Privacy Policy
Effective 19 September 2026
Daykite holds the most personal thing most people have — where their time goes. This policy explains what we collect, why, who sees it, and how you stay in control of it.
In short: we collect what the service needs, we don’t sell it or use it for advertising, Google data is used only for the features you turn on, and you can export or delete everything yourself.
Contents
1.Who we are
Daykite is a calendar, task and booking service run by Daykite (“we”, “us”). For the personal data you put into your account, we are the data controller.
When you use Daykite to collect other people’s details — guests who book a time on your booking page, or colleagues you add to a project — you decide what is collected and why. For that data we act on your behalf, and you’re responsible for having a reason to collect it.
Questions about this policy or your data: privacy@daykite.com.
2.What we collect
We collect only what the service needs to work:
| Kind of data | Examples | Where it comes from |
|---|---|---|
| Account | Name, email address, password (stored only as a salted hash), time zone, two-factor secret and recovery codes (hashed). If you use Continue with Google: your Google account ID and profile photo | You, at sign-up and in Settings; Google, if you sign in with it |
| What you create | Events, routines, tasks, projects, comments, attachments, Spaces, meeting types, automations, preferences | You and the people you share Spaces and projects with |
| Bookings | A guest's name, email address, chosen time, and any answers or notes they give | Guests, on your booking page |
| Connected Google data | Calendar events; Gmail message subject, sender and preview for labels you choose; Meet links; spreadsheet names and tabs you pick; the Google Tasks lists you choose to import; the Google Docs your automations create | Google, only after you connect and approve each permission (see section 4) |
| Connected Microsoft data | Outlook calendar events; Outlook message subject, sender, preview and link for the category you choose; Teams meeting links Daykite creates; the To Do lists you choose to import; links to OneDrive folders your automations create; your Microsoft account ID and email address | Microsoft, only after you connect Outlook and approve its permissions |
| Connected Slack workspace | The workspace's name and ID, your Slack user ID, and the names of channels you post to. Daykite doesn't read Slack messages. | Slack, only after you connect it and approve |
| Connected Calendly account | Your Calendly user and organization IDs and email address, and your scheduled events: time, event type, location or call link, and each invitee's name and email address. | Calendly, only after you connect it and approve |
| Connected task tools: Notion, Linear, Asana, Trello, ClickUp, Jira, GitHub, Airtable, HubSpot, Salesforce, monday.com, Pipedrive, GitLab, Zoho CRM, Azure DevOps | Your account ID and email or username there, and the tasks (names, notes, due dates, done or not) in the databases, teams, projects or boards you choose to import. Daykite only reads these tools. | The tool you connect, only after you approve |
| Connected Todoist account | Your Todoist user ID and email address, and the tasks in the projects you choose to import. Daykite only reads Todoist. | Todoist, only after you connect it and approve |
| Watched forms: Typeform, Jotform, Google Forms | The forms you choose to watch, their questions, and new responses (answers and, where collected, the respondent's email) — to start your automations. Response ids are kept 30 days so none runs twice. | The form tool, only after you connect it and choose a form |
| Acuity Scheduling and Eventbrite | Your appointments (time, type, client name, place) or the events you organise (name, time, venue, link). | Acuity or Eventbrite, only after you connect it |
| Stripe | Your Stripe account ID, and for payments, subscriptions and invoices after you connect: the amount, currency, description, status and the customer's name and email — to start your automations. Card details are never read or stored. Connection tokens are stored encrypted. | Stripe, only after you install Daykite's Stripe app and approve its permissions |
| WhatsApp Business | Your WhatsApp Business Account and phone number IDs, the business name and number, your approved template names and text, a daily count of messages sent, and the messages customers send your number (sender's number, profile name and text) — to start your automations. Message ids are kept 7 days so none runs twice. The token Meta issues is stored encrypted. | Meta, after you connect through its sign-in and choose your WhatsApp account |
| Apple iCloud and other CalDAV calendars | Your Apple ID email (or username), the app-specific password you made for Daykite (stored encrypted), the calendars you choose and their events over the past 90 days and next year. Changes you make in Daykite are written back. | Apple or your CalDAV provider, only after you connect and choose calendars |
| Subscribed calendars (.ics) | The calendar address you subscribe to (which may contain a private link from iCloud, Fastmail or others) and the events it publishes over the past 90 days and next year. | The calendar's provider, when you subscribe |
| Evernote | Your Evernote account ID, name and email, and the notes your automations create (title, text, notebook). Daykite asks only to read and create, and doesn't read your existing notes. Connection tokens are stored encrypted. | Evernote, only after you connect it and approve |
| Dropbox and Box | Your account ID and email, and the names and links of folders your automations create. Daykite doesn't read your files. Connection tokens are stored encrypted. | Dropbox or Box, only after you connect it and approve |
| QuickBooks and Xero | The company or organisation name and your unpaid sales invoices (number, customer name, amount owed, due date), to make follow-up tasks. Connection tokens are stored encrypted. | QuickBooks or Xero, only after you connect it and approve |
| WordPress site | The site address, your WordPress username and email, the application password you made for Daykite (stored encrypted), and the titles and dates of your scheduled and recent posts. | Your site, only after you connect it |
| Twilio | Your Account SID, API key SID and secret (stored encrypted), the number you send from, and a count of texts sent today. The numbers and messages your automations text are sent to Twilio, and kept in the automation's run history. | You, when you connect Twilio |
| Time trackers: Toggl Track, Clockify, Harvest | The last two weeks of your time entries (times, descriptions, project and task names), and your API token or connection, stored encrypted. | The tracker, only after you connect it |
| Discord server | The server's ID and name and its channel names, so you can pick where automations post. Daykite's bot doesn't read messages. | Discord, when you add Daykite to a server |
| Connected Zoom account | Your Zoom user ID and email address, and the Zoom meetings Daykite creates. Removing Daykite in Zoom deletes the connection. | Zoom, only after you connect it and approve |
| Billing | Number of seats, subscription status, Polar customer and subscription IDs. We never see or store card numbers. | Polar, our payment provider |
| Security and device | IP address and browser user agent for each signed-in session; device name and push token if a Daykite app registers one; and, for each browser you turn notifications on in, the push address and keys your browser's push service (Google, Mozilla, Apple or Microsoft) gives it. The title and short text of each notification pass through Expo (phones) or that push service (browsers) to reach you — encrypted end to end for browsers. | Your browser or device |
| Assistant | What you ask the assistant and its answers, the changes it suggested and whether you confirmed them, your ratings, and page or email text you chose to share from the Chrome extension | You, when you use the assistant (see section 5) |
| Support | Bug reports: your description, the page you were on and your browser; emails you send us | You |
We don't use advertising trackers, sell data to data brokers, or run third-party analytics scripts in the app.
Our public website (the home page, feature and pricing pages, docs and blog) uses Google Analytics to count visits and see which pages are useful. It records the pages you view, roughly where you are, your device and browser, and how you arrived. It doesn't run on the signed-in app, and we don't send it your account details or anything you put in Daykite. You can block it with your browser's tracking protection or Google's opt-out add-on.
3.How we use it
- To run the service — show your calendar, sync it, send booking confirmations and reminders, run the automations you set up, and keep your devices in step.
- To keep accounts secure — verify your email address, check sign-ins and two-factor codes, show you your active sessions, and stop abuse.
- To bill organizations — count seats and keep subscription status up to date.
- To support you — answer questions and fix the bugs you report.
- To tell you about the service — important changes to your account, security or these terms. We don’t send marketing email without your consent.
Where laws such as the GDPR require a legal basis, we rely on performing our contract with you for running the service and billing, legitimate interests for security and fixing problems, consent for connecting Google and any optional email, and legal obligations for keeping financial records.
We do not use your content to train artificial-intelligence or machine-learning models, unless you turn on “Help improve DayKite AI” (section 5). Data from Google is never used for that, whatever you choose.
4.Google user data
Using Google is optional. Continue with Google only signs you in. Connecting Google Calendar is a separate step, and you’re asked separately again for Gmail, Google Meet and Google Sheets — only when you turn on a feature that needs them. Here is exactly what each permission is used for:
| Permission | What Daykite does with it | What it doesn't do |
|---|---|---|
Sign in with Googleopenid email profile | Signs you in or creates your account: your Google account ID, email address, name and profile photo. Also shows which Google account is connected. | Give Daykite access to your calendar, email, contacts or files. |
Google Calendarauth/calendar | Lists your calendars so you can choose which to show; copies their events into Daykite and keeps them in sync both ways; adds bookings and events you create to the calendar you pick. | Change calendars or events you haven't chosen to sync, or share them outside the Spaces and visibility you set. |
Gmail — sendauth/gmail.send | Sends an email from your address when an automation you created says to. | Send anything you didn't set up in a rule. |
Gmail — labelsauth/gmail.modify | For a label you choose, reads each labelled message's subject, sender and short preview to create a task, then removes that label so it isn't filed twice. | Read message bodies or attachments, read mail outside the chosen label, or delete email. |
Google Meetauth/meetings.space.created | Creates a new Meet link for an event or booking when you ask for one. | Join, record or read your meetings, or see Meet spaces Daykite didn't create. |
Google Tasksauth/tasks.readonly | For the task lists you choose, reads each task's title, notes, due date and whether it's done, to keep a copy in your Daykite list. | Create, change or delete anything in Google Tasks, or read lists you didn't choose. |
Google Formsauth/forms.body.readonly, auth/forms.responses.readonly | For forms you add by link, reads the questions and new responses, to start the automations you set up. | See or change any other form, or anything else in Google Drive. |
Google Sheetsauth/spreadsheets | Reads the name and tabs of a spreadsheet you point Daykite at; creates spreadsheets you ask for; adds rows from your automations and booking exports. | Read cell contents of your spreadsheets, or touch spreadsheets you haven't given it. |
Google Docsauth/drive.file | Creates documents from your automations (a title and the starting text you write) and keeps their links. | See, open or change any file in your Google Drive that Daykite didn't create. |
In line with those requirements:
- We use Google user data only to provide and improve the features you can see in Daykite and that you turned on.
- We transfer it to others only when needed to provide those features (for example, to the people you share a Space with, at the visibility you choose), to comply with the law, for security, or as part of a merger or sale with notice to you.
- We don't use it for advertising, including retargeting or personalised or interest-based ads, and we don't sell it.
- We don't use it to build or train generalised artificial-intelligence or machine-learning models.
- No person at Daykite reads it unless you give us permission for a specific support request, it's necessary for security (such as investigating abuse), it's required by law, or it has been aggregated and anonymised for internal operations.
Google access and refresh tokens are encrypted (AES-256-GCM) before they are stored. You can disconnect Google at any time under Integrations: we revoke our access with Google straight away and stop syncing. You can also remove access from your Google Account permissions page. Events already copied from Google stay in your account, hidden, until you delete them or your account; ask us at privacy@daykite.com and we’ll remove them sooner.
5.The AI assistant
The assistant answers questions about your calendar, tasks and routines, and suggests changes that happen only when you confirm them. It sees what you can see in Daykite, under the same visibility rules.
Most requests never reach an AI model — quick actions and everyday requests are answered by Daykite’s own code. Open-ended requests are sent to an AI model provider (see section 6): the request, the last few messages of the conversation, the information the assistant looked up to answer it, and any page or email text you chose to share from the Chrome extension. Before anything is sent, passwords, keys, tokens and payment card numbers are masked, and shared page text is cut to a fixed size. The provider processes it only to produce the answer.
The Chrome extension reads a web page only when you ask it to — by right-clicking selected text, or by ticking “Include this page” — and then only the selection, the open email, or the page’s main text. Web addresses are stored without their query strings.
- Retention: conversations are kept for 90 days unless you choose 7 days, 30 days or a year in Settings → Assistant; shared page and email text is removed after 7 days; unanswered suggestions expire after 30 minutes. You can delete all assistant history at any time.
- Improving the assistant: “Help improve DayKite AI” is off unless you turn it on. When on, conversations without page or email content may be used to improve the assistant. Data received from Google APIs is never used for this, or to train any AI model.
- Separate storage: assistant data is kept apart from your calendar data and is deleted with your account.
7.How long we keep it
- Your account and content — for as long as you have an account. Items you delete are marked deleted so your other devices can catch up, and are removed with your account.
- When you delete your account — your profile, the Spaces you own and their calendars and events, tasks, routines, connected accounts and sessions are deleted immediately. Events you organised in other people’s Spaces stay there without your name on them. Copies in encrypted backups are overwritten as those backups rotate.
- Sign-in sessions — up to 30 days, or until you sign out. Email and sign-in codes expire within 15 minutes and stop working after five wrong attempts.
- Billing records — as long as tax and accounting law requires, even after an account is closed.
8.Your choices and rights
Most of these you can do yourself, straight away, without contacting anyone:
- See and download your data — Settings → Account → Your data exports everything as a JSON file, and each calendar as an .ics file.
- Correct it — edit your profile and content in the app.
- Delete it — delete items individually, or your whole account from Settings → Account.
- Withdraw consent for Google — disconnect it under Integrations.
- Control notifications — Settings → Notifications.
Depending on where you live (for example under the GDPR, UK GDPR or California law), you may also have the right to restrict or object to processing, and to complain to your local data protection authority. Email privacy@daykite.com for anything the app doesn’t cover; we answer within 30 days and won’t treat you differently for asking.
9.Security
Connections to Daykite use HTTPS. Passwords are hashed, never stored as text. Tokens for connected services are encrypted. Attachments are only served to signed-in people with access to them. You can turn on two-factor authentication and see or end your active sessions in Settings.
No system is perfectly secure. If we learn of a breach that affects your data, we’ll tell you and the authorities as the law requires. To report a vulnerability, email security@daykite.com.
11.International transfers
Our providers may process data in countries other than yours, including the United States. Where the law requires it, we rely on safeguards such as the European Commission’s Standard Contractual Clauses.
12.Children
Daykite isn’t meant for anyone under 16, and we don’t knowingly collect their data. If you believe a child has given us personal data, email privacy@daykite.com and we’ll delete it.
13.Changes to this policy
When we change this policy we update the effective date above. If a change is significant — especially to how we use Google user data — we’ll email account owners before it takes effect, and ask for your consent again where the law or Google’s policies require it.
14.Contact
Privacy questions and requests: privacy@daykite.com. Everything else: help@daykite.com.