Privacy policy
Last updated: 31 August 2026
This policy explains what personal data Dayveo processes, why it is needed, who it may be shared with, and how to exercise your rights. We do not sell personal data. The content of your account — tasks, notes, habits, clients, projects and financial records — is never shared with advertising platforms. Advertising and analytics tools run only on our marketing pages, and only after you consent.
Who is responsible for your data
The controller of personal data is Oleksandr Abramenko, sole proprietor (FOP), Shkilna street 7, Novodmytrivka Druha, Ivanivskyi district, Kherson region, Ukraine. For privacy questions and to exercise your rights: support@dayveo.com.
No separate data protection officer (DPO) has been appointed: the scope and nature of our processing do not meet the thresholds of Article 37 GDPR. All requests are handled by the owner of the service at the address above.
What data we process
- Account and profile: email, name, avatar, user identifier, profile settings and — if you voluntarily connect Telegram notifications — your Telegram chat ID. Passwords are not stored in readable form. When you sign in with Google or Apple, we receive the profile data you allowed that provider to share.
- Your content: tasks, habits, notes, clients, projects, team messages, comments, files, links, reminders, tags and anything else you add to Dayveo.
- Photos, files and audio: avatars, attachments and audio you deliberately send for voice or AI features. Audio for transcription is passed to the speech recognition provider while the request runs; Dayveo does not build a separate permanent audio archive from it.
- Financial content: income, expenses, client payments and other records you keep inside Dayveo yourself. These records are not bank account data and do not initiate any banking operation on their own.
- Subscription and web payments: plan, amount, currency, status, date, invoice identifier and subscription history. To renew a web subscription automatically, Dayveo may receive a secure card token and a masked card number from Plata by mono. We do not receive the full card number or CVV.
- Technical and service data: IP address, date and time of the request, device or browser type, error logs, and events related to sign-in, security, subscription, support and the use of specific features, including AI. This is needed to run the service, protect accounts, diagnose problems and enforce plan limits.
- Connections to external AI apps: the connection name, the name of the app that connected, a fingerprint of the access key, the date it was last used and the permissions you chose. The key itself is not stored in the database — only its irreversible fingerprint — so not even we can recover it. A separate activity log records which app used which tool, how many records were created or changed, the result and a short description of the action.
- Advertising data and visits to marketing pages: if you consented in the banner — IP address, browser and device type, the pages of our website you viewed, and advertising cookie identifiers. In the mobile app — the device advertising identifier (IDFA) and the install event, and only if you allowed tracking in the iOS system prompt.
- Support requests: contact details, the content of your message and any attachments you send voluntarily.
What we use the data for
- to provide Dayveo features and sync data across devices;
- to create your account, sign you in and protect access;
- to run AI features, only after an action by you;
- to handle subscriptions, payments, renewals and cancellations;
- to send service emails and reminders;
- to answer requests and fix problems;
- to carry out the actions you instruct an external AI app to perform through a connection you enabled;
- to measure the performance of our advertising and to show Dayveo ads — only where consent has been given;
- to send product news, if you subscribed to it separately;
- to prevent abuse and to comply with the law.
Who your data may be shared with
We share only the data a specific feature requires. The current categories of providers are:
- Google — sign-in with Google, if you choose that method.
- Apple — sign-in with Apple; Apple also handles purchases and subscriptions made through In-App Purchase on iOS.
- Anthropic, OpenAI and Groq — processing of text or audio for AI features. Which provider is used depends on the feature and the server-side model selected. Only the content needed for your request is sent, together with the technical parameters of that request.
- Companies whose AI apps you connected yourself — for example Anthropic (Claude Code, Claude.ai, Claude Desktop) or OpenAI (ChatGPT). Data is shared only while you keep a connection enabled, within the permissions you granted, and at your request. See “Connections to external AI apps” below.
- Plata by mono (monobank) — creating and processing payments made in the web version of Dayveo, and automatic renewals if you enabled them.
- Resend — delivery of service emails, including password recovery and subscription reminders.
- Telegram — optional notifications to you about Dayveo events, and service notifications to the owner of the service. A service notification may contain an email address, a payment status or a short excerpt of a support request needed to answer quickly.
- Meta Platforms Ireland Ltd. — measurement of our advertising on Facebook and Instagram. We share events from marketing pages and the app install event, technical request data and advertising identifiers. This happens only after consent in the website banner or permission to track on iOS. Account content is never shared.
- Infrastructure providers — hosting, domain, network and backup services required to run and protect Dayveo. The main application data is stored on infrastructure controlled by the owner of Dayveo.
We share data only with providers who are contractually obliged to protect personal data to a standard no lower than the one described in this policy, and to use the data solely for the function they provide. Providers may process data in the countries where their infrastructure is located, in line with their own policies and the applicable data protection mechanisms.
AI features: what exactly is sent
AI features are triggered by your own action — a message in the chat, a voice recording, a “turn this text into tasks” command. Without such an action, no account content is sent to AI providers.
- What is sent: only the fragment the request needs — the text of your message, the audio to transcribe, task titles and times within the requested period, the text of a note. Technical request parameters go with it.
- What is never sent: passwords, payment tokens, card details, payment history.
- Who processes it: Anthropic, OpenAI or Groq, depending on the feature and the server-side model.
- Model training: under the terms of their developer interfaces, these providers do not use the data we send to train their models.
- Retention: providers may keep requests temporarily for abuse monitoring — typically up to 30 days — and then delete them. The exact period is set by each provider’s own policy.
AI answers can contain mistakes, so important results are worth checking. Using AI is not required to work with Dayveo.
Connections to external AI apps
Dayveo lets you connect external AI apps — for example Claude Code, ChatGPT, Claude.ai or Claude Desktop — so you can work with your tasks from there. This is off by default and is enabled only by you, by creating an access key or confirming the connection on the consent page.
While a connection is active, the external app receives from Dayveo, at your request, the content you allowed it to see: tasks, projects, notes, comments, client data and financial summaries. That content is then processed by the company that owns the connected app (for example Anthropic or OpenAI) under its own privacy policy, not this one. Dayveo does not control how long or for what purpose it keeps the data.
What is never shared: card details, payment tokens, payment history and the state of your Dayveo subscription. This data is outside the scope of any connection and cannot be exposed through one.
About team data. If you give a connection access to projects, what other team members wrote in those projects — tasks, comments and messages — may leave with it. The scope is always limited by your role in the team, but it is not limited to your own records. Enable project access with that in mind.
Control. Access is configured per section — “no access”, “read” or “write”. Client data and finances are available for reading at most and cannot be changed through a connection. Deleting any records through a connection is not possible at all, and neither is access to the trash or the archive. A connection can be revoked at any time in “Settings → Connections”; the key stops working immediately.
Analytics and advertising
We advertise Dayveo on Facebook and Instagram. To understand which ads bring people in, we use tools provided by Meta Platforms Ireland Ltd.
-
On dayveo.com we run the Meta Pixel. It reports
events to Meta: page view, start of registration, subscription
checkout. Along with the event it sends the IP address, browser data
and advertising cookie identifiers (
_fbp,_fbc). The pixel does not load until you consent in the banner. - In the iPhone app we run the Meta SDK, which reports app installs and registrations. It uses the device advertising identifier (IDFA) only when you allowed tracking in the iOS system prompt. If you declined, the identifier is not used and we do not try to recognise the device by any other means.
- Events from our server. Registration, trial start, checkout and successful payment are reported to Meta by Dayveo’s server rather than by your browser. The payment amount and currency go with the event, and for matching — your email address and account identifier as an irreversible fingerprint (SHA-256): the address cannot be reconstructed from it, and we never send it in readable form. Account content takes no part in these events.
- Why: to measure advertising results, to avoid showing ads to people who already signed up, and to build audiences similar to our users.
- Legal basis: consent. It can be withdrawn at any time.
What is never shared with advertising platforms: tasks, notes, habits, clients, projects, team messages and financial records. Advertising tools have no access to account content.
Meta processes the data it receives as an independent controller under its own policy. You can manage your ad settings in Meta ad preferences. To withdraw consent on the website use “Cookie settings” at the bottom of any page; on iOS use “Settings → Privacy & Security → Tracking”. Details about the files are in our Cookie policy.
Retention, backups and deletion
Account content is kept while the account is active or while it is needed to provide the service. After an account is deleted, active data and associated files are deleted or anonymised, as far as is technically possible and legally permitted.
The activity log for connections is kept for up to 90 days and then deleted automatically; the app shows you the last 30 days. Anonymised daily summaries (counts of actions and errors, with no record text or titles) may be kept longer — they are needed to monitor load and improve the service. Deleting an account also deletes its access keys and its log.
Technical security logs — time of the action, IP address, type of operation and its result — are kept for up to 12 months. They are needed to investigate abuse, attempts to bypass limits, and disputes about access and payments; without them we could neither confirm a violation nor disprove a mistaken accusation.
Individual payment, security and service records may be kept longer where this is required for accounting, dispute resolution, fraud prevention or compliance with the law. Copies of data may remain temporarily in secure backups until they are overwritten on schedule. We do not promise one fixed period for every type of data: it depends on the purpose, the law and the backup cycle.
Your rights
- Access and export: use the export in the app or contact support.
- Correction: change your profile and content in the app, or ask us for help.
- Deletion: open “Settings → Profile → Delete account”, or write to support@dayveo.com.
- Withdrawing access: disable or restrict a connected AI app in “Settings → Connections”.
- Objection or restriction: contact us and explain your request; we will consider it under the applicable law.
Deleting your Dayveo account does not cancel a subscription bought through Apple. That subscription is managed in your Apple ID settings. A web subscription can be cancelled in Dayveo settings.
Legal bases for processing
- Performance of a contract: creating your account, syncing data, handling subscriptions and payments.
- Consent: AI features, connections to external AI apps, advertising and analytics tools, product news, Telegram notifications. Consent can be withdrawn at any time — this does not affect the lawfulness of processing before the withdrawal.
- Legitimate interest: protecting accounts, preventing abuse and fraud, diagnosing errors, keeping the service stable.
- Legal obligation: accounting and tax records, answering lawful requests from competent authorities.
Users in the EU, EEA and the United Kingdom
The GDPR and the Data Protection Act 2018 apply to the processing of such users’ data. In addition to the rights listed above, you have the right to receive your data in a machine-readable format, the right to object to processing based on legitimate interest, and the right not to be subject to decisions made solely by automated means that produce legal effects — Dayveo makes no such decisions.
We answer requests within 30 days. If our answer does not satisfy you, you have the right to lodge a complaint with the data protection supervisory authority in your country of residence, and in Ukraine with the Ukrainian Parliament Commissioner for Human Rights.
International data transfers
The main application data is stored on infrastructure in the European Union. Some providers (in particular the AI providers and Meta) may process data outside the EEA, including in the United States. In those cases the transfer relies on the European Commission’s Standard Contractual Clauses or on other safeguards provided for by law and applied by the relevant provider.
Security
We apply technical and organisational safeguards, including HTTPS, access control and restrictions on server keys. That said, no system can guarantee absolute security. Do not share your password with anyone and tell us about suspicious activity.
Children
Dayveo is intended for users aged 13 and over and is not directed at younger children. We do not knowingly collect data from users under 13. If you believe a child has given us personal data, please write to support.
Changes to this policy
We may update this policy as the service evolves or as legal requirements change. The current date is always shown at the top of the page.
Contact
Oleksandr Abramenko, sole proprietor (FOP)
Shkilna street 7, Novodmytrivka Druha,
Ivanivskyi district, Kherson region, Ukraine
Email:
support@dayveo.com
This is a translation of the Ukrainian original. If the two versions differ, the Ukrainian version prevails.