor]
How long we keep data
- Account data and your content — for as long as your account exists.
- Synchronisation and reminder bookkeeping records — for a limited period needed to keep sync and reminders correct. [Retention period]
- Activity and administrative logs — [Retention period]
- Backups — deleted data may persist in backups for up to [Backup retention period] before being overwritten.
When you delete your account, we delete your account data and content from the live database, subject to the backup window above and to any records we must keep by law.
Deleting your account and data
You can request deletion of your account and all associated data at any time by emailing privacy@dailyflux.io from the address registered to the account. We will confirm the request and complete the deletion within 30 days.
A self-service deletion option inside the app is in development; until it ships, the email route above is the way to request deletion.
Deleting your account removes: your profile, preferences, tasks, projects, sections, labels, time entries, push subscriptions, authorised third-party application grants, and activity logs tied to your account.
Your rights
If you are in the EEA or the UK, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, and to receive a portable copy. You can exercise any of these by writing to privacy@dailyflux.io.
You also have the right to lodge a complaint with your local data protection authority. [Supervisory authority]
Security
- All traffic between apps and our servers uses HTTPS/TLS, and the connection from our server to the database is TLS-encrypted.
- Passwords are stored as bcrypt hashes.
- Sign-in uses short-lived access tokens (15 minutes) with refresh tokens; you can sign out of all sessions, which revokes them.
- Access to production systems is limited to the people who operate the service.
- The local database on your device is not encrypted at rest (see section 4).
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant supervisory authority as required by law.
Children
DailyFlux is not directed at children under 16, and we do not knowingly collect data from them. If you believe a child has created an account, contact privacy@dailyflux.io and we will delete it.
Changes to this policy
If we change this policy in a way that materially affects you, we will notify you in the app or by email before the change takes effect. The "last updated" date at the top always reflects the current version.
Contact
Questions about this policy, a data export, or a deletion request go to the address below.