Privacy policy
Draft. This policy still needs legal review and the operator's details. Last updated: [date].
DaisyTasks is built so that we can't read your tasks. This page explains exactly what we do store, why, and for how long.
Who we are
[Operator name, address, country], contact: [email address]. We are the controller for the data described below.
The apps
- Your tasks are stored on your device. The apps contain no advertising, analytics or tracking code, and don't send your tasks anywhere unless you turn on sync.
- Notifications for due tasks are scheduled on the device itself.
Sync
With sync on, each device encrypts every change (AES-256-GCM) with a key derived from your sync code (and password, if you set one) before uploading it. The key never leaves your devices; we cannot decrypt anything. The sync server stores:
| Data | Why | Kept |
|---|---|---|
| A vault id (random-looking, derived from your sync code) and a hash of its access token | To know which encrypted data belongs together and who may write it | Until you delete the vault |
| Encrypted change history: ciphertext, its size, an id, a type (changes or snapshot) and when it was uploaded | To deliver your changes to your other devices | Until you delete the vault |
| Storage used by the vault | Quotas | Until you delete the vault |
| The id of a deleted vault and when it was deleted | So a deleted vault can't be recreated or reused | Permanently (it contains nothing else) |
| Your IP address | Rate limiting and protection against abuse and password guessing (in memory); web server access logs | Rate limiting: minutes, never written to disk. Access logs: [N] days |
| Backups of the above | Recovery after a server failure | [30] days |
Inside the encrypted data (unreadable to us) are your tasks and a short record of each synced device: its name, platform, app version and when it last synced, so your devices can show the list of linked devices.
You can delete everything from the server at any time in the app: Sync → Delete vault from server. It is removed immediately; backups age out within the period above. If you use your own sync server, we receive nothing at all.
Subscriptions
Payments are processed by Stripe, Inc. and its affiliates ("Stripe"). When you subscribe, Stripe collects your email address, payment details and billing address under Stripe's privacy policy; we never see your card number. We keep, linked to your vault id: the Stripe customer and subscription ids, the plan, its status and the current billing period, to know whether sync is paid. Stripe keeps invoices as required by tax law; we can see your email address and invoices in Stripe's dashboard, and use them only to provide the service and answer you.
When you open the subscription page from the app, it receives a one-hour link that only gives access to that vault's subscription, never to your sync code or tasks. We store a hash of that link's token until it expires.
This website
No cookies, no analytics, no third-party scripts. The subscription page keeps its one-hour link in your browser's session storage, which is cleared when you close the tab. [Hosting provider] serves the site and may keep standard access logs (IP address, time, page) for [N] days.
Legal bases
- Providing sync and subscriptions you asked for: performance of a contract (GDPR art. 6(1)(b)).
- Security, abuse prevention and backups: our legitimate interest in a working, safe service (art. 6(1)(f)).
- Keeping invoices: legal obligation (art. 6(1)(c)).
Processors and transfers
- [VPS provider, country]: hosts the sync server and its data (encrypted by you).
- [Backup storage provider, country]: stores encrypted backups.
- Stripe: payments. Stripe may process data outside the EEA under its own safeguards.
Your rights
You can access, correct, delete or export your data, object to processing, and complain to a supervisory authority (in Poland: Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl). Because we have no accounts, the easiest way is in the app: export your tasks, or delete the vault from the server. For subscription data, use the subscription page or write to [email address] with your vault id (shown on the subscription page).
Children
DaisyTasks is not directed at children under 16, and we don't knowingly collect their data.
Changes
We will post changes here and update the date above. Material changes will also be announced in the apps.