Privacy Policy

Last updated: 2 August 2026

This policy covers the Dashday app (iOS/macOS) and the website dashday.io. Controller: mediawaves services GmbH / privacy@dashday.io.

1. Summary

2. Data we process

Local (app): task titles, notes, due dates, completion state, recurrence, ordering — in SwiftData on device (including the App Group for Share/Siri).

Account & sync (optional): email and auth via Supabase Auth; with active Dashday Plus, your todos in the todos table with row-level security (your user only).

Dashday Plus (optional): purchase and management via Apple (StoreKit). We receive subscription status from Apple to enable sync; Apple processes payment details.

Backup (optional): iCloud folder you choose, or Google Drive OAuth with drive.file scope to upload a CSV into a Dashday folder in your Drive.

Dictation (optional, iOS): microphone and speech recognition to create task text. Dashday does not run its own speech servers.

Website: standard host/CDN logs may include IP, user agent, and time. No analytics cookies for tracking.

3. Purposes & legal bases

Providing app features, optional sync/backup at your request, and keeping the service secure. Where GDPR applies: Art. 6(1)(b), (f), and/or consent for optional services.

4. Processors

We do not share data for advertising.

5. Retention

Local data until you delete it or reset the app store. Synced data until you delete todos or request account deletion. Cloud backups remain under your control in iCloud/Drive.

6. Your rights

Access, correction, deletion, restriction, portability, and objection where applicable. Delete your sync account and server todos in the app under Settings → Delete Account. Contact privacy@dashday.io. You may lodge a complaint with a supervisory authority.

7. Children

Dashday is not directed at children under 13 (or the applicable minimum age).

8. Changes

We may update this policy. The date at the top reflects the latest revision.