daylog legal
Privacy Policy
How Daylog collects, uses, shares, and protects account, log, AI, and MCP data.
last updated · 12 August 2026
The short version
Daylog stores the information needed to run your account and personal log. Your entries are private to your account. Daylog does not sell your personal data or use your entries for advertising.
Information Daylog processes
- Account information, including your email address, authentication identifiers, and role.
- Content you create, including task and note titles, note content, dates, statuses, and tags.
- Settings and credentials you create, including AI preferences and hashed personal access tokens. A raw personal access token is shown once and is not stored in plaintext.
- Operational information needed to deliver and secure requests, such as timestamps, request metadata, error information, and token last-used dates.
- Anonymous website analytics such as page paths, referrers, country-level location, browser, operating system, and device type.
How the information is used
- Authenticate you, maintain your session, and protect private routes.
- Create, display, search, update, export, and delete your Daylog entries.
- Provide optional AI parsing and authenticated MCP access when you choose to use those features.
- Operate, troubleshoot, protect, and improve the service.
- Comply with legal obligations and enforce the Terms.
Service providers and optional AI processing
Daylog is hosted on Vercel and uses Supabase for authentication and the PostgreSQL database. These providers process data on Daylog’s behalf to deliver the service.
If you use AI Capture, the text you submit is sent to the currently configured provider—GroqCloud, Google Gemini, or OpenRouter—for parsing. Provider availability may change. Do not submit sensitive information to AI Capture unless you are comfortable with the selected provider’s terms and privacy practices.
If you connect an external MCP client, that client may receive entry data and request changes according to the tools you enable and approve. The client provider’s privacy policy applies to data handled by that client.
Analytics and cookies
Daylog uses Vercel Web Analytics for aggregated traffic measurement. Vercel describes this product as cookie-free and based on anonymous, daily-reset visitor identification. Daylog does not use advertising trackers.
Authentication requires essential session cookies. See the Cookie Policy for details.
Security and your choices
Daylog uses account-scoped authorization checks, encrypted HTTPS transport, hashed personal access tokens, and managed authentication. No internet service can guarantee absolute security.
You can edit or delete entries, revoke personal access tokens, disconnect OAuth clients, or request account deletion. Markdown export lets you keep a portable copy of your log.
Contact and changes
Questions, privacy requests, and account deletion requests can be sent through the contact details published at aasimahmed.com. Daylog may update this policy as the service changes; the revised date above will be updated when material changes are made.