УКР ENG ← Home

Privacy policy

Last updated: 31 August 2026

This policy explains what personal data Dayveo processes, why it is needed, who it may be shared with, and how to exercise your rights. We do not sell personal data. The content of your account — tasks, notes, habits, clients, projects and financial records — is never shared with advertising platforms. Advertising and analytics tools run only on our marketing pages, and only after you consent.

Who is responsible for your data

The controller of personal data is Oleksandr Abramenko, sole proprietor (FOP), Shkilna street 7, Novodmytrivka Druha, Ivanivskyi district, Kherson region, Ukraine. For privacy questions and to exercise your rights: support@dayveo.com.

No separate data protection officer (DPO) has been appointed: the scope and nature of our processing do not meet the thresholds of Article 37 GDPR. All requests are handled by the owner of the service at the address above.

What data we process

What we use the data for

Who your data may be shared with

We share only the data a specific feature requires. The current categories of providers are:

We share data only with providers who are contractually obliged to protect personal data to a standard no lower than the one described in this policy, and to use the data solely for the function they provide. Providers may process data in the countries where their infrastructure is located, in line with their own policies and the applicable data protection mechanisms.

AI features: what exactly is sent

AI features are triggered by your own action — a message in the chat, a voice recording, a “turn this text into tasks” command. Without such an action, no account content is sent to AI providers.

AI answers can contain mistakes, so important results are worth checking. Using AI is not required to work with Dayveo.

Connections to external AI apps

Dayveo lets you connect external AI apps — for example Claude Code, ChatGPT, Claude.ai or Claude Desktop — so you can work with your tasks from there. This is off by default and is enabled only by you, by creating an access key or confirming the connection on the consent page.

While a connection is active, the external app receives from Dayveo, at your request, the content you allowed it to see: tasks, projects, notes, comments, client data and financial summaries. That content is then processed by the company that owns the connected app (for example Anthropic or OpenAI) under its own privacy policy, not this one. Dayveo does not control how long or for what purpose it keeps the data.

What is never shared: card details, payment tokens, payment history and the state of your Dayveo subscription. This data is outside the scope of any connection and cannot be exposed through one.

About team data. If you give a connection access to projects, what other team members wrote in those projects — tasks, comments and messages — may leave with it. The scope is always limited by your role in the team, but it is not limited to your own records. Enable project access with that in mind.

Control. Access is configured per section — “no access”, “read” or “write”. Client data and finances are available for reading at most and cannot be changed through a connection. Deleting any records through a connection is not possible at all, and neither is access to the trash or the archive. A connection can be revoked at any time in “Settings → Connections”; the key stops working immediately.

Analytics and advertising

We advertise Dayveo on Facebook and Instagram. To understand which ads bring people in, we use tools provided by Meta Platforms Ireland Ltd.

What is never shared with advertising platforms: tasks, notes, habits, clients, projects, team messages and financial records. Advertising tools have no access to account content.

Meta processes the data it receives as an independent controller under its own policy. You can manage your ad settings in Meta ad preferences. To withdraw consent on the website use “Cookie settings” at the bottom of any page; on iOS use “Settings → Privacy & Security → Tracking”. Details about the files are in our Cookie policy.

Retention, backups and deletion

Account content is kept while the account is active or while it is needed to provide the service. After an account is deleted, active data and associated files are deleted or anonymised, as far as is technically possible and legally permitted.

The activity log for connections is kept for up to 90 days and then deleted automatically; the app shows you the last 30 days. Anonymised daily summaries (counts of actions and errors, with no record text or titles) may be kept longer — they are needed to monitor load and improve the service. Deleting an account also deletes its access keys and its log.

Technical security logs — time of the action, IP address, type of operation and its result — are kept for up to 12 months. They are needed to investigate abuse, attempts to bypass limits, and disputes about access and payments; without them we could neither confirm a violation nor disprove a mistaken accusation.

Individual payment, security and service records may be kept longer where this is required for accounting, dispute resolution, fraud prevention or compliance with the law. Copies of data may remain temporarily in secure backups until they are overwritten on schedule. We do not promise one fixed period for every type of data: it depends on the purpose, the law and the backup cycle.

Your rights

Deleting your Dayveo account does not cancel a subscription bought through Apple. That subscription is managed in your Apple ID settings. A web subscription can be cancelled in Dayveo settings.

Legal bases for processing

Users in the EU, EEA and the United Kingdom

The GDPR and the Data Protection Act 2018 apply to the processing of such users’ data. In addition to the rights listed above, you have the right to receive your data in a machine-readable format, the right to object to processing based on legitimate interest, and the right not to be subject to decisions made solely by automated means that produce legal effects — Dayveo makes no such decisions.

We answer requests within 30 days. If our answer does not satisfy you, you have the right to lodge a complaint with the data protection supervisory authority in your country of residence, and in Ukraine with the Ukrainian Parliament Commissioner for Human Rights.

International data transfers

The main application data is stored on infrastructure in the European Union. Some providers (in particular the AI providers and Meta) may process data outside the EEA, including in the United States. In those cases the transfer relies on the European Commission’s Standard Contractual Clauses or on other safeguards provided for by law and applied by the relevant provider.

Security

We apply technical and organisational safeguards, including HTTPS, access control and restrictions on server keys. That said, no system can guarantee absolute security. Do not share your password with anyone and tell us about suspicious activity.

Children

Dayveo is intended for users aged 13 and over and is not directed at younger children. We do not knowingly collect data from users under 13. If you believe a child has given us personal data, please write to support.

Changes to this policy

We may update this policy as the service evolves or as legal requirements change. The current date is always shown at the top of the page.

Contact

Oleksandr Abramenko, sole proprietor (FOP)
Shkilna street 7, Novodmytrivka Druha,
Ivanivskyi district, Kherson region, Ukraine
Email: support@dayveo.com

This is a translation of the Ukrainian original. If the two versions differ, the Ukrainian version prevails.