Daykite
Legal

Privacy Policy

Effective 19 September 2026

Daykite holds the most personal thing most people have — where their time goes. This policy explains what we collect, why, who sees it, and how you stay in control of it.

In short: we collect what the service needs, we don’t sell it or use it for advertising, Google data is used only for the features you turn on, and you can export or delete everything yourself.

Contents
  1. 1. Who we are
  2. 2. What we collect
  3. 3. How we use it
  4. 4. Google user data
  5. 5. The AI assistant
  6. 6. Who we share it with
  7. 7. How long we keep it
  8. 8. Your choices and rights
  9. 9. Security
  10. 10. Cookies and local storage
  11. 11. International transfers
  12. 12. Children
  13. 13. Changes to this policy
  14. 14. Contact

1.Who we are

Daykite is a calendar, task and booking service run by Daykite (“we”, “us”). For the personal data you put into your account, we are the data controller.

When you use Daykite to collect other people’s details — guests who book a time on your booking page, or colleagues you add to a project — you decide what is collected and why. For that data we act on your behalf, and you’re responsible for having a reason to collect it.

Questions about this policy or your data: privacy@daykite.com.

2.What we collect

We collect only what the service needs to work:

Kind of dataExamplesWhere it comes from
AccountName, email address, password (stored only as a salted hash), time zone, two-factor secret and recovery codes (hashed). If you use Continue with Google: your Google account ID and profile photoYou, at sign-up and in Settings; Google, if you sign in with it
What you createEvents, routines, tasks, projects, comments, attachments, Spaces, meeting types, automations, preferencesYou and the people you share Spaces and projects with
BookingsA guest's name, email address, chosen time, and any answers or notes they giveGuests, on your booking page
Connected Google dataCalendar events; Gmail message subject, sender and preview for labels you choose; Meet links; spreadsheet names and tabs you pick; the Google Tasks lists you choose to import; the Google Docs your automations createGoogle, only after you connect and approve each permission (see section 4)
Connected Microsoft dataOutlook calendar events; Outlook message subject, sender, preview and link for the category you choose; Teams meeting links Daykite creates; the To Do lists you choose to import; links to OneDrive folders your automations create; your Microsoft account ID and email addressMicrosoft, only after you connect Outlook and approve its permissions
Connected Slack workspaceThe workspace's name and ID, your Slack user ID, and the names of channels you post to. Daykite doesn't read Slack messages.Slack, only after you connect it and approve
Connected Calendly accountYour Calendly user and organization IDs and email address, and your scheduled events: time, event type, location or call link, and each invitee's name and email address.Calendly, only after you connect it and approve
Connected task tools: Notion, Linear, Asana, Trello, ClickUp, Jira, GitHub, Airtable, HubSpot, Salesforce, monday.com, Pipedrive, GitLab, Zoho CRM, Azure DevOpsYour account ID and email or username there, and the tasks (names, notes, due dates, done or not) in the databases, teams, projects or boards you choose to import. Daykite only reads these tools.The tool you connect, only after you approve
Connected Todoist accountYour Todoist user ID and email address, and the tasks in the projects you choose to import. Daykite only reads Todoist.Todoist, only after you connect it and approve
Watched forms: Typeform, Jotform, Google FormsThe forms you choose to watch, their questions, and new responses (answers and, where collected, the respondent's email) — to start your automations. Response ids are kept 30 days so none runs twice.The form tool, only after you connect it and choose a form
Acuity Scheduling and EventbriteYour appointments (time, type, client name, place) or the events you organise (name, time, venue, link).Acuity or Eventbrite, only after you connect it
StripeYour Stripe account ID, and for payments, subscriptions and invoices after you connect: the amount, currency, description, status and the customer's name and email — to start your automations. Card details are never read or stored. Connection tokens are stored encrypted.Stripe, only after you install Daykite's Stripe app and approve its permissions
WhatsApp BusinessYour WhatsApp Business Account and phone number IDs, the business name and number, your approved template names and text, a daily count of messages sent, and the messages customers send your number (sender's number, profile name and text) — to start your automations. Message ids are kept 7 days so none runs twice. The token Meta issues is stored encrypted.Meta, after you connect through its sign-in and choose your WhatsApp account
Apple iCloud and other CalDAV calendarsYour Apple ID email (or username), the app-specific password you made for Daykite (stored encrypted), the calendars you choose and their events over the past 90 days and next year. Changes you make in Daykite are written back.Apple or your CalDAV provider, only after you connect and choose calendars
Subscribed calendars (.ics)The calendar address you subscribe to (which may contain a private link from iCloud, Fastmail or others) and the events it publishes over the past 90 days and next year.The calendar's provider, when you subscribe
EvernoteYour Evernote account ID, name and email, and the notes your automations create (title, text, notebook). Daykite asks only to read and create, and doesn't read your existing notes. Connection tokens are stored encrypted.Evernote, only after you connect it and approve
Dropbox and BoxYour account ID and email, and the names and links of folders your automations create. Daykite doesn't read your files. Connection tokens are stored encrypted.Dropbox or Box, only after you connect it and approve
QuickBooks and XeroThe company or organisation name and your unpaid sales invoices (number, customer name, amount owed, due date), to make follow-up tasks. Connection tokens are stored encrypted.QuickBooks or Xero, only after you connect it and approve
WordPress siteThe site address, your WordPress username and email, the application password you made for Daykite (stored encrypted), and the titles and dates of your scheduled and recent posts.Your site, only after you connect it
TwilioYour Account SID, API key SID and secret (stored encrypted), the number you send from, and a count of texts sent today. The numbers and messages your automations text are sent to Twilio, and kept in the automation's run history.You, when you connect Twilio
Time trackers: Toggl Track, Clockify, HarvestThe last two weeks of your time entries (times, descriptions, project and task names), and your API token or connection, stored encrypted.The tracker, only after you connect it
Discord serverThe server's ID and name and its channel names, so you can pick where automations post. Daykite's bot doesn't read messages.Discord, when you add Daykite to a server
Connected Zoom accountYour Zoom user ID and email address, and the Zoom meetings Daykite creates. Removing Daykite in Zoom deletes the connection.Zoom, only after you connect it and approve
BillingNumber of seats, subscription status, Polar customer and subscription IDs. We never see or store card numbers.Polar, our payment provider
Security and deviceIP address and browser user agent for each signed-in session; device name and push token if a Daykite app registers one; and, for each browser you turn notifications on in, the push address and keys your browser's push service (Google, Mozilla, Apple or Microsoft) gives it. The title and short text of each notification pass through Expo (phones) or that push service (browsers) to reach you — encrypted end to end for browsers.Your browser or device
AssistantWhat you ask the assistant and its answers, the changes it suggested and whether you confirmed them, your ratings, and page or email text you chose to share from the Chrome extensionYou, when you use the assistant (see section 5)
SupportBug reports: your description, the page you were on and your browser; emails you send usYou

We don't use advertising trackers, sell data to data brokers, or run third-party analytics scripts in the app.

Our public website (the home page, feature and pricing pages, docs and blog) uses Google Analytics to count visits and see which pages are useful. It records the pages you view, roughly where you are, your device and browser, and how you arrived. It doesn't run on the signed-in app, and we don't send it your account details or anything you put in Daykite. You can block it with your browser's tracking protection or Google's opt-out add-on.

3.How we use it

  • To run the service — show your calendar, sync it, send booking confirmations and reminders, run the automations you set up, and keep your devices in step.
  • To keep accounts secure — verify your email address, check sign-ins and two-factor codes, show you your active sessions, and stop abuse.
  • To bill organizations — count seats and keep subscription status up to date.
  • To support you — answer questions and fix the bugs you report.
  • To tell you about the service — important changes to your account, security or these terms. We don’t send marketing email without your consent.

Where laws such as the GDPR require a legal basis, we rely on performing our contract with you for running the service and billing, legitimate interests for security and fixing problems, consent for connecting Google and any optional email, and legal obligations for keeping financial records.

We do not use your content to train artificial-intelligence or machine-learning models, unless you turn on “Help improve DayKite AI” (section 5). Data from Google is never used for that, whatever you choose.

4.Google user data

Using Google is optional. Continue with Google only signs you in. Connecting Google Calendar is a separate step, and you’re asked separately again for Gmail, Google Meet and Google Sheets — only when you turn on a feature that needs them. Here is exactly what each permission is used for:

PermissionWhat Daykite does with itWhat it doesn't do
Sign in with Google
openid email profile
Signs you in or creates your account: your Google account ID, email address, name and profile photo. Also shows which Google account is connected.Give Daykite access to your calendar, email, contacts or files.
Google Calendar
auth/calendar
Lists your calendars so you can choose which to show; copies their events into Daykite and keeps them in sync both ways; adds bookings and events you create to the calendar you pick.Change calendars or events you haven't chosen to sync, or share them outside the Spaces and visibility you set.
Gmail — send
auth/gmail.send
Sends an email from your address when an automation you created says to.Send anything you didn't set up in a rule.
Gmail — labels
auth/gmail.modify
For a label you choose, reads each labelled message's subject, sender and short preview to create a task, then removes that label so it isn't filed twice.Read message bodies or attachments, read mail outside the chosen label, or delete email.
Google Meet
auth/meetings.space.created
Creates a new Meet link for an event or booking when you ask for one.Join, record or read your meetings, or see Meet spaces Daykite didn't create.
Google Tasks
auth/tasks.readonly
For the task lists you choose, reads each task's title, notes, due date and whether it's done, to keep a copy in your Daykite list.Create, change or delete anything in Google Tasks, or read lists you didn't choose.
Google Forms
auth/forms.body.readonly, auth/forms.responses.readonly
For forms you add by link, reads the questions and new responses, to start the automations you set up.See or change any other form, or anything else in Google Drive.
Google Sheets
auth/spreadsheets
Reads the name and tabs of a spreadsheet you point Daykite at; creates spreadsheets you ask for; adds rows from your automations and booking exports.Read cell contents of your spreadsheets, or touch spreadsheets you haven't given it.
Google Docs
auth/drive.file
Creates documents from your automations (a title and the starting text you write) and keeps their links.See, open or change any file in your Google Drive that Daykite didn't create.
Daykite’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In line with those requirements:

  • We use Google user data only to provide and improve the features you can see in Daykite and that you turned on.
  • We transfer it to others only when needed to provide those features (for example, to the people you share a Space with, at the visibility you choose), to comply with the law, for security, or as part of a merger or sale with notice to you.
  • We don't use it for advertising, including retargeting or personalised or interest-based ads, and we don't sell it.
  • We don't use it to build or train generalised artificial-intelligence or machine-learning models.
  • No person at Daykite reads it unless you give us permission for a specific support request, it's necessary for security (such as investigating abuse), it's required by law, or it has been aggregated and anonymised for internal operations.

Google access and refresh tokens are encrypted (AES-256-GCM) before they are stored. You can disconnect Google at any time under Integrations: we revoke our access with Google straight away and stop syncing. You can also remove access from your Google Account permissions page. Events already copied from Google stay in your account, hidden, until you delete them or your account; ask us at privacy@daykite.com and we’ll remove them sooner.

5.The AI assistant

The assistant answers questions about your calendar, tasks and routines, and suggests changes that happen only when you confirm them. It sees what you can see in Daykite, under the same visibility rules.

Most requests never reach an AI model — quick actions and everyday requests are answered by Daykite’s own code. Open-ended requests are sent to an AI model provider (see section 6): the request, the last few messages of the conversation, the information the assistant looked up to answer it, and any page or email text you chose to share from the Chrome extension. Before anything is sent, passwords, keys, tokens and payment card numbers are masked, and shared page text is cut to a fixed size. The provider processes it only to produce the answer.

The Chrome extension reads a web page only when you ask it to — by right-clicking selected text, or by ticking “Include this page” — and then only the selection, the open email, or the page’s main text. Web addresses are stored without their query strings.

  • Retention: conversations are kept for 90 days unless you choose 7 days, 30 days or a year in Settings → Assistant; shared page and email text is removed after 7 days; unanswered suggestions expire after 30 minutes. You can delete all assistant history at any time.
  • Improving the assistant: “Help improve DayKite AI” is off unless you turn it on. When on, conversations without page or email content may be used to improve the assistant. Data received from Google APIs is never used for this, or to train any AI model.
  • Separate storage: assistant data is kept apart from your calendar data and is deleted with your account.

6.Who we share it with

We share personal data only in these cases:

  • People you share with. Members of your Spaces, projects and organization see what the visibility settings allow — full details, “busy” only, or nothing. Guests see what your booking page shows them.
  • Service providers who process data for us under contract, only to run Daykite:
ProviderWhat forData involved
BrevoSending account, verification, booking and notification emailsRecipient name and email, and the email's contents
PolarPayments and invoices, as merchant of recordOrganization name, billing email, seats; card details go to Polar, not us
GoogleThe Google features you connectWhat section 4 describes
GroqAnswering assistant requests that need an AI modelWhat section 5 describes, only for those requests
Hosting and database providersRunning our servers, database and file storageEverything stored in the service, encrypted in transit
  • Tools you connect yourself. Webhooks, API keys and apps you authorise receive the data you point them at. Their own privacy policies apply once it reaches them.
  • The law. When we must, to comply with a valid legal request, or to protect people’s safety or the service. Where we’re allowed to, we’ll tell you first.
  • A change of ownership. If Daykite is merged or sold, your data moves with the service under this policy, and we’ll tell you beforehand.

We don't sell personal data, and we don't share it for cross-context behavioural advertising.

7.How long we keep it

  • Your account and content — for as long as you have an account. Items you delete are marked deleted so your other devices can catch up, and are removed with your account.
  • When you delete your account — your profile, the Spaces you own and their calendars and events, tasks, routines, connected accounts and sessions are deleted immediately. Events you organised in other people’s Spaces stay there without your name on them. Copies in encrypted backups are overwritten as those backups rotate.
  • Sign-in sessions — up to 30 days, or until you sign out. Email and sign-in codes expire within 15 minutes and stop working after five wrong attempts.
  • Billing records — as long as tax and accounting law requires, even after an account is closed.

8.Your choices and rights

Most of these you can do yourself, straight away, without contacting anyone:

  • See and download your data — Settings → Account → Your data exports everything as a JSON file, and each calendar as an .ics file.
  • Correct it — edit your profile and content in the app.
  • Delete it — delete items individually, or your whole account from Settings → Account.
  • Withdraw consent for Google — disconnect it under Integrations.
  • Control notifications — Settings → Notifications.

Depending on where you live (for example under the GDPR, UK GDPR or California law), you may also have the right to restrict or object to processing, and to complain to your local data protection authority. Email privacy@daykite.com for anything the app doesn’t cover; we answer within 30 days and won’t treat you differently for asking.

9.Security

Connections to Daykite use HTTPS. Passwords are hashed, never stored as text. Tokens for connected services are encrypted. Attachments are only served to signed-in people with access to them. You can turn on two-factor authentication and see or end your active sessions in Settings.

No system is perfectly secure. If we learn of a breach that affects your data, we’ll tell you and the authorities as the law requires. To report a vulnerability, email security@daykite.com.

10.Cookies and local storage

In the app we use only what's needed to sign you in and remember your settings — no advertising or cross-site tracking cookies. The public website also sets Google Analytics cookies:

NamePurposeLasts
daykite_sessionKeeps you signed inUp to 30 days
daykite_oauth_stateProtects the Google connection step from forgery10 minutes
daykite_oauth_returnReturns you to the page you connected Google from10 minutes
Browser local storageTheme, view preferences and changes waiting to sync while you're offlineUntil you clear it
_gaGoogle Analytics, public website only: tells one visit from anotherUp to 2 years
_ga_*Google Analytics, public website only: keeps a visit togetherUp to 2 years

11.International transfers

Our providers may process data in countries other than yours, including the United States. Where the law requires it, we rely on safeguards such as the European Commission’s Standard Contractual Clauses.

12.Children

Daykite isn’t meant for anyone under 16, and we don’t knowingly collect their data. If you believe a child has given us personal data, email privacy@daykite.com and we’ll delete it.

13.Changes to this policy

When we change this policy we update the effective date above. If a change is significant — especially to how we use Google user data — we’ll email account owners before it takes effect, and ask for your consent again where the law or Google’s policies require it.

14.Contact

Privacy questions and requests: privacy@daykite.com. Everything else: help@daykite.com.