Privacy Policy
This policy explains what DailyFlux collects, why, who processes it, and how you control it. It covers the DailyFlux web app, the Android app (com.dailyflux.app), and the desktop app.
Summary
What we collect
2.1 Account data
Collected when you register and while you use your account:
| Data | Why |
|---|---|
| Email address | Account identity, sign-in, email verification, password reset, service notices |
| Name (display name) | Shown in the app interface |
| Password | Stored only as a bcrypt hash — we never store or can read your password |
| Email verification status, account status, last-active timestamp | Account security, abuse prevention, support |
| Preferences (theme, calendar, notification and planning settings) | Delivering the app as you configured it |
2.2 Content you create
Everything you enter into the app: tasks (titles, descriptions, dates, times, priorities, estimates, recurrence rules, reminders, locations), projects, sections, labels, and time-tracking entries.
We treat this as private content. It is accessible to your account, and to nobody else — except where you deliberately grant access (see section 6) or where the law compels disclosure.
2.3 Technical data needed to run the service
| Data | Why |
|---|---|
| Device identifier generated by the app, platform (web/android) | Multi-device sync, delivering notifications to the right device, de-duplicating reminders |
| Push subscription data (web push endpoint and keys, or Firebase Cloud Messaging token) | Delivering task reminders you enabled |
| Synchronisation commands and change metadata | Applying offline edits, resolving conflicts between devices |
| Activity log of changes to your own data (action, entity type and name, device, timestamp) | Letting you and our support trace what changed and from which device |
| IP address | Processed transiently for rate limiting and abuse prevention; it may also appear in short-lived server logs. It is not part of your account record |
If an administrator performs an account action (for example suspending an account for abuse), that action is logged with the administrator identity, the affected account, and the change made.
2.4 What we do not collect
No analytics or telemetry SDKs, no advertising identifiers, no cross-site or cross-app tracking, no location tracking, no access to your contacts, camera, microphone, or files on your device.
Legal bases (GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the app, account, and sync | Performance of a contract (Art. 6(1)(b)) |
| Transactional email (verification, password reset, essential service notices) | Performance of a contract (Art. 6(1)(b)) |
| Push reminders you enabled | Performance of a contract, and your consent at the operating-system permission prompt |
| Security, rate limiting, abuse prevention, activity logging | Legitimate interests (Art. 6(1)(f)) — keeping the service available and accounts safe |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
Data stored on your device
DailyFlux is offline-first, so a copy of your data lives locally:
- Web — a local SQLite database in the browser's Origin Private File System (or IndexedDB as a fallback), plus app state in localStorage.
- Android — a local SQLite database, protected by Android's app sandbox and by your device lock screen. Session tokens are held in the platform's secure storage.
- Desktop — a local SQLite database in the application data directory.
The local database is not encrypted at rest. On Android it is protected by the app sandbox and your lock screen, not by encryption of the file itself.
Uninstalling the app, or clearing site data in a browser, removes this local copy. It does not delete your account or the server-side copy — to delete those, use one of the two routes in section 9.
Who processes data for us
We use a small number of processors. They act on our instructions and only for the purposes below.
| Processor | Purpose | Data involved |
|---|---|---|
| Resend | Sending transactional email | Email address, message content (verification and password-reset links) |
| Google Firebase Cloud Messaging | Delivering push notifications to Android devices | Device push token, notification payload |
| Browser push services (Google, Mozilla, Apple, depending on your browser) | Delivering web push notifications | Push endpoint, notification payload |
| Neon | Managed PostgreSQL database hosting | All server-side account and content data |
| Hetzner | Server hosting (Germany) | Application traffic and server-side processing |
Notification payloads may contain the task title you are being reminded about. If you do not want task titles to leave the device through these services, turn off push notifications.
We do not sell your data, and we do not share it with advertisers or data brokers.
Third-party apps you authorise
DailyFlux can issue access to third-party applications (including AI assistants connecting over the Model Context Protocol) through OAuth 2.0. This happens only when you explicitly approve a consent screen, and the access is limited to the scopes shown on that screen.
You can review and revoke connected applications at any time in the app's settings. Revoking access stops future access; it does not retrieve data the application already received.
What a connected application does with your data is governed by its own privacy policy, not by this one.
International transfers
Our servers are located in Germany (EU). Some processors listed in section 5 may process data outside the European Economic Area. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or another valid transfer mechanism. [Transfer mechanism, to confirm per processor]
How long we keep data
- Account data and your content — for as long as your account exists.
- Synchronisation bookkeeping — the record of which changes a device has already applied is kept for as long as your account exists and is deleted with it.
- Reminder bookkeeping — the record of which reminders have already been sent (so the same reminder does not fire twice) is deleted after 7 days.
- Your activity log — kept for as long as your account exists and deleted with it.
- Administrative log — records of privileged actions by staff (for example suspending an account) are kept indefinitely as a security record. When an account is deleted, its entries are anonymised: the account identifier is removed, and the name and email address are stripped from the record.
- Server logs and metrics — application logs and operational metrics are kept for 15 days and then deleted automatically.
- Backups — database backups are kept for 14 days and then deleted, so deleted data may persist in a backup for up to 14 days after it is removed from the live database.
When you delete your account, we delete your account data and content from the live database, subject to the backup window above and to any records we must keep by law. Backups are never used to restore an individual deleted account — only to recover the service as a whole from a failure.
Deleting your account and data
You can delete your account yourself, in either of two ways:
- In the app — Settings → General → Danger zone → Delete account. You confirm with your current password and by typing the word DELETE.
- On the web, without signing in and without the app installed — https://dailyflux.io/delete-account/ — enter the address the account is registered to and we email you a confirmation link, valid for one hour and usable once.
Either route starts a 30-day cancellation window. Requesting deletion immediately signs out every device and disconnects every authorised third-party application, but your data stays intact until the window closes.
To cancel, sign in with your password before the deadline and choose Restore account — signing in alone does not cancel anything. When the window closes, the data is erased automatically; erasure runs on a schedule, so it happens within a day of the deadline rather than at the exact minute. After that it cannot be recovered.
Deleting your account removes: your profile, preferences, tasks, projects, sections, labels, time entries, push subscriptions, authorised third-party application grants and tokens, and activity logs tied to your account. What is kept, and for how long, is set out in section 8: backups for up to 14 days, and anonymised administrative records.
You can still write to privacy@dailyflux.io if you would rather we handled the deletion for you.
Your rights
If you are in the EEA or the UK, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, and to receive a portable copy. You can exercise any of these by writing to privacy@dailyflux.io.
You also have the right to lodge a complaint with your local data protection authority. [Supervisory authority]
Security
- All traffic between apps and our servers uses HTTPS/TLS, and the connection from our server to the database is TLS-encrypted.
- Passwords are stored as bcrypt hashes.
- Sign-in uses short-lived access tokens (15 minutes) with refresh tokens; you can sign out of all sessions, which revokes them.
- Access to production systems is limited to the people who operate the service.
- The local database on your device is not encrypted at rest (see section 4).
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant supervisory authority as required by law.
Children
DailyFlux is not directed at children under 16, and we do not knowingly collect data from them. If you believe a child has created an account, contact privacy@dailyflux.io and we will delete it.
Changes to this policy
If we change this policy in a way that materially affects you, we will notify you in the app or by email before the change takes effect. The "last updated" date at the top always reflects the current version.
Contact
Questions about this policy, a data export, or a deletion request go to the address below.