Privacy policy

Draft. This policy still needs legal review and the operator's details. Last updated: [date].

DaisyTasks is built so that we can't read your tasks. This page explains exactly what we do store, why, and for how long.

Who we are

[Operator name, address, country], contact: [email address]. We are the controller for the data described below.

The apps

Sync

With sync on, each device encrypts every change (AES-256-GCM) with a key derived from your sync code (and password, if you set one) before uploading it. The key never leaves your devices; we cannot decrypt anything. The sync server stores:

DataWhyKept
A vault id (random-looking, derived from your sync code) and a hash of its access tokenTo know which encrypted data belongs together and who may write itUntil you delete the vault
Encrypted change history: ciphertext, its size, an id, a type (changes or snapshot) and when it was uploadedTo deliver your changes to your other devicesUntil you delete the vault
Storage used by the vaultQuotasUntil you delete the vault
The id of a deleted vault and when it was deletedSo a deleted vault can't be recreated or reusedPermanently (it contains nothing else)
Your IP addressRate limiting and protection against abuse and password guessing (in memory); web server access logsRate limiting: minutes, never written to disk. Access logs: [N] days
Backups of the aboveRecovery after a server failure[30] days

Inside the encrypted data (unreadable to us) are your tasks and a short record of each synced device: its name, platform, app version and when it last synced, so your devices can show the list of linked devices.

You can delete everything from the server at any time in the app: Sync → Delete vault from server. It is removed immediately; backups age out within the period above. If you use your own sync server, we receive nothing at all.

Subscriptions

Payments are processed by Stripe, Inc. and its affiliates ("Stripe"). When you subscribe, Stripe collects your email address, payment details and billing address under Stripe's privacy policy; we never see your card number. We keep, linked to your vault id: the Stripe customer and subscription ids, the plan, its status and the current billing period, to know whether sync is paid. Stripe keeps invoices as required by tax law; we can see your email address and invoices in Stripe's dashboard, and use them only to provide the service and answer you.

When you open the subscription page from the app, it receives a one-hour link that only gives access to that vault's subscription, never to your sync code or tasks. We store a hash of that link's token until it expires.

This website

No cookies, no analytics, no third-party scripts. The subscription page keeps its one-hour link in your browser's session storage, which is cleared when you close the tab. [Hosting provider] serves the site and may keep standard access logs (IP address, time, page) for [N] days.

Legal bases

Processors and transfers

Your rights

You can access, correct, delete or export your data, object to processing, and complain to a supervisory authority (in Poland: Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl). Because we have no accounts, the easiest way is in the app: export your tasks, or delete the vault from the server. For subscription data, use the subscription page or write to [email address] with your vault id (shown on the subscription page).

Children

DaisyTasks is not directed at children under 16, and we don't knowingly collect their data.

Changes

We will post changes here and update the date above. Material changes will also be announced in the apps.