Skip to main content

daylog legal

Data Retention Policy

How long Daylog keeps active accounts, entries, tokens, operational records, and deleted data.

last updated · 12 August 2026

Daylog currently has no automated self-service account deletion screen. Contact the address below for account and associated-data deletion.

Active account data

Account profiles, tasks, notes, tags, settings, and active credential records are retained while your account remains active so Daylog can provide the service. Entries remain until you delete them or request account deletion.

Deleted entries and revoked tokens

Deleting an entry removes it from the active Daylog database. Revoking a personal access token removes the credential record from active use; the plaintext token was never retained after it was first shown.

Supabase, Vercel, or other infrastructure providers may retain limited copies in logs, disaster-recovery systems, or backups for their documented retention periods. Those copies are isolated from normal product use and expire through provider processes.

Authentication and OAuth records

Supabase retains authentication sessions and OAuth authorization records needed to operate and secure login. Signing out removes the current browser session; disconnecting an OAuth client or deleting the account ends the relevant authorization path, subject to token expiry and provider retention.

AI requests

Daylog does not intentionally store a separate permanent copy of AI Capture prompts or model responses beyond the entries you choose to save and ordinary short-lived operational logs. The selected AI provider may retain request data under its own policy and account settings.

Analytics and operational logs

Vercel Web Analytics uses aggregated data and a visitor identifier that resets daily. Hosting, database, security, and error logs may be retained temporarily by service providers for operations, abuse prevention, debugging, and legal compliance.

Account deletion requests

Send a request from the address associated with your Daylog account using the contact details at aasimahmed.com. After identity verification, Daylog will remove or anonymize active account data within 30 days unless retention is required for security, dispute resolution, fraud prevention, or law. Provider backups may take additional time to age out under provider schedules.

Legal holds and policy changes

Specific records may be retained longer when reasonably necessary to comply with law, preserve evidence, resolve disputes, or protect users and the service. This policy will be updated when retention practices materially change.